Your Payment Process Is Probably More Vulnerable Than You Think
South African businesses lose billions to payment fraud every year. The uncomfortable truth? Most of it is preventable.
Here is a scenario that plays out more often than any business owner wants to admit. An employee receives an email. It looks exactly like one from a trusted supplier. The account details look right. The urgency feels real. A payment goes out. And by the time anyone realises what happened, the money is gone.
A Real Case. A Real Loss.
One of the most common fraud scenarios we are currently seeing involves a supplier emailing a client to notify them that their company bank account has changed. The client does not action the necessary due diligence. Payments go out to the new, fraudulent banking details. The real supplier sees nothing.
It is only when the supplier follows up on their 30-day outstanding payment that the full picture emerges. In a live case we are assisting with right now, the fraud occurred on 30 March. The supplier called. The client had paid in full. Into the wrong account. R593,000, gone, and very little recourse available.
This is called Business Email Compromise (BEC). It does not require sophisticated hacking. It requires your trust and a moment of not verifying.
The Gaps You Might Not Know You Have
Payment fraud does not care about your antivirus. It exploits the spaces between your systems, the manual steps, the workarounds, the processes that have not been questioned in years. The most common vulnerabilities we see include:
- Outdated or unpatched software. Known exploits in older systems are actively targeted because attackers know not everyone updates regularly.
- Manual payment processes. Copying beneficiary details between systems, downloading and re-uploading files to banking portals. Each handoff is a fraud opportunity.
- Single-point authorisation. When one person can both capture and approve a payment without oversight, the door is open for error and internal fraud.
- Unverified beneficiary details. Paying into an account without confirming it belongs to who you think it does.
- Third-party risk. Your payment process is only as strong as the weakest link in your provider chain.
Every manual step in your payment workflow is a potential fraud entry point. The businesses that get hurt most are the ones that assume it will not happen to them.
The Threats Are Getting Smarter
Cybercriminals are now using artificial intelligence to craft highly convincing phishing emails, impersonate executives over voice calls, and automate attacks at scale. The old spelling mistake giveaway no longer applies. Ransomware attackers no longer just lock your data either. They exfiltrate it first and threaten to release it publicly, adding POPIA exposure to an already costly incident.
What makes BEC particularly dangerous is its simplicity. No malware. No hacking. Just a convincing email, an unverified account number, and a business that trusted without checking.
What Genuine Payment Security Looks Like
There is a meaningful difference between security as a feature and security as a foundation. The former is a checkbox. The latter is built into every step of how payments are processed, verified, and authorised. Here is what actually matters:
Verify Before You Pay
Account Verification Services (AVS) confirm that a bank account belongs to the person or business entity you believe you are paying. Before any payment leaves your account, you should know with certainty it is going to the right place. Alongside AVS, ID Verification checks identity against authoritative sources, and Check-Digit Validation (CDV) pre-validates account numbers and branch codes before processing. Together these form a verification stack that stops errors and fraud attempts before they become losses.
Multiple Authorisation Levels
No single person should be able to capture and approve a payment without a second pair of eyes. Multi-level authorisation is particularly critical for bulk payments and payroll, where one compromised user account can cause enormous, rapid damage.
Know Your Compliance Obligations
POPIA makes payment security a legal obligation, not just an operational one. A breach that exposes customer or employee financial data is a compliance failure with real consequences. For businesses running debit order collections, SARB and BankServAfrica standards apply, including DebiCheck, which exists specifically because disputed debit order fraud reached unacceptable levels under the old NEADO system.
Security is not a feature you add to a payment platform. It is the infrastructure the platform is built on. The difference matters when it counts.
The Bottom Line
Fraud does not announce itself. It finds the gap. The unverified account detail, the single-approver payment, the third party nobody thought to question. By the time it is visible, the damage is already done.
The businesses that protect themselves most effectively are not the biggest or the most technical. They are the ones who have built payment processes on a foundation that does not assume trust, that verifies, authorises, and logs everything before the money moves.
At Paysoft, security is not a product feature. It is the reason we built our platform the way we did: bank-agnostic, purpose-built for the South African environment, with verification, multi-level authorisation, and compliance-readiness at every layer. If you are not completely confident in how your payments are protected today, that is worth a conversation.