Digital banking fraud incidents in South Africa rose 86% in a single year, with banking apps now the dominant channel for these attacks, according to SABRIC's Annual Crime Statistics for 2024. Standard Bank now sits at the centre of three overlapping incidents that should worry every business and trust account holder banking with them, and most of the noise in the news is missing what these incidents have in common.
What is happening
On 20 May 2026, News24 reported that a flaw in Standard Bank's new online business platform allowed at least one client to gain unauthorised access to other businesses' accounts during migration to the new system. The bank has been moving business clients onto a refreshed Online Banking for Business platform in phases since October 2024, and Engineering News reported in February 2026 that more than 140,000 businesses had already been onboarded onto a system processing billions of rand a month.
That migration sits alongside two other problems. Standard Bank confirmed on 23 March 2026 that it had detected unauthorised access to select internal data, and by its 14 April 2026 update the bank acknowledged that client and company information had been published online. Daily Maverick reported on 17 April 2026 that a threat actor calling itself Rootboy claimed to have exfiltrated roughly 1.2TB of data from Standard Bank and its subsidiary Liberty, dumping files on the dark web after a ransom was refused. The published records reportedly included customer and company names, ID and registration numbers, contact details, bank account numbers, VAT numbers, and B-BBEE categorisation. Standard Bank has stated that its transactional banking and core operating systems were not accessed and that no client funds were affected.
The third strand is the most concerning for business clients. Daily Maverick's bank fraud series by Rebecca Davis, published in late March 2026, documented multiple cases where Standard Bank business clients lost large sums in hours after fraudsters allegedly migrated their profiles onto the Online Banking for Business platform, loaded beneficiaries the client had never seen, lifted payment limits, and processed transfers without the client receiving any one-time PIN messages. In one case the bank's own explanation was that the client's login credentials had been used to migrate her profile onto the business platform, after which user roles, permissions, and limits were set by the attacker.
Why this hits harder for SA business owners
Business banking profiles are not personal accounts with one signatory and a card limit, they are control panels with user roles, multi-user permissions, bulk payment limits, beneficiary lists, and accounting integrations. When a fraudster, or a system flaw, hands someone a working session inside a business profile, the damage is done at scale before the legitimate owner sees a notification. Trust accounts add another layer because attorneys, estate agents, and conveyancers are holding client money under Legal Practice Council and Estate Agency Affairs Board rules, with reporting duties to the Legal Practitioners Fidelity Fund that do not wait for a bank to finish its forensics.
Under POPIA, the responsible party that holds personal information has a duty to apply reasonable safeguards and to notify the Information Regulator and affected data subjects as soon as reasonably possible after a breach is detected. If your business is named in published data from the Standard Bank incident, or if you suspect your own systems may have been touched as a result, that obligation runs against you, not against the bank, for any onward exposure of your clients' information. Daily Maverick's reporting also raised a separate concern that the Information Regulator's own spokesperson Nomzamo Zondi confirmed: under Section 50 of the Promotion of Access to Information Act and POPIA Chapter 4, clients have a right to the forensic investigation records on their own accounts, and banks routinely refusing those records may not be acting in line with the law.
The local pattern is not isolated. Court records cited in Daily Maverick include a former Standard Bank administrator jailed for eight years in May 2025 for reactivating a deceased client's dormant account and loading beneficiaries, and a former Standard Bank IT operator who appeared in the Johannesburg Magistrates Court in January 2026 accused of altering account settings over nearly four years to expand his overdraft. SABRIC's own data, cited by Standard Bank, attributes the 2024 surge in digital fraud almost entirely to phishing, vishing, and social engineering rather than technical compromise, but that framing leaves business clients carrying the blame when a platform migration, an audit log they cannot see, and a confidentiality clause are part of the same picture.
What to do this week
If your business banks with Standard Bank, treat this as the cue to lock down your own posture rather than wait for the bank to finish its investigation. The same advice holds even if you bank elsewhere because the underlying patterns repeat across all of SA's major banks.
- Reconcile every business and trust account against your accounting records today. Pull the last 90 days of transactions, check every beneficiary still listed on the profile, and check the payment limits set on each user. If a beneficiary or a user looks unfamiliar, screenshot it first, then phone the bank from a number you trust.
- Audit who has access to your business banking profile. Remove ex-staff and ex-bookkeepers, demote anyone who does not need approval rights, and confirm that the OTP delivery point for every user is a phone number and email address the user still controls. The Online Banking for Business platform allows email fallback, and a compromised mailbox can authorise transactions on its own.
- Lock down the email accounts that approve payments. Turn on multi-factor authentication on the email service itself, not just the banking app, and review forwarding rules and connected applications for anything you did not set up. Most business banking takeovers begin in the mailbox days or weeks before the money moves.
- Write a one-page incident response checklist for your business and trust accounts. Name who phones the bank, who notifies the Information Regulator if client data is involved, who notifies the Legal Practitioners Fidelity Fund or relevant professional body, and who speaks to clients. Silence after an incident lets rumour and fake screenshots fill the space.
- If you have already lost money or access, request your forensic investigation report and audit logs in writing under POPIA and PAIA. Reference Section 50 of PAIA and POPIA Chapter 4. The bank's standard line that the report is internal and confidential is contested by the Information Regulator's own published position.
Where Ubuntu Guard fits
If you bank with Standard Bank for your business or trust account and you cannot tell whether your profile has been touched, if you have lost money you cannot trace, or if your details may be inside the data that was leaked online, that is the work we do. We treat it as a confirmed compromise until the evidence says otherwise, work from a clean device, and give you a plain-language report and a defensible response path that covers what POPIA requires you to do and by when. We speak human, not tech jargon. You can read how we work at our incident response service.
Had a breach or think you have been hit? WhatsApp us now, we respond fast. Otherwise reach us at [email protected].
Cybersecurity Made Simple
Sources
- News24, "Standard Bank glitch hands full account control to wrong clients", 20 May 2026.
- Daily Maverick, "Inside job — the fraud question South African banks won't answer" by Rebecca Davis, 25 March 2026.
- Daily Maverick, "The second ordeal — what happens when SA fraud victims fight back?" by Rebecca Davis, 24 March 2026.
- Daily Maverick, "Standard Bank is discovering the extent of the cyberattack in the daily data dumps", 17 April 2026.
- Standard Bank, "An Important Data Incident Update", 14 April 2026.
- ITWeb, "Standard Bank notifies clients of data breach", 8 April 2026.
- News24, "Standard Bank-owned Liberty warns clients after security breach", 23 March 2026.
- Engineering News, "Standard Bank continues to drive online business banking platform modernisation", 19 February 2026.
- SABRIC, Annual Crime Statistics 2024, released August 2025.
- Connecting Africa, "Standard Bank customer data leaked online", 17 April 2026.
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za