Cybercrime

R903,000 gone in 10 minutes: Small business takes on Standard Bank

An alleged cyberfraud that saw a company’s account cleared out is headed to the high court

When Tanks Connected administrator Jenny-Ann Herholdt sat down at her computer on the morning of November 24 2023 to process the company payroll, she wouldn’t have believed that the small storage-tank business’s bank account would soon be completely drained.

As she tells it, she received a one-time PIN at 11.35am and logged into Standard Bank’s Business Online desktop platform. Only, the system was slow and she thought she had accidentally logged out, so she logged back in using a second OTP.

In the next few minutes, she was inundated with OTPs, receiving 11 in total.

“I found it difficult to load everybody’s salaries because I kept getting interrupted by OTPs. I just couldn’t believe that I was getting interrupted so much,” Herholdt says.

Concerned, she closed the platform and tried to log back in. This time, she was asked to complete a QR code verification — a method for which, she says, she had never been registered.

“I went out of the business platform and closed my laptop,” she says. “And I sent Sean [Gough], the business owner, a message asking him to check and release salaries.”

Gough checked the bank’s mobile app and discovered that the account had been cleaned out.

“I wanted to release the salaries and it said ‘insufficient funds’. That’s the first time I saw that the funds were out of the account. I couldn’t believe it … because we battle to release money from our account.”

In total, R903,000 vanished from the company’s account in 10 minutes. Of that, R902,500 was transferred into an account registered to cryptocurrency exchange AltCoin Trader, where it was converted into bitcoin and withdrawn from the platform.

Standard Bank refuses to reimburse a cent. In court papers, it maintains Tanks Connected’s transactions were effected after the company’s username and password — information known only by Tanks Connected — were entered with system-generated OTPs.

In a February 2024 internal risk management report, and in response to the FM’s questions, the bank suggests that the customer fell prey to social engineering or phishing.

Forensic investigations, regulatory gaps and high-stakes court filings tell a far more complex story.

Tanks Connected, which is based in KwaZulu-Natal, is now preparing for a David and Goliath high court showdown with Standard Bank. The company is suing the bank, along with AltCoin Trader, to recover its losses. The National Financial Ombud Scheme (NFOS) is cited as a third defendant, though Tanks Connected seeks no relief from it; it is joined only as an interested party.

Standard and AltCoin are defending the action and have delivered pleas.

In its court papers, Tanks Connected states that Standard Bank was obliged to maintain a reasonably secure electronic banking platform, to act only on properly authenticated instructions and to exercise the skill and care reasonably expected of a bank. It says the bank should have taken the steps provided for in its own contractual terms to reverse or prevent further unauthorised activity once it had been notified.

Standard Bank denies liability. The bank invokes its electronic banking terms and conditions, under which activity conducted after an access code has been entered is regarded as authorised by the client. It pleads that it was “not obliged to check the authenticity or integrity of any instruction” and that “it was not possible” for it to have reversed or frozen the allegedly unauthorised transactions.

Tanks Connected disputes that those terms relieve the bank of liability on the facts of the case. This will be for the court to decide when it hears the matter (pleadings have not yet closed and a trial date has yet to be set).

Following the money

Standard Bank’s own court papers track the alleged fraud. It admits in its plea that 11 OTPs were generated between 11.35am and 11.54am on November 24. It says they were sent to both the mobile number and the e-mail address registered for the account.

According to Standard, an “allegedly unauthorised” transfer of R500 was made to an Absa account at 12.13pm. Then came the first transfer to an AltCoin Trader account: R15,500 at 12.15pm. (The bank puts the figure at R15,000; both Tank and AltCoin have it as R15,500.) Seven minutes later, that money was withdrawn from the AltCoin Trader account, according to the bank.

Just a minute later — at 12.23pm — R887,000 was transferred to AltCoin. According to an AltCoin e-mail to Standard Bank, annexed to the bank’s plea, that R887,000 was converted into bitcoin and rapidly withdrawn: two withdrawals within eight seconds at 12.30pm and another at 12.42pm.

Herholdt had phoned Standard Bank’s fraud department at 12.39pm.

The banks are forcing you to put the apps on [your devices] because they’re closing their branches, and the apps are not secure
Laurie Pieters-James

Standard Bank argues that, given the compressed timeline, it could not have taken steps to secure the first amount, “could not reasonably have been expected to take steps expeditiously enough” to secure the balance of the R887,000 and could not have alerted AltCoin Trader in time to enable it to secure the funds.

AltCoin Trader, for its part, had advised the bank that the funds could not be secured as they were “utilised in the form of cryptocurrency where funds were used to purchase bitcoin and withdrawn from our platform”.

In its court papers, the crypto exchange pleads that it “at no time had possession or control” of the funds, which were credited to the account of one of its clients on its trading platform, and that it derived only transaction fees of about R3,000.

Tanks Connected disputes this, alleging that AltCoin Trader held the receiving bank account, internally credited its client’s account and controlled the conversion and withdrawal processes. Tanks Connected further alleges that AltCoin Trader, as an accountable institution under the Financial Intelligence Centre (FIC) Act, should have flagged the transaction and reported the matter to the FIC.

AltCoin Trader denies those allegations.

It declined to respond to the FM’s questions regarding whether it was investigating its platform user, whose credentials had allegedly been used to convert the transferred funds into bitcoin.

In a statement, AltCoin Trader says the matter is sub judice and “for that reason, we do not consider it appropriate to comment publicly on the merits of the matter, the allegations made, the evidence or our legal position”.

