In today’s business environment, cyber security is often perceived as a technical issue managed by IT teams and external providers. In reality, most cyber incidents begin not with systems, but with people.
A simple email, message, or request can open the door to significant financial loss or reputational damage. This is why phishing remains the most common and effective cyber-attack method globally.
Recent data highlights how widespread the risk has become:
- Over 90% of successful cyber-attacks start with phishing
- Phishing is involved in up to 36% of data breaches
- Approximately 3.4 billion phishing emails are sent every day
In South Africa, the risk is even more pronounced. Phishing accounts for more than half of all cyber threats locally.
Phishing does not rely on technical complexity. It relies on trust, urgency, and human behaviour. As such, every individual within an organisation plays a critical role in identifying and preventing it.
What is phishing?
Phishing is a method used by attackers to impersonate a trusted individual or organisation in order to:
- Trick individuals into clicking malicious links
- Obtain sensitive information such as passwords or banking details
- Influence business decisions, such as approving a payment
The different types of phishing
- Email phishing
The most common form, typically involving urgent emails containing links or attachments. - Spear phishing
Targeted and personalised messages referencing your business, role or responsibilities. - Business email compromise
High-risk attacks involving fraudulent payment or banking requests. - Smishing
SMS or WhatsApp-based phishing messages. - AI-enabled phishing
More sophisticated, personalised, and difficult to detect phishing messages.
Why phishing still works
Phishing is effective because it exploits urgency, authority, and trust. Individuals often respond instinctively when placed under pressure, rather than pausing to verify legitimacy.
Why this matters during tax season
During tax season, phishing risks increase significantly as attackers exploit:
- Financial deadlines
- Expectations of official communication
- Increased pressure on individuals and businesses
Cybercriminals frequently impersonate tax authorities, including SARS, using messages relating to refunds, audits, or outstanding submissions. They may also impersonate staff or directors from ASL (to confirm – impersonating without comprising ASL) as a trusted adviser or service provider, relying on the existing relationship with the reader as an ASL client to make fraudulent communication appear credible.
What you can do
- Pause before acting on urgent requests.
- Verify requests independently using trusted channels, such as a telephone call to the known contact person or organisation.
- Recognise your role in cyber security.
Conclusion
Phishing remains one of the most effective cyber-attack methods because it targets human behaviour rather than systems. Organisations that successfully manage this risk are those that foster a culture of awareness, where individuals feel confident to pause, question, and verify.
About Cyberlogic
Cyberlogic partners with organisations to strengthen their cyber resilience through technology, processes, and user awareness.