Your email is the master key to everything else. Banking apps, SARS eFiling, POPIA consent records, supplier invoices, password resets for every other account you own. If a threat actor owns your inbox, they own the door to all of it.
In 2025, South African banking fraud losses climbed to R3.9 billion, up 23% on the previous year, according to SABRIC. The single largest driver is phishing, which made up 52% of all cyber threats in the country in 2025, against a global average of 28% (Intelligent CIO Africa, October 2025). Most victims have no idea anything is wrong until money has already moved.
Dr Sandy Kalyan, writing in The Post this week, described finding out the hard way. Three red flags she missed over four days. Her email had been silently rerouted. Keyword filters had been planted so her attackers were alerted every time she typed words like "bank," "invoice," or "receipt." A new forwarding address, just the letter "n," sat quietly redirecting her messages.
She is not unusual. Ryan, the service provider consultant who helped her, said he handles at least a dozen calls like hers every day.
What the red flags actually look like
The problem with email compromise is that it is designed to be invisible. Here are the signs most people miss.
Mailbox-full warnings you did not cause. If your storage fills up without you sending or receiving large files, someone may be using your account to blast phishing emails to your contact list.
A PIN or OTP that never arrives. You request a one-time password from your bank or streaming service, but nothing comes through. A threat actor may have set up a filter that intercepts and deletes those messages before they reach you.
A password change you did not make. Your account holder, spouse, or IT administrator gets an SMS about a password reset. You made no such change. That is a confirmed compromise. Treat it as one immediately.
Unexpected sent items. Check your sent folder right now. If you see emails you did not write, the account has been used in your name.
What attackers plant once they are inside
This is the part most people do not know about. Getting your password is step one. What a sophisticated attacker does next is set up rules that make the access persistent and hard to detect.
In Dr Kalyan's case, 43 keyword filters had been planted in her account. Words like "bank," "invoice," "receipt," and "pro-forma statement." Every time she used those words, the system flagged the email and the attacker received an alert. They were not just passively reading her mail. They were waiting for specific conversations to intercept.
This is called a mailbox rule attack. It is common, it is quiet, and it survives a password reset if you do not know to look for it.
What to do if you suspect your email has been compromised
Work through these steps in order. Use a clean device, ideally a phone that has not connected to the same Wi-Fi as your compromised machine.
- Change your password immediately using a device you trust.
- Go to your email settings and check rules, filters, and forwarding addresses. Delete anything you did not create.
- Check your sent folder and your deleted items. Document what you find with screenshots.
- Enable two-factor authentication using an authenticator app or biometric, not just a PIN.
- Contact your bank to flag the compromise. Even if your banking apps appear untouched, the bank needs to know.
- Warn your contacts. If your sent folder shows outbound phishing emails, the people you work with may already have received them.
- If you handle client data under POPIA, assess whether the compromise qualifies as a reportable breach. Fines run to R10 million. The Information Regulator can be reached at inforegulator.org.za. For a plain-language walkthrough of section 22 timelines, see our POPIA data breach notification guide.
Why a password reset alone is not enough
This is what catches most people out. Resetting your password stops the attacker from logging in again. It does not remove the keyword filters, forwarding rules, or secondary email addresses they have already planted. They keep access through those rules even after the password changes.
After a reset, you must audit every setting in your account. Rules. Filters. Forwarding. Delegate access. Recovery email addresses. Secondary phone numbers. All of it.
The good news
Dr Kalyan's banking apps were not compromised. Catching it early mattered. The attacker had access for four days. Long enough to plant the filters, not long enough to move money.
You do not have to be technically skilled to catch this early. You just have to know what to look for. A mailbox-full warning you cannot explain. A password reset SMS you did not trigger. A streaming app OTP that never arrives. These are the signals. They are easy to dismiss as server errors. They almost never are.
What this means for South African businesses
If you run a business and one of your team's accounts gets compromised, the damage spreads fast. Invoices to clients get redirected to attacker-controlled bank accounts. Suppliers get phishing emails from a domain they trust. The classic Business Email Compromise loss in South Africa is six figures, and most of it is unrecoverable once the funds have moved.
For a look at how this plays out locally, see our case study on how a Durban accounting firm nearly lost R380,000 to a Business Email Compromise attack.
If you want to know whether your email environment is configured securely, our cybersecurity assessment covers exactly that. Half a day on site. It tells you exactly where you stand. R4,500. Book at /services/cybersecurity-assessment/.
Reach us at [email protected].
Sources
- Dr Sandy Kalyan: First-person account of email compromise, The Post (Published: May 2026)
- SABRIC: 2025 Annual Crime Statistics (Published: 2026)
- Intelligent CIO Africa: Phishing share of South African cyber threats (Published: October 2025)
- Information Regulator South Africa: POPIA Section 22 Breach Notification Guidance (Published: 2024-2026)
- South African Government: Protection of Personal Information Act 4 of 2013 (Published: 2013)
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za