South Africa’s ecommerce sector has shown remarkable growth over the past few years. The Visa Retail Spend Monitor shows how South Africans have significantly increased their online shopping, particularly over the 2025/26 holiday season, with ecommerce spend up by 49.9% year-on-year. This is echoed by Trading Economics’ January to April retail trade data that shows continued growth across retail trade, especially across the categories most popular to household deliveries, such as household appliances and clothing. On the other side of the delivery chain is another success story as the South Africa Courier, Express and Parcel (CEP market report highlights an expected growth from $627.8 million in 2025 to $672.25 million in 2026.
This growth is also exactly what makes the sector an attractive target for scams. The ones riding on the back of this boom have moved past clumsy and easily spotted phishing attempts into coordinated operations. Attackers are timing their messages and mirroring real delivery workflows down to the smallest details, and these are having a serious impact on consumer safety and are putting immense pressure on organisations at the same time.
The starting point for all of these scams is the consumer, and it’s worth examining exactly what happens at that level before looking at what it costs the business behind the brand being impersonated. A fake delivery message, built to mirror a real one almost exactly, often asks the consumer to pay a small release fee that’s deliberately modest enough to minimise them pausing and thinking about it. When the consumer pays, attackers capture their card details and use them to perpetrate additional fraud. Each of these incidents carries the name of the real courier or retailer, whether they had any part in it or not.
For the courier and ecommerce organisation, this cost extends past financial loss. Credential theft and account takeovers are a direct risk to the company, and can be particularly damaging in ecommerce and banking-adjacent contexts. There is also the regulatory exposure under POPIA or, for global companies, GDPR, where the misuse of customer data can result in fines and deeper reputational harm. Once a company’s name has been used in a scam, the effects are difficult to reverse.
There are two ways courier companies can respond to this threat. On the consumer-facing side, they should use one communication channel consistently using a predictable format and cadence. So predictable, in fact, that anything unusual or unfamiliar will immediately be recognisable by consumers as something out of the ordinary. On the technical side, brand and domain monitoring are an excellent way of catching spoofed sites. Teams can then detect fake sites and communicate them to customers regularly and clearly, allowing them to make informed decisions when receiving falsified SMS’ or WhatsApps. Endpoint detection and response is also critical as this allows proactive malware detection and deflection, plus these tolls provide staff with mobile threat defences that can support them in the field. Multi-factor authentication remains a baseline control alongside a DNS and email filtering with AI-based detection, but the greatest defence remains the human in the loop. People are the biggest vulnerability in any organisation, so training and awareness across both employees and customers is essential to building both a robust security perimeter and providing consumers with ongoing visibility and support.
However, despite the risk and the complexity introduced by scammers within the courier ecosystem, there remains opportunity. The same growth that has made it a target, makes it worth defending. Companies that treat customers as part of the security and prioritise communication are not just reducing fraud losses, they are protecting trust and building reputational foundations. As online shopping and delivery volumes continue to climb, companies getting ahead of this threat can now lean into it and build for it, which puts them at a direct market advantage.
By Allan Juma, Lead Cybersecurity Engineer at ESET
About ESET
ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown, securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use.
ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defence and strong local support, we keep users safe and businesses running without interruption.
The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centres and a strong global partner network. For more information, visit https://www.eset.com/za/ or follow our social media, podcasts, and blogs.




