Impersonation Fraud Used To Be Easy To Spot
South Africa is the proud holder of many sporting and other records. However, we also hold a couple of more dubious titles we’d sooner do without. Business Tech, for example, reports we have a murder rate almost 1000% higher than other G20 countries, while Statista rates us as having the highest crime rate in Africa, and as the fifth most dangerous country globally.
And now, adding insult to injury, a Mimecast survey found we have one of the highest impersonation fraud rates in the world. Just 16% of all organisations in South Africa claim they haven’t been targeted by phishing or impersonation attacks.
Between 2023 and 2024, the South African Fraud Prevention Service recorded a 356% jump in cases.
You may remember the Passenger Rail Agency of South Africa lost R30 million this way, and even the investigative journalism publication the Daily Maverick came under attack when someone with a WhatsApp profile and picture exactly matching that of a senior company official tried to scam one of their staff. The message read: “I’m currently in a very critical meeting and I can’t take calls at the moment. I need you to run a very quick urgent task for me… I need you to initiate a transfer to a prospect of mine. You will be reimbursed…”
Luckily, journalists are sceptical by nature, so they quickly confirmed the message was fraudulent. A corporate employee, on the other hand, might not have been so suspicious.
One of the key issues is that most of us still operate under the premise that fake messages are easy to spot. Fraud used to look like an awkwardly worded email from a misspelled domain, or a clumsy attempt to mimic a supplier’s invoice.
And for years, this baseline level of operational awareness was enough to catch the vast majority of external threats.
Unfortunately, the security landscape of 2026 demands a complete overhaul of that outdated mindset.
In the past two years, impersonation fraud has evolved from opportunistic messaging to a highly industrialised and technologically advanced operation. Fraudsters have moved way beyond trying to guess passwords and are now systematically cloning the identities, voices, and faces of C-suite leaders.
Data from the Global Economic Crime Survey reveals that cybercrime – and particularly impersonation fraud using deepfake technology – now ranks as the single most reported type of corporate fraud.
The irony of how this has happened is what I personally find particularly galling: the technology we’ve embraced at scale to make our businesses more cost-effective and efficient is now being used against us. Generative AI has effectively lowered the barrier to entry for sophisticated, targeted attacks by massively expanding organisations’ cyberattack surfaces.
Today, criminals don’t need advanced coding skills or complex network access to breach a multi-million-Rand enterprise; they just need a few minutes of clear audio or video of a CEO to bypass conventional security protocols.
The often unvetted adoption of cloud technologies doesn’t, of course, help the situation. In fact, over two thirds of security leaders believe this is a primary driver of corporate vulnerability.
One of the biggest problems is that impersonation fraud isn’t just happening in one space. It’s rapidly diversifying across multiple structures, making it increasingly tricky to track with traditional corporate compliance mechanisms.
The three areas of attack we see most often are:
Phishing
This remains the foundational entry point for larger criminal operations, but instead of the previously clumsy, mass-blasted generic email templates, today’s fraudsters send highly tailored, deceptive emails pretending to be trustworthy individuals or organisations. They are worrying effective at duping accounting staff, HR managers, or system admins into providing sensitive information, login credentials, or internal directories. Unfortunately, phishing is rarely a standalone breach – it’s more like a reconnaissance mission, gleaning intelligence to plan more aggressive financial attacks.
Business Email Compromise (BEC)
This relies purely on corporate social engineering. Cybercriminals defraud businesses by impersonating high-level executives or strategic vendors using meticulously spoofed email addresses. They follow authentic corporate communication styles which gives them an implicit authority that frequently overrides standard, manual double-check protocols.
Deepfakes
This is by far the most alarming development in impersonation fraud. It is terrifying how good deepfake technology is at mimicking the voices or physical appearances of company executives, specifically CEOs and CFOs.
Why is the C-suite in particular being targeted? The reason is clear: hierarchy creates compliance.
When a simulated executive contacts junior or mid-level employees, they deliberately cultivate an atmosphere of extreme urgency and absolute confidentiality. The target is often instructed to bypass standard, multi-signature internal controls to facilitate an immediate wire transfer, for example, or release a proprietary database.
Increasingly, these attacks use multiple channels, backing up an email with a text message or WhatsApp thread, building a fictional contextual story, such as the one used in the Daily Maverick attempt. It’s typical to establish a narrative that the executive is currently traveling, locked in board meetings, or unable to access normal communication channels.
The way forward
While it’s impossible to overstate how serious this situation is, there are concrete steps we can take to strengthen our defences against these increasingly sophisticated attacks. Here are my top three recommendations:
Build an uncompromising defence protocol
Modern impersonation fraud is so effective because it bypasses firewalls and attacks human psychology. Organisations cannot rely solely on software updates or perimeter security; defeating an AI-driven identity threat requires strict, unyielding operational discipline and absolute process adherence.
Implement Out-of-Band (OOB) verification
Verify, verify, verify. It’s one of the simplest, yet most critical elements of any defence strategy. If an employee receives an urgent, but unusual directive from a senior leader, no matter how it arrived, they must not proceed with the transaction until it’s been verified through an entirely separate, pre-established channel (such as calling the executive back on a known corporate landline, using a separate encrypted internal communication network, or securing physical, in-person authorisation).
Make ongoing, high-fidelity training mandatory
Traditional cybersecurity training is obsolete, and if your finance or operations teams assume they can instinctively spot a fake communication, your capital is actively at risk. Take the time today to review your out-of-band verification policies, tighten your internal payment approvals, and ensure your workforce understands that no executive mandate ever supersedes verified corporate protocol.
Teams handling capital, sensitive personnel records, and system infrastructure must undergo regular, simulated social engineering drills. Employees need to see firsthand how easy it is to clone an executive’s voice and face.
Although impersonation fraud is AI-driven, the best defence is deeply rooted in human responses. Just as even the deadliest virus can’t penetrate unbroken human skin, even the most sophisticated AI fraud won’t breach a well-trained, aware, and on-the-ball human barrier.
We need to see a company-wide commitment to procedural discipline. If every urgent, unverified financial directive is treated with systematic scepticism, even the most sophisticated and expensive AI tools used by criminals will fail.