It adds: “Our decision not to comment is not an admission or acceptance of any allegation, factual proposition or legal contention, whether in your e-mail or in the underlying proceedings, and we ask that it not be reported or characterised as one.

“We reserve all of our rights in relation to the proceedings and in respect of any publication concerning this matter, including our rights in relation to any inaccurate, misleading or defamatory statements which may be published.”

In an effort to recoup its funds, Tanks Connected opened a case of theft and fraud with the police and filed a complaint with the bank and later with the NFOS.

Standard Bank’s internal fraud risk management department concluded that it “could not find any wrongdoing on the bank’s part” and that the credentials must have been compromised through phishing or some other method.

The bank tells the FM as much. In response to questions, it alleges Tanks Connected’s credentials may have been compromised via social engineering. Still, with the issue before the courts, it says it would be “inappropriate to publicly debate or disclose detailed forensic evidence, security architecture, investigative methodologies or other information that may become relevant in the litigation process”.

It does, however, add that the bank “employs multiple layers of security, authentication controls, fraud monitoring capabilities and transaction screening measures designed to identify and prevent suspicious activity”.

While it admits that cybercrime is evolving, it holds that it “increasingly focus[es] on manipulating legitimate users rather than attempting to penetrate banking systems directly”.

Tanks Connected denies that it fell for a phishing scam. It commissioned an independent forensic investigation of its own devices, its mobile telephone line and its e-mail domain, and Gough says the investigation found no evidence that the company or its staff had been compromised and that credentials were given away. 

Herholdt vehemently rejects the bank’s claim that she fell for a scam. “Could they explain which of the 11 OTPs I gave to somebody? It defies logic that that can be the explanation,” she says.

In an effort to find relief, Tanks Connected approached the NFOS, but the matter was shut down on jurisdictional grounds when the bank submitted proof that Tanks Connected’s annual turnover exceeds the ombud’s threshold for small businesses.

Herholdt argues this leaves small businesses defenceless, as most do not have funds for lawyers to take on the banks.

The police did not respond to requests for comment.

A hub for cybercriminals

The R903,000 that Tanks Connected lost is a drop in the bucket of the 110,074 digital bank fraud incidents in South Africa in 2025. According to data from the South African Banking Risk Information Centre released in August, banks’ reported losses from digital banking crime increased to R2.4bn in 2025, up from about R1.9bn in 2024. Banking app-related crime accounted for more than 70% of reported digital banking losses.

Tanks Connected’s losses are also a fraction of the R227m reported to the NFOS in 2025. Standard Bank customers reported 638 cases of digital fraud with losses of R65.46m, Absa’s clients reported 461 cases to the value of R62.87m and FNB clients reported 279 cases totalling R36.55m.

Rounding out the top six were Nedbank, with 275 cases valued at R22.68m, Capitec’s 441 cases valued at R22.21m and Discovery Bank’s 164 cases totalling R11.41m.

The data confirms what cybercrime experts have warned: that South Africa has become a hub for cybercriminals wise to the inherent weaknesses in the country’s digital banking system security, the relatively small size of cybercrime-fighting teams within banks and the police, and the criminal justice system’s apparent capture by criminals as highlighted during the Madlanga commission.

Laurie Pieters-James, founder of Cybareti Consulting Services, warns that systemic security vulnerabilities and underresourced defence units leave banking clients exposed.

“South Africa is becoming a crime hub for especially cybercrime … [criminals] know that the South African police have no capacity to investigate,” Pieters-James says. “If you look at the cyber units inside of the banks, there are two or three people. And how can two or three people manage crime? … They’re insufficiently staffed on cybersecurity. They’re not running optimal cybersecurity … and there’s a massive internal threat problem.”

The NFOS is monitoring the situation. NFOS banking and credit division lead ombud Nerosha Maseti says Tanks Connected’s case is consistent with the complaints about increasingly sophisticated cyberfraud being seen across the banking sector.

“These matters often involve social engineering, compromised credentials, digital authentication prompts and disputed authorisation. While the NFOS could not adjudicate this complaint due to jurisdictional limits, we continue to monitor such complaints for possible trends and systemic concerns and regularly report on complaints data to industry stakeholders and the FSCA [Financial Sector Conduct Authority],” she says.

She adds that the NFOS is aware of the evolving nature of financial crime and the impact that cyberfraud has on individuals and businesses.

“It is appropriate for the financial sector to consider whether existing dispute resolution mechanisms remain fit for purpose. Any change to jurisdictional thresholds would require engagement and direction from the relevant regulatory and governance structures.”

Still, Pieters-James says there’s significant exposure for consumers and businesses — particularly when combined with internal vulnerabilities at financial institutions.

“The banks are forcing you to put the apps on [your devices] because they’re closing their branches, and the apps are not secure,” she says. Pointing to internal threats, she adds that financial institutions fail to conduct ongoing lifestyle audits and repeat screenings on staff over time. “There are lots of internal threats in the banks … circumstances change, but the banks are not rescreening employees.”

To mitigate risks, Pieters-James advises business owners and consumers to compartmentalise digital exposure.

“Don’t bank on your phone that you use for everyday use. Get a silent SIM card that you never use for anything else and a separate phone. Put the apps on that phone and use it only for banking.” She also recommends keeping operational funds separate: “Keep only sufficient for operating costs in your account … put the rest of your money into a one-day notice account.”

Tanks Connected maintains that it upheld its end of the security bargain. It’s now for the court to decide the merits of the case.

In Related News