Skip to main content

ASL – Expert Accounting Services

In today’s business environment, cyber security is often perceived as a technical issue managed by IT teams and external providers. In reality, most cyber incidents begin not with systems, but with people.

A simple email, message, or request can open the door to significant financial loss or reputational damage. This is why phishing remains the most common and effective cyber-attack method globally.

Recent data highlights how widespread the risk has become:

  • Over 90% of successful cyber-attacks start with phishing
  • Phishing is involved in up to 36% of data breaches
  • Approximately 3.4 billion phishing emails are sent every day

In South Africa, the risk is even more pronounced. Phishing accounts for more than half of all cyber threats locally.

Phishing does not rely on technical complexity. It relies on trust, urgency, and human behaviour. As such, every individual within an organisation plays a critical role in identifying and preventing it.

What is phishing?

Phishing is a method used by attackers to impersonate a trusted individual or organisation in order to:

  • Trick individuals into clicking malicious links
  • Obtain sensitive information such as passwords or banking details
  • Influence business decisions, such as approving a payment

The different types of phishing

  • Email phishing
    The most common form, typically involving urgent emails containing links or attachments.
  • Spear phishing
    Targeted and personalised messages referencing your business, role or responsibilities.
  • Business email compromise
    High-risk attacks involving fraudulent payment or banking requests.
  • Smishing
    SMS or WhatsApp-based phishing messages.
  • AI-enabled phishing
    More sophisticated, personalised, and difficult to detect phishing messages.

Why phishing still works

Phishing is effective because it exploits urgency, authority, and trust. Individuals often respond instinctively when placed under pressure, rather than pausing to verify legitimacy.

Why this matters during tax season

During tax season, phishing risks increase significantly as attackers exploit:

  • Financial deadlines
  • Expectations of official communication
  • Increased pressure on individuals and businesses

Cybercriminals frequently impersonate tax authorities, including SARS, using messages relating to refunds, audits, or outstanding submissions. They may also impersonate staff or directors from ASL (to confirm – impersonating without comprising ASL) as a trusted adviser or service provider, relying on the existing relationship with the reader as an ASL client to make fraudulent communication appear credible.

What you can do

  • Pause before acting on urgent requests.
  • Verify requests independently using trusted channels, such as a telephone call to the known contact person or organisation.
  • Recognise your role in cyber security.

Conclusion

Phishing remains one of the most effective cyber-attack methods because it targets human behaviour rather than systems. Organisations that successfully manage this risk are those that foster a culture of awareness, where individuals feel confident to pause, question, and verify.

About Cyberlogic

Cyberlogic partners with organisations to strengthen their cyber resilience through technology, processes, and user awareness.

Contact:
www.cyberlogic.co.za
hello@cyberlogic.co.za

We use cookies to improve your experience on our website. By continuing to browse, you agree to our use of cookies
X