In an era where “Agentic AI” can mimic voices and handle complex conversations, traditional security (like simple passwords) is no longer enough.
1. IDENTITY & VOICE AUTHENTICATION
Establish a “Safe Word”: Because AI can now clone voices with just a 3-second clip from a video, establish a “family or office safe word” for urgent financial requests made over the phone.
Be Skeptical of “Urgency”: If a colleague or “official” calls with a crisis that requires immediate fund transfers, hang up and call them back on their known, saved number.
2. EMAIL & DOMAIN SECURITY (SPF/DKIM/DMARC)
Verify your SPF Records: (As we did for straton.co.za). Ensure your organization’s domain is configured so that scammers cannot “spoof” your official email address to send fake invoices to donors.
Look for “Look-alike” Domains: Check for subtle typos in sender addresses (e.g., nmbcsc-org.za instead of nmbcsc.org.za).
3. TRANSACTIONAL SAFETY (THE “GOLDEN RULE”)
Two-Factor Everything (2FA): Use an Authenticator App (like Google Authenticator or Authy) rather than SMS-based 2FA. Scammers can “SIM-swap” your phone number, but they cannot easily steal an app-based token.
Confirm Bank Details: Never change banking details based on an email notification. Always confirm the change via a physical phone call to a verified representative.
4. AI & “PIG BUTCHERING” AWARENESS
The “Slow Play” Scam: Be wary of new “business contacts” or “volunteers” who spend weeks building a relationship on WhatsApp or LinkedIn before mentioning a “high-yield investment” or “crypto opportunity.”
AI Profiles: Use reverse-image searches on profile pictures. Often, these “volunteers” are using AI-generated faces that don’t exist in the real world.
HOW FRAUDSTERS MOVE THE MONEY
Understanding the “Laundering Lifecycle” helps you spot where a local scam might be plugging into a global network.
5. INCIDENT RESPONSE GUIDE
If you are compromised:
Freeze Accounts: Contact your bank’s fraud department immediately.
Report to the Hawks/SAPS: Get a case number for insurance and legal purposes.
Notify the Coalition: If the breach involves the Coalition’s data, you have a legal obligation under POPIA (Protection of Personal Information Act) to notify the affected parties and the Regulator.
