Banking31.01.2026

TymeBank fraud warning

South Africa’s largest digital-only bank, TymeBank, warns that remote access trojan (RAT) attacks are one of the fastest-growing and most dangerous scams targeting South African consumers.

According to Bonolo Sebolai, Head of Fraud at TymeBank, these scams rely on tricking customers into giving criminals direct access to their devices.

“RAT scams are particularly dangerous and extremely sophisticated because they are designed to use the device at the same time as the customer without any clear signs of a device takeover,” said Sebolai.

“The criminal doesn’t steal your login details but rather takes control of your device.”

Sebolai explained that RATs are a type of malicious software that allows a fraudster to remotely control a person’s phone or computer.

In South Africa, these scams typically start with a call or message claiming to be from a bank’s fraud or security department, mobile network provider, courier company, online retailer, or government department.

Victims are told there’s an urgent problem with their account, device, or expected service and are instructed to install an app or click a link, often sent via WhatsApp or SMS.

This leads them to install software on their device that supposedly solves the problem. Once installed, the scammer has full control over the customer’s device.

They can see the customer’s screen, capture PINs and passwords, intercept one-time passwords (OTPs), and even initiate banking transactions in real time.

“To the bank, it can look like the customer is making the transaction themselves because the criminal is actually using the customer’s own device,” said Sebolai.

Fraudsters exploit urgency, such as warnings that an account is “about to be blocked” or that a service can’t be delivered.

“These scams thrive on pressure and authority,” said Sebolai. “If you’re being rushed to act immediately, that’s one of your biggest red flags.”

Other red flags consumers should never ignore include requests to install software or apps to “fix” a problem, being asked to stay on the line while logging in, or instructions to approve transactions to “reverse fraud”.

A key rule: Your bank will never ask you to install remote access software or share your PIN or OTP.

Cat-and-mouse game

Bonolo Sebolai, Head of Fraud at TymeBank

As scams become more sophisticated, so must banking security, said Sebolai. “In 2026, bank-grade security means monitoring behaviour in real time, not just checking passwords,” he said.

“At TymeBank, we use real-time behavioural monitoring and risk-based controls to detect suspicious activity — even when fraudsters are using a customer’s own device.”

This includes real-time fraud detection and monitoring for unusual behaviour, such as signs of remote device control.

Sebolai said banks have adopted risk-based security that adapts to the situation and proactive alerts when something doesn’t look right.

Crucially, strong security shouldn’t create unnecessary friction. “The goal isn’t to make banking harder for customers,” he said. “It’s to stop criminals while keeping everyday banking simple.”

To avoid becoming a victim, Sebolai advised people to only download apps from official app stores. “And don’t be afraid to hang up and contact your bank directly if something feels wrong,” he said.

“You should act immediately if you suspect your device has been compromised.”

As digital banking grows, fraud attempts will continue, and Sebolai said awareness remains one of the strongest and most foundational defences.

“In banking, trust isn’t something you just say, but rather something you prove every day,” he said. “And that starts with keeping customers informed.”

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter