Urgent.News

What's breaking now, across thousands of outlets.

Tech

Bad news for South Africans using banking apps

Banking apps were linked to about 89% of reported digital banking crime cases in South Africa in 2025, accounting for 70.5% of reported client losses, according to SABRIC. The organisation said many scams began with impersonation and social engineering rather than hacked bank systems

Bad news for South Africans using banking apps

South African banking apps have become a hotspot for digital banking crime, accounting for a staggering 89% of reported cases in 2025, according to a recent report from the South African Banking Risk Information Centre (SABRIC). This figure translates to nearly R1.7 billion in client losses, making banking apps the primary driver of digital banking crime losses.

Despite the high financial impact, only about 70.5% of the total claim amount was linked to banking apps, while internet banking contributed to roughly 28.6% of claim value, albeit in a smaller number of cases. Mobile banking represented an even smaller fraction of both cases and claim value, primarily due to its association with SIM swap-related risks.

SABRIC recorded a total of 110,074 digital banking crime incidents in 2025, with reported client claims reaching R2.41 billion, a 29.2% increase from the previous year. Importantly, these figures do not indicate that banking apps or bank systems were breached. Instead, many fraud cases began outside the banking platform, often through deception, urgency tactics, or real-time guidance by criminals impersonating trusted organizations.

Written by urgent.news from IOL's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at iol.co.za →

More in Tech

Delivery Map Presence at Scale: A 4-State Room Lifecycle for Trusted Event Flow

Short answer: use a room lifecycle with explicit token scope, presence state, and recovery rules; pick the realtime API that makes those boundaries visible instead of hiding them in a client SDK.

  • Four-state lifecycle: authenticated, subscribed, publishing, recoverable
  • Server determines workspace access, client only renders presence and sends intent
  • Three streams maintained: authentication, subscription state, business events

More from Tuesday 8 September →