The phishing meaning most people know is a scam email, but the real definition is tricking a person into handing over access that no attacker could take by force. It is the most reported cybercrime in Africa, and it works because it targets judgement rather than software. This guide covers what phishing actually means, the variants that hit South African businesses hardest, why the old advice about spelling mistakes is now useless, and what POPIA requires of you within hours of someone falling for one.

What does phishing mean?

Phishing means sending a fraudulent message that impersonates someone the recipient trusts, in order to trick them into revealing credentials, transferring money, or installing malware. The name plays on fishing: the attacker casts bait and waits for somebody to bite.

The defining characteristic is that the target does the damage themselves. No firewall was bypassed. Nobody cracked a password. An employee received a message that appeared to come from a supplier, a bank or their own managing director, and did exactly what it asked.

That is what makes phishing structurally difficult. Every other attack class has a technical control that stops it. Phishing exploits the fact that businesses run on people acting quickly on instructions.

How a phishing attack actually works

A phishing attack runs in four stages, and only the last one is visible to the victim. Understanding the sequence explains why detection has to happen early.

Reconnaissance. The attacker learns who works where. LinkedIn supplies the org chart, the company website supplies the email format, and a supplier’s compromised mailbox supplies the invoice template.

Pretexting. A believable scenario gets built. The finance clerk receives a message about a genuine outstanding invoice, referencing a real project, from an address one character different from the supplier’s.

Delivery. The message arrives by email, SMS, WhatsApp or phone call, usually with time pressure attached. Urgency suppresses verification.

Exploitation. Credentials get entered on a convincing fake login page, or banking details get changed, or an attachment installs a remote access tool.

Stage four is where most businesses start paying attention. By then the account is already compromised.

What are the four types of phishing?

The four types most commonly distinguished are email phishing, spear phishing, smishing and vishing, separated by targeting and by delivery channel.

Type Channel Targeting Typical goal
Email phishing Bulk email Anyone Credential harvesting
Spear phishing Email, researched Named individual Access to a specific system
Smishing SMS or WhatsApp Broad or targeted Fake delivery or banking links
Vishing Voice call Targeted OTP or payment authorisation

Two variants deserve separate mention because they cost the most money. Whaling targets executives specifically, on the logic that a financial director can authorise a payment nobody will question. Business email compromise skips credential theft entirely and simply persuades finance to redirect a legitimate payment to the wrong bank account.

Interpol’s 2025 Africa Cyberthreat Assessment found online scams, particularly phishing, to be the most frequently reported cybercrime across Africa, with business email compromise widespread and scam notifications spiking by up to 3,000 per cent in some jurisdictions.

Why spotting a phish is harder than it used to be

The old advice about spotting bad grammar and misspellings is now actively harmful, because it teaches staff that a well-written message is a safe one. Generative AI removed the language barrier that once made foreign-origin fraud obvious to a South African reader.

What is left as a reliable signal is not the writing. It is the request.

Does the message ask you to do something with money, credentials or access? Does it apply urgency? Does it discourage verification through another channel, with phrasing along the lines of going into a meeting so please just handle it? Those three markers survive any amount of polish.

Sender addresses have become similarly unreliable. Display names are trivially spoofed, lookalike domains substitute a lowercase L for a capital I, and a genuinely compromised supplier mailbox sends real mail from a real address.

Teach the request pattern, not the typo. Staff who verify payment changes by phoning a number they already had will stop attacks that no filter catches. If you are building that capability inside a partner business, apply to become an accredited partner and get access to the vendor training behind it.

How to protect a business against phishing

Effective phishing defence is layered, because each control catches what the previous one misses. No single measure is sufficient, and any vendor claiming otherwise is selling.

Email filtering removes the bulk of it before anyone sees it. Products such as Barracuda Email Protection screen inbound mail for known-bad senders, malicious links and impersonation patterns.

Multi-factor authentication is the single highest-value control, because a stolen password alone stops being enough. It is not absolute, since attackers now relay MFA prompts in real time, but it eliminates the commodity attacks.

Verification procedure for anything financial. Any change to banking details gets confirmed by voice on a previously known number. Written into policy, not left to judgement.

Staff simulation. Send your own people realistic test phishes and train the ones who click. Repeat quarterly, because the click rate on an untrained workforce is far higher than any manager expects.

Least privilege. When an account is compromised, the damage is bounded by what that account could reach.

Backups you have restored from. Phishing is a common delivery route for ransomware, and an untested backup is a hope, not a control.


SELLING EMAIL SECURITY?
LOOPHOLD distributes and supports the email protection stack South African partners deploy against phishing.
See partner enablement


What to do if someone has been phished

Act on the account before you investigate the message, because every minute of retained access widens the damage. The order matters.

Reset the password and revoke active sessions, not just the password. An attacker holding a live session token is unaffected by a password change alone.

Check for mailbox rules the attacker created. Auto-forwarding and auto-delete rules are standard practice in business email compromise, and they hide the fraud from the account owner while it continues.

Look at what that account could reach: shared drives, finance systems, the customer database.

Warn anyone the compromised account emailed, because the attacker’s next move is to phish the contact list from a trusted address.

Then handle the legal obligation. Under section 22 of POPIA, a responsible party must notify the Information Regulator and the affected data subjects where personal information has been accessed or acquired by an unauthorised person. The Information Regulator publishes a prescribed notification form, and its guidance states that failing to use it may render the notification non-compliant.

That obligation is easy to miss in the scramble. A phished mailbox containing customer personal information is a reportable event, not merely an IT inconvenience.

Phishing sits inside a bigger picture

Phishing is one attack class among several, and defending it in isolation leaves the flanks open. The same layered thinking applies across the estate: controls at the perimeter, on the endpoint, around identity, and in backup.

Our guide to cyber security for South African businesses sets out the full model and how the layers interact. For teams who want the underlying technical grounding, SonicWall certification training covers the network side of the same problem.

One closing point. Every control listed here fails eventually against a sufficiently determined attacker. What determines the outcome is how quickly somebody notices and how well-rehearsed the response is.


WANT THE FULL SECURITY STACK?
Talk to LOOPHOLD about vendor accreditation and technical enablement for South African partners.
Start my partner enquiry


Pin It on Pinterest

Share This