Fraud Alert: Standard Bank warns of a rise in spoofing; it’s harder to detect

In recent months, Standard Bank has seen a rise in spoofing scams, where fraudsters use AI-generated voices and emails to impersonate bank officials. These scams are increasingly difficult for customers to identify, as calls and emails appear to come from their banks’ legitimate contact details.

“With the rapid development of artificial intelligence (AI), we have seen an alarming enhancement in spoofing techniques,” says Adv. Athaly Khan, Head of Fraud Risk Management at Standard Bank. “Current scams look and sound more real than ever before.”

AI gives fraudsters access to advanced technologies like voice cloning, deep-fake videos, chatbots, and AI-generated phishing emails. This makes consumer awareness more critical than ever. “Stay safe, stay alert. Know what NOT to do, and what NOT to share,” adds Khan.

What is spoofing?

Spoofing is a deceptive tactic where criminals impersonate trusted entities, like banks by manipulating caller ID or email addresses to appear legitimate.

How it’s combined with vishing

In vishing scams, fraudsters call customers using what appears to be a valid Standard Bank number. The call mimics the tone and structure of a genuine bank interaction, often including standard security questions and disclaimers. To build trust, scammers may reference personal details such as birth dates, addresses, or account types. This information might seem harmless, but it is used to create credibility.

Typically, the caller claims to be calling about a service offering or to validate detected suspicious activity on the customer’s banking profile, such as unauthorized changes to their contact details. Once panic sets in, they offer fake solutions such as asking customers to transfer funds to a “safe” account, scan a QR code, click a link, or share sensitive information like One-Time-Pins (OTPs) or instant money voucher codes and pin.

How spoofing works in phishing emails

Phishing emails appear to come from a legitimate email from a bank employee and replicate the bank’s branding. These messages often use urgent, threatening tone to pressure customers into acting quickly. For example, they may claim that accounts have been flagged due to KYC or FICA compliance issues.

Usually embedded in these emails is malware hidden in links, attachments, icons, or QR codes. Clicking or scanning these elements can install harmful software to a customer’s device or redirect them to legitimate-looking fake websites designed to steal login credentials and card details. The emails typically impose tight deadlines, ranging from hours to a few days, to heighten anxiety and push immediate action.

What NOT to do:

  • Don’t transfer funds to another account on instruction. Your bank can secure your funds without your involvement.
  • Don’t generate instant money vouchers at someone else’s request. Authentication doesn’t require transactions.
  • Don’t click links, icons, download attachments, or scan QR codes from texts or emails. Standard Bank doesn’t send these via digital communication.

What NOT to share:

  • Never share login details, card expiry date, CVV (three digits on the back of your card), OTP, or ATM Pin.
  • Never disclose financial information like your investments or where you hold other financial products.
  • Never reveal your account details. You could unknowingly become a money mule.
  • Fraud is widespread and constantly changing. Scammers use fear and urgency to manipulate victims. Stay calm, think critically, and always remember what NOT to do, and what NOT to share.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

11,081FansLike
1,358FollowersFollow
4,893FollowersFollow
- Advertisement -

Latest Articles