A Microsoft researcher spent months explaining why scam emails were so badly written, and the answer was that scammers wanted them that way. That trick worked for over a decade because clumsy wording cost a criminal nothing to produce and filtered out anyone sharp enough to be a waste of time. SABRIC has spent 2025 and 2026 warning South Africans that artificial intelligence has removed that cost, and the messages landing in local inboxes now read as clean as a text from your own bank.
What is happening
In 2012, Cormac Herley of Microsoft Research set out to answer a question that had puzzled people for years: why does a Nigerian prince email still claim to be from a Nigerian prince, when everyone knows the scam by name? Herley modelled the attacker's problem as a numbers game rather than a writing problem. A scammer working a low-density pool of realistic victims cannot afford to waste time on people who will never pay, so the badly written email does the sorting for him. Anyone with enough judgement to spot the trick reads it, laughs, and moves on for free. Only the reader with the least resistance left writes back, and that reply is the only one worth the scammer's time. Herley found that shrinking the pool of realistic victims tenfold could shrink the number caught more than a thousandfold, which is why the filter mattered so much that scammers kept it deliberately crude.
That filter depended on one thing: good writing cost the scammer time and skill he did not have, so bad writing was the cheaper, more profitable option. Generative AI has taken that cost away entirely. A criminal can now produce a phishing email, an SMS, or a WhatsApp message that is grammatically flawless, contextually specific, and formatted exactly like the institution it is impersonating, in seconds and at no meaningful cost. The filter Herley described has not disappeared. It has simply stopped requiring bad writing to work, which means the messages reaching the most cautious, literate readers are now polished enough to get past them too.
Why it hits harder here
SABRIC's own 2024 Annual Crime Statistics, released in August 2025, showed digital banking fraud cases more than doubling in a single year, from 31,612 in 2023 to 64,000 in 2024, with losses climbing from R1 billion to over R1.4 billion. Digital banking is now the channel behind the majority of reported fraud in the country. Layered onto that trend, SABRIC has repeatedly flagged AI-written phishing, cloned WhatsApp accounts impersonating known contacts, and voice-cloned calls impersonating bank officials as the tools now driving that surge, and has said plainly that these messages are designed to appear as legitimate as the real thing.
One pattern deserves specific attention for KZN business owners: business email compromise, where criminals intercept a genuine conversation between a business and its supplier, then quietly swap the banking details on an invoice before it reaches the customer. A South African fraud specialist confirmed in June 2026 that AI is making these swapped-detail scams harder to catch, because the surrounding email thread and tone are the criminal's own reply, not a fabricated message dropped in from nowhere. Under POPIA, a business that processes client or supplier personal information on a compromised mailbox carries the responsibility to apply reasonable safeguards and, where a breach is confirmed, to notify the Information Regulator and affected data subjects. "We didn't notice because it looked exactly like our supplier" is not a defence POPIA recognises, and it will not satisfy a client who lost money because your invoice was the one that got intercepted.
What to do this week
- Stop grading a message by its spelling. Retrain the instinct in yourself and your staff. A clean, professional-sounding message is no longer evidence that it is genuine, and treating it as such is now the riskier habit.
- Confirm through a number or app you already trust, never one supplied inside the message. If a message asks you to click a link, call a number, or update a banking detail, verify it through a channel you saved yourself, not one the message conveniently provides.
- Call the supplier directly before paying any changed banking detail. Use the number on file from a previous invoice or your own records, not the number printed on the new one. This single habit closes most of the business email compromise cases reported in South Africa this year.
- Turn on multi-factor authentication for every mailbox that touches invoices or payments. A compromised inbox is how most of these threads get intercepted in the first place, and MFA is the cheapest control against it.
- Brief your team on the new tell. Urgency, a request to bypass a normal process, or pressure to act before verifying is now a stronger warning sign than a typo ever was.
Where Ubuntu Guard fits
If you have ever wondered whether an email, invoice, or WhatsApp message your business received was genuine, that uncertainty is worth resolving properly rather than guessing. Our cybersecurity assessment looks at your email security controls, how invoices and banking details move through your business, and where a compromise like this could slip through. The report is plain language, and the fix list is prioritised so you know what to close first.
Think your business email could be faked? WhatsApp us and we will check it for you: wa.me/27791595040
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za