Johannesburg – South African businesses are facing an unprecedented rise in business email compromise (BEC) leading to fund transfer fraud (FTF), a form of digital fraud occurring far more often than ransomware despite receiving far less media attention.
As artificial intelligence (AI) gives cybercriminals new ways to infiltrate inboxes, manipulate payment workflows and deceive employees with machine-crafted precision, iTOO Special Risks and cybersecurity innovator Certra are urging organisations to rethink payment controls, supplier verification and insurance against increasingly deceptive attacks.
The companies have partnered to combine advanced cyber-defence intelligence with specialised commercial risk architecture, providing a unified view of how modern cybercrime exploits human behaviour, compromised communications and vulnerable financial processes.
Their warning to business is that BEC leading to FTF is now the most common cyber event affecting South African organisations, with AI accelerating its growth.
Andrew Henwood, co-founder and Director at Certra, said the shift is unmistakable.
“There’s been a significant increase in business email compromise leading to fund transfer fraud; it’s the most frequent incident we see and the same trend is reflected in global incident reports,” shared Henwood.
“We as cybersecurity professionals predict it’s only going to get worse, and a lot of that is due to AI.
“AI is weaponising threat actors.
“It’s enabling them to craft more convincing social engineering, analyse compromised inboxes at scale and insert themselves into payment-related conversations with machine‑level precision.”
Henwood notes that, unfortunately, ransomware dominates headlines but affects far fewer victims than the reality that payment diversion or fund transfer fraud is so prevalent.
Understanding the magnitude of the problem
“Traditional media is besotted with ransomware,” noted Henwood.
“But ransomware accounts for a very small portion of the money that ends up in fraudsters’ pockets.
“Business email compromise and funds transfer fraud are happening every day.
“People tend to know someone who’s been a victim, or they’ve been a victim themselves, in having an invoice forged and bank details changed.
“What they don’t understand is how big this problem really is.”
Lwando Cwane, Product Head: Cyber Underwriting at iTOO Special Risks, emphasises that the threat is universal.
“Business email compromise and funds transfer fraud are by quite a long way the most common cyber events we see,” Cwane said.
“AI is playing more and more of a role, enabling attackers to better craft their social engineering attacks.
“If they gain access to communications, they can filter through those a lot better.
“The whole attack landscape has become more fraught.”
Attackers typically compromise an email inbox without deploying malware, monitor for payment discussions and intervene just before a transaction.
They alter invoices or supplier banking details or impersonate the intended recipient.
Victims may then be tricked into calling the attacker to verify the fraudulent details and then make the payment.
Cwane added that the human element is central to the problem.
“On the personal side, we’re seeing high numbers of scams and payment fraud,” Cwane said.
“If you and I in our home life are not strong in identifying scams, how can we be in business life?
“That’s where the weaknesses really lie when it comes to a corporation.”
Why traditional verification checks are failing
Henwood warns that familiar verification methods, including call-backs, email confirmations, and bank account verification systems (AVS), are becoming less effective.
“Fraudsters know you’re doing those checks, and they’re using tricks to get around them,” Henwood stated.
“People think they’re doing the right thing, for example, by paying R10 to the purported recipient account.
“But the account belongs to the fraudster, who simply pays the R10 on to the real recipient.
“The real recipient sees the R10 arrive and confirms it, so everyone believes and is tricked into thinking the bank details are correct.
“The fraudster then receives the full payment.”
Henwood explained that the South African-born solution Certra provides a proven, automated payment protection platform that confirms a payment is going to the intended recipient, rather than a single check.
iTOO is preparing updated cyber policy wording to reflect the realities of AI-enabled fraud.
Henwood said the change marks a meaningful shift.
“iTOO is responding, and one of the big responses coming out is an adaptation of the policy wording to protect their policyholders,” Henwood said.
“It is accessible to everyday users, and the partnership with iTOO ensures we conquer risk so clients can focus on their full business potential.”
Cwane agrees that the industry must evolve.
“Insurance has to reflect the new threats and the evolving landscape. We need to give clients guidance on what they should be doing to protect themselves,” Cwane said.
Henwood concurred, saying: “If we can open people’s eyes to how common and damaging this crime is, they’ll understand why the insurance response matters, and why modernised safer payment processes are essential.”


