Digital Banking Fraud Surges: Cyber Law Expert Prof. Sizwe Mtuze Warns of Sophisticated Cybercrime Tactics

GQEBERHA, Eastern Cape — As digital banking fraud continues to dominate the cybercrime landscape, accounting for more than 65% of incidents in 2024, consumers are facing increasingly sophisticated threats to their financial security. According to Prof. Sizwe Mtuze, a professor of cyber law at Nelson Mandela University, the rapid evolution of these scams requires urgent, shared responsibility between financial institutions and the public to mitigate vulnerabilities.

Criminals are deploying a wide array of advanced methods to access personal funds, including phishing, stolen one-time PINs (OTPs), SIM swaps, WhatsApp takeovers, remote access applications, and even voice cloning. Prof. Mtuze noted that while fraudsters previously relied on rudimentary tactics—such as emailing altered proof of payment documents to trick victims into refunding non-existent money—they have now become highly sophisticated, frequently using false voice prompts and impersonating legitimate banking institutions.

The cybercrime industry operates with full-time dedication to exploiting consumer vulnerability or ignorance. Prof. Mtuze highlighted a real-world example where a colleague received a link for a special airline offer that did not exist. Clicking the link allowed scammers to extract information directly from the victim’s phone, ultimately leading to unauthorized access to their bank accounts.

When addressing the critical question of liability following a breach, Prof. Mtuze described the situation as a “catch-22.” Financial institutions have a fundamental duty to ensure the technology they deploy is secure and confidential. However, consumers must also remain highly vigilant. He emphasized that a legitimate bank will never ask a customer for their one-time PIN. If a consumer receives an unexpected call from someone claiming to be a banker requesting personal verification, the safest course of action is to hang up and call the institution back using a confirmed, official number on record.

Despite existing legislation, such as the Cybercrimes Act, victimization rates continue to climb year on year. Prof. Mtuze clarified that the issue is not necessarily a lack of laws or insufficient police services, but rather a critical need for increased capacity and education within law enforcement agencies. He stressed that government investment must focus on training officials to understand electronic crime, properly collect digital evidence, and successfully prosecute these cases in court.

Beyond the digital realm, consumers remain highly vulnerable in physical spaces. Prof. Mtuze pointed out that individuals routinely hand over sensitive personal information, such as ID numbers, when signing into gated communities, office buildings, or job interviews, often leaving this data exposed in open logbooks.

He reminded the public that under the Protection of Personal Information Act (POPIA), individuals are the owners of their personal data and have the right to refuse handing over unnecessary details like ID numbers. Responsible parties collecting this data have a positive legal duty to keep it safe and confidential. To address these physical vulnerabilities, the Information Regulator has recently released a proposed code of conduct for comment, specifically guiding gated communities on how personal information must be collected, handled, and protected to prevent misuse.

As the anonymity of the online space continues to embolden cybercriminals, Prof. Mtuze concluded that a collective mindset shift is essential. Both consumers and institutions must recognize that the crimes occurring in the physical world are now mirrored, and often amplified, in the digital space.

 

Related Articles

Latest Articles