A voice note is no longer proof: AI impersonation fraud in South Africa

SHARE:
Finance professional checking a suspicious AI-generated voice call

A familiar voice, a recognised WhatsApp profile or a caller ID that appears to belong to a bank is no longer reliable proof of identity—and identity alone has never been proof of authority to make a payment. AI-generated voices, cloned emails and deepfake content allow fraudsters to imitate trusted people with unsettling accuracy. For South African businesses, the safest response is not better intuition. It is a payment process that assumes every urgent digital instruction may be false until independently verified.

That principle became starkly practical in a recent South African case. In June 2026, the National Prosecuting Authority (NPA) reported that approximately R21.55 million had been diverted from a company’s bank account after its financial manager received WhatsApp messages and a telephone call from people purporting to represent the bank’s fraud division.

According to the NPA’s public statement, the manager was instructed to approve electronic links supposedly needed to cancel suspicious transactions. The Financial Intelligence Centre later directed that funds in nine recipient accounts be frozen, and the Asset Forfeiture Unit obtained a High Court preservation order under section 38 of the Prevention of Organised Crime Act 121 of 1998.

The statement does not say that AI was used in that particular incident, and it would be wrong to suggest otherwise. It demonstrates, however, how quickly a convincing digital impersonation can produce a major loss. The risk is increasing: Standard Bank warned in March 2026 that criminals were combining spoofed calls, phishing and vishing with AI-generated voices, cloned emails and deepfake content.

The dangerous assumption: “I recognised the person”

Most payment controls ask the wrong question: “Do I believe this is the person I know?”

The better question is: “Has this payment instruction been authorised through a channel and process that a fraudster cannot reproduce merely by copying a voice, profile or email style?”

AI changes the quality of the deception, but not the underlying legal and operational problem. A fraudster may sound like a director, family member, client, supplier or bank employee. They may know the names of colleagues, refer to a real transaction and create a plausible reason for urgency. None of those features establishes authority.

A voice note should therefore be treated as information to verify, not as a payment mandate.

Is an AI-generated instruction a crime in South Africa?

Depending on the facts, ordinary fraud, theft, money laundering and offences under the Cybercrimes Act 19 of 2020 may apply.

Section 8 of the Cybercrimes Act criminalises an intentional misrepresentation made by means of data or a computer program that causes actual or potential prejudice. Section 9 deals with cyber forgery and cyber uttering: unlawfully creating false data, or passing it off, with intent to defraud and to another person’s actual or potential prejudice. An AI-generated voice recording, manipulated email or synthetic video may therefore be part of the evidence of an offence even though the Act does not use the modern term “deepfake”.

The technology does not create a legal vacuum. It creates a more difficult proof problem.

Can a voice note, email or WhatsApp message still be evidence?

Yes. South African law does not exclude evidence merely because it is electronic. Section 15 of the Electronic Communications and Transactions Act 25 of 2002 recognises the admissibility and evidential weight of data messages.

But admissibility is not the same as authenticity, and authenticity is not the same as authority. A court may need to consider how the communication was created, sent, stored and preserved; whether its integrity can be demonstrated; what surrounding records support it; and whether the apparent sender had authority to give the instruction.

That distinction matters well beyond criminal cases. It can affect contractual disputes, disciplinary proceedings, insurance claims, bank complaints and attempts to recover money from recipients or intermediaries.

Who bears the loss after an impersonation scam?

There is no automatic rule that the bank, employer, employee, supplier or professional adviser must carry the loss. Liability depends on the contracts, banking mandate, security warnings, payment process, representations made, control failures, causation and the steps reasonably available to each party.

In Edward Nathan Sonnenberg Inc v Hawarden, the Supreme Court of Appeal rejected a delictual claim arising from a R5.5 million business-email-compromise payment. On those facts, the claimant had reasonably available means to verify the banking details, and the Court declined to impose the broad legal duty contended for.

The judgment is not a licence for careless security. It is a warning against assuming that another participant will necessarily reimburse the victim. Prevention and immediate response remain critical, and liability must be assessed on the evidence of the particular incident.

What to do in the first hour

Speed matters because fraud proceeds are often moved through multiple accounts. Recovery is never guaranteed, but delay can close the available window.

1. Contact the bank through an independently verified channel

Use the bank’s official fraud number, banking application or a number already held in verified records. Do not call a number supplied in the suspicious message. Ask the bank to stop, recall or trace the transfer, flag recipient accounts and preserve relevant logs.

2. Secure the compromised systems

Change credentials, terminate unknown sessions, enable stronger authentication and isolate affected devices or accounts. If the incident may involve a company network, obtain appropriate technical assistance without wiping evidence.

