Businesses urged to tighten card security as fraud is on the rise

Photo: istockphoto.com

Business across South Africa are being urged to strengthen their payment security after Absa warned of an increase in card fraud targeting commercial banking clients.

According to the bank, fraudsters are increasingly exploiting business payment processes by targeting company cards used for in-store purchases, online shopping and supplier payments.

Businesses where multiple employees use the same card, or where cards are linked to recurring supplier payments, travel expenses or fuel purchases, are considered particularly vulnerable.

Absa said criminals are using a range of tactics, including phishing emails, fake merchant websites, social engineering, stolen card information and unauthorised transactions to gain access to business funds.

One of the fastest-growing threats remains so-called “card-not-present” fraud, where purchases are made online without the physical card being used. Criminals often obtain card details through phishing