Quick answer: use this route first
The three names describe the same fraud arriving by three routes. Phishing comes by email, smishing by SMS or messaging app, and vishing by phone call. The goal is always the same: a credential, a payment, or access to your device. If you have already responded, phone your bank on the number on the back of your card, then report to SAPS on 10111. Verified 18 August 2026.
The three routes and what each exploits
| Name | Arrives by | What makes it work | The check that defeats it |
|---|---|---|---|
| Phishing | A convincing sender name and a linked login page | Read the domain after the @ and never sign in via a link | |
| Smishing | SMS or messaging app | Lands in a real thread; short messages hide detail | Type the organisation’s address yourself |
| Vishing | Phone call | Caller ID can be set by the caller; pressure works live | Hang up and dial the number on your card |
Vishing is the most dangerous of the three because it runs in real time. An email can be re-read and a message forwarded to someone sceptical, but a caller controls the pace, supplies the reassurance and keeps you talking until the transaction is done.
Why these are hard to spot now
The traditional advice about spelling mistakes and clumsy grammar no longer separates real from fake. Several things have changed.
- The language is clean. Poor wording was never essential to the fraud, and its absence proves nothing.
- They know real details about you. Your name, ID number, account number or a recent purchase can come from a data breach. Knowledge is not authentication.
- The channels are spoofable. Sender names, caller IDs and display pictures are all set by the sender.
- They arrive when expected. A delivery message during a week you ordered something, or a bank alert after a real transaction, is timed to be plausible.
Because none of the surface signals is reliable, the only durable defence is procedural: never act inside the channel that contacted you. Leave it, reach the organisation independently, and continue there.
The three requests that end the conversation
- A one-time password. It authorises a transaction. Reading it out is the transaction.
- Moving money to a safe account. No bank has holding accounts for customers, and none will ask you to transfer your own money to protect it.
- Installing an app so someone can assist. Remote-access software hands over the device and the session.
Any one of these is sufficient on its own. You do not need to work out whether the rest of the story is true.
Official reporting channels
| Body | Contact | What it handles |
|---|---|---|
| Your bank | The number on the back of your card | Blocking accounts, attempting a recall, first priority |
| SAPS | 10111, or any station | The criminal case and case number |
| SAFPS | 011 867 2234, [email protected] | Protective Registration, free, if ID details were exposed |
| ICASA | 012 568 3000, [email protected] | Licensed telecoms provider conduct |
| FSCA | 0800 203 722 | Financial institution market conduct and FSP checks |
| National Financial Ombud | 0860 800 900 | Unresolved bank disputes, after the bank’s process |
What information to prepare
- The email address, number or link used to contact you, copied exactly.
- The date and time of the contact, and of any transaction that followed.
- Precisely what you disclosed. Whether an OTP was given changes what your bank does next.
- Screenshots or the original email with its headers, kept rather than deleted.
- Your account or reference number with the organisation impersonated.
What not to share
- One-time passwords, PINs, card CVV numbers and banking login details.
- Remote access to any device.
- Identity documents to a channel you did not verify independently.
- Payments to a personal bank account, or in cryptocurrency.
- Confirmation of a transaction you did not start, however it is described.
If the issue is not resolved
Lodge a written dispute with your bank rather than relying on a phone call, quoting your SAPS case number and stating exactly what was disclosed and when. If the bank’s own process does not resolve it, the National Financial Ombud handles unresolved banking disputes once that process is exhausted, subject to jurisdiction. Where a licensed telecoms provider is involved, ICASA is the route after the provider has had its opportunity. Outcomes depend heavily on how quickly the bank was told, and no route guarantees recovery.
Related contact pages
- Fake Bank SMS And Call Scams South Africa: the banking version in detail.
- How To Check If A Phone Number Is Official: the verification method in full.
- Verify Contact Details South Africa: checking emails, domains and banking details.
- What Not To Share With Customer Care: the credentials no agent needs.
- Report A Scam South Africa: which body handles which loss.
Frequently asked questions
What is the difference between phishing, smishing and vishing?
Only the delivery route. Phishing arrives by email, smishing by SMS or messaging app, and vishing by phone call. The objective is identical, so the same defence applies to all three: leave the channel that contacted you and reach the organisation independently.
The message had no spelling errors and knew my account number. Is it real?
Neither tells you anything. Clean language is normal now, and personal details circulate through data breaches. Knowing something about you is not proof of who they are.
What information should I prepare?
The address, number or link used, the date and time, precisely what you disclosed, screenshots or the original email with headers, and your account reference with the organisation impersonated.
What should I do if I cannot get help?
Put the dispute in writing to your bank with your SAPS case number, and escalate to the National Financial Ombud on 0860 800 900 once the bank’s process is exhausted, after confirming your matter falls within its mandate.
Last verified 18 August 2026. Reporting routes confirmed on saps.gov.za, safps.org.za, icasa.org.za, fsca.co.za and nfosa.co.za.