Every day when you log on to your banking site you expose yourself to a man in the middle attack [through SSL]. Sure, it's a lot more difficult to impliment but conceptually it's the same thing [in a way at least].
It's a risk we're all fairly comfortable to live with, since, not much can be done about it because at the end of the day, someone will still have access to whatever is being protected. The only safe way of dealing with information is not to tell anyone, not to write it down and not to need it. Clearly we need this, so in this instance we'd have to put our faith in Vodacom to minimize the risk of it happening again and to work with the SAPS [and others where needed].
More importantly I'm happy that the employee has been taken into custody and that he/she is ultimately held responsible for this fraud, to me, it's the positive in this case.