South Africa recorded 4,571 kidnapping cases in 2025, a 6.8% rise on the year before, and research from the Global Initiative Against Transnational Organised Crime shows the majority of victims are not wealthy individuals. They are ordinary people who made themselves easy to find. Criminals profiled them through social media posts, location tags, school uniform photos, and the kind of casual digital breadcrumbs most of us drop without thinking twice. The physical threat and the digital one have converged, and the bridge between them is information.
Two concepts from the world of professional security address this directly: OPSEC (Operational Security) and threat modeling. Both sound like they belong in a classified government briefing. They do not. Once you understand what they mean in plain terms, you will use them every week without thinking about the names.
What is OPSEC
OPSEC was developed by the US military in the 1960s as a way to stop enemies from piecing together sensitive plans from small, unclassified details. A soldier's letter home mentioning bad weather and jungle terrain told anyone listening roughly where that unit was operating. No secret was shared. The picture emerged from the scraps.
That exact problem applies to every South African with a smartphone. You are not hiding classified operations. You are living your life, and your life, posted piece by piece, becomes a targeting document. OPSEC for ordinary people means getting deliberate about what information you put out, who can access it, and what picture it builds when someone puts it all together.
The key word there is deliberate. OPSEC is less about secrecy and more about intention. You are not trying to disappear. You are trying to make sure the wrong people cannot use what you share to find you, predict your routine, or impersonate someone you trust.
What a threat model is, and why you need one before anything else
A threat model is your personal answer to four questions: what do you want to protect, who might want it, what happens if they get it, and how much effort are you willing to put into stopping them? Every security decision flows from those answers, and the answers are different for everyone.
A 19-year-old student has a very different threat profile from a 45-year-old SME owner in uMhlanga who posts cars and travel regularly. A woman leaving an abusive relationship has different concerns from a contractor who works for a municipality. Security advice that ignores these differences is either too paranoid for most people to follow, or too relaxed to protect the ones who genuinely need coverage.
The reason to build your threat model first is simple: without it, you will spend effort protecting the wrong things. Most generic security advice tells you to worry about hackers in dark rooms running sophisticated attacks. For most South Africans, the real threat is closer, more opportunistic, and more interested in your daily routine than your passwords.
How to build your threat model in five questions
Sit down somewhere quiet and work through these honestly. There are no right answers, only honest ones.
1. What information about me is worth something to someone else?
Think broadly. Your home address, your employer, your car registration, your children's school, your daily route, your banking details, your relationship status, your travel dates. Also think about access: who can log into your email and from there reset every other account you own?
2. Who might realistically want that information?
Be specific. For most people the realistic list includes opportunistic criminals watching social media for soft targets, online scammers running phishing attempts or identity fraud, and sometimes people from their personal life. Very few ordinary South Africans face nation-state actors. Shape your defences around who is likely, not who is theoretically possible.
3. How would they get it?
Would they find it on your public Instagram? Would they phish you with a fake email? Would they intercept a package, follow your car, or social-engineer someone who works for your bank? The method matters because it tells you where to focus.
4. What is the worst realistic outcome if they succeed?
Financial fraud, physical robbery, identity theft, SIM swap, a stalker finding your home. Rank these by how bad they would be for you personally. The worst outcome shapes how hard you need to work on prevention.
5. What are you willing to change?
Security costs convenience. A private Instagram account is free. Running every app through a VPN is not for everyone. Be honest about what you will maintain consistently, because a security habit you drop after two weeks is worse than a moderate habit you keep forever.
Once you have worked through those questions, you have a threat model. Write it down. It does not need to be formal; a few bullet points on your phone's notes app is enough. The act of writing it forces clarity, and clarity is most of the work.
Why this hits differently in South Africa
In March 2024, OSINT.Industries published an analysis of South Africa's parliamentary website and found that hundreds of MPs had used their personal email addresses as public contact information. Using those addresses, researchers were able to pull together Google reviews from restaurants across the globe, fitness tracking data, entertainment platform accounts, and travel patterns, all publicly accessible and all building a detailed picture of each person's life. The report called it an operational security nightmare, and the individuals involved were not naive people: they were legislators, simply operating without any framework for thinking about what their data reveals when combined.
The same thing happens to ordinary South Africans daily, at a more granular level. IT News Africa's reporting in December 2025 on kidnapping trends noted that criminals use location-enabled photos, school uniform tags, and lifestyle content to profile potential victims before approaching. Digital banking fraud surged 45% in Q1 2025, according to TechCabal, with much of it enabled by information that targets had already made publicly available. Cell C's 2024 breach exposed roughly 7.7 million customer records including ID numbers, banking details, and SIM metadata, and that data feeds the kind of SIM-swap and impersonation fraud that starts with knowing a victim's phone number and ends with their bank account emptied.
The data leaking from other people's breaches is largely outside your control. The data you post yourself is not.
What to do now
These steps follow the order of your threat model. Do the first ones regardless of your answers. Go further based on what your model told you.
- Audit your social media as a stranger would. Log out and visit your own profiles. What can someone you have never met see? Your suburb, your car, your children's names and school, your employer, your rough income level, when you travel and where. Decide intentionally what stays public. Set everything else to private, and mean it: check that your settings applied correctly, because platforms change defaults regularly.
- Remove location data from photos before posting. Every photo your phone takes embeds GPS coordinates in the file unless you switch this off. On Android, turn off location in your camera settings. On iPhone, set photo location sharing to "Never" or select it manually per post. A photo of your braai in your garden should not come with a precise map reference.
- Lock your SIM with a PIN and activate number porting protections. SIM swapping, where a criminal convinces your network to transfer your number to a new SIM they control, is among the most damaging attacks in SA right now because your phone number is the recovery key for most of your accounts. Contact your network operator and add a PIN to any number porting or SIM swap request. It takes one call.
- Use a separate email address for financial accounts. Your shopping, social media, and newsletter subscriptions can share one address. Your bank, SARS, medical aid, and investment accounts should use a completely different one that you never use for anything else and never share publicly. When that address receives a phishing attempt, you know the sender already has data on you from somewhere.
- Build a family protocol for urgent contact. One of the most effective scams targeting South African families is the fake-emergency call: a criminal calls a parent claiming a child has been in an accident and demanding an immediate transfer. Agree on a family code word now, something absurd and unmistakable, that anyone can ask for if a call feels off. If the caller cannot produce it, hang up and call the supposed victim directly.
Where Ubuntu Guard fits
If you want to go further than a personal audit, a professional assessment maps your full digital exposure across devices, accounts, email infrastructure, and third-party access points you may not have considered. We work through it systematically and give you a plain-language report with a prioritised action list: what to fix this week, what to schedule, and what you can reasonably deprioritise given your specific threat model. You can read how that works at our cybersecurity assessment page.
See what else criminals are targeting in South Africa right now. Follow the blog or reach us directly at [email protected].
Cybersecurity Made Simple
Sources
- IT News Africa: "Oversharing on Social Media is fueling Targeted Kidnappings," December 2025. References Global Initiative Against Transnational Organised Crime (GI-TOC) kidnapping data.
- South African Police Service: Annual Crime Statistics 2023/24. Cited via ISS Africa and The Citizen, December 2024.
- OSINT.Industries / The Debrief: "Operational Security: Failure Within the South African Government," March 2024.
- TechCabal: "Cybercrime in South Africa is rising; here's why," April 2025. Digital banking fraud figures.
- Corbado / multiple sources: Cell C data breach coverage, 2024.
- Cliffe Dekker Hofmeyr: "Social media and AI: Legal risks and South Africa's response," March 2026. Deepfake and voice cloning cases in SA.
© 2026 Ubuntu Guard Cybersecurity | 21 Lighthouse Road, uMhlanga, Durban. South Africa
ubuntuguard.co.za