3. Preserve the evidence in its original form

Keep the original phone, emails, messages, audio files, call logs, banking notifications, URLs and payment records. Record the exact timeline and the names of everyone involved. Screenshots are useful, but they should supplement rather than replace the original data.

4. Report the incident

Open a criminal case with SAPS and provide a coherent evidence pack. Notify affected financial institutions and relevant insurers promptly. A cyber or fidelity policy may impose strict notification and cooperation requirements.

5. Obtain urgent legal advice where the amount is material

The available measures may include urgent civil relief, disclosure processes and steps to trace or preserve assets. POCA preservation proceedings are state-led processes; a private victim cannot simply obtain an NPA preservation order on demand. The appropriate civil and criminal routes must be assessed quickly and separately.

For a fuller action sequence, see SD Law’s guide to an EFT scam in South Africa.

The evidence pack your lawyer, bank and investigators will need

Assemble, without editing the originals:

  • proof of payment and bank statements;
  • the full email or messaging thread, including headers where available;
  • original audio, video and image files;
  • call logs, telephone numbers, profile details and URLs;
  • the genuine payment mandate and internal approval policy;
  • a list of every person who acted on or saw the instruction;
  • a minute-by-minute incident chronology;
  • correspondence with the bank, recipient bank, SAPS and insurer; and
  • any technical report identifying account compromise, spoofing or manipulation.

Do not circulate suspected deepfake material more widely than necessary. Uncontrolled forwarding can alter metadata, compromise an investigation and expose personal or confidential information.

A payment protocol designed for the deepfake era

Training staff to “spot a fake” is not enough. Good synthetic media may be convincing precisely because it contains none of the obvious errors people are taught to look for.

Businesses should instead make the instruction powerless until a separate control is satisfied:

  1. No payment based only on email, WhatsApp, voice or video. Treat every digital instruction as unverified.
  2. Call back on a pre-approved number. Do not use the number or link contained in the instruction.
  3. Require dual approval above a sensible threshold. Separate the person creating a payee from the person releasing the payment.
  4. Verify every change of banking details. Use a known contact and a second channel.
  5. Introduce a cooling period for new beneficiaries. Urgency must not override verification.
  6. Use an agreed challenge question or transaction reference. It should not be discoverable from social media, email history or public records.
  7. Set realistic payment limits and alerts. Controls should make an unusual transaction visible before funds leave.
  8. Rehearse the incident response. Staff must know who can call the bank, who preserves evidence and who makes the legal and insurance notifications.

The provocative but necessary conclusion is this: trust should remain human, but authority must become procedural.

Frequently asked questions

Can AI voice cloning be used to commit fraud in South Africa?

Yes. If a synthetic voice or other data is used intentionally to make a false representation and cause actual or potential prejudice, the conduct may support charges including fraud and offences under the Cybercrimes Act, depending on the facts.

Is a WhatsApp voice note legally binding?

Not automatically. Electronic communications can have legal effect and may be admissible in evidence, but the sender’s identity, intention, authority, authenticity and the surrounding agreement still matter.

Will the bank refund money lost in an impersonation scam?

Not necessarily. The result depends on the banking mandate, how the payment was authorised, the bank’s and customer’s conduct, notification timing and the contractual and legal framework. The incident should be reported immediately and assessed on its facts.

Can a lawyer freeze the recipient’s bank account?

A lawyer can assess and pursue appropriate urgent civil remedies and engage with banks and investigators. POCA preservation orders are pursued by the state through the NPA’s Asset Forfeiture Unit. No freezing or recovery outcome can be promised.

What is the most important preventive control?

Independently verify every payment instruction—especially new beneficiaries or changed banking details—through a pre-agreed channel that is separate from the instruction itself.

When the voice is fake but the loss is real

AI impersonation fraud succeeds by exploiting ordinary trust and manufactured urgency. Victims should not be blamed for finding a sophisticated imitation convincing. But businesses should no longer build payment authority on recognition alone.

SD Law advises individuals and businesses on urgent fraud response, evidence preservation, cybercrime and commercial litigation. If a suspicious instruction has led to a payment or exposed confidential information, act before the trail goes cold.

This article provides general information and does not constitute legal advice. Fraud recovery and liability are fact-specific, and no recovery outcome can be guaranteed.

Previous post:
Disclaimer

The information on this website is provided to assist the reader with a general understanding of the law. While we believe the information to be factually accurate, and have taken care in our preparation of these pages, these articles cannot and do not take individual circumstances into account and are not a substitute for personal legal advice. If you have a legal matter that concerns you, please consult a qualified attorney. Simon Dippenaar & Associates takes no responsibility for any action you may take as a result of reading the information contained herein (or the consequences thereof), in the absence of professional legal advice.

Need legal assistance?

Request a free call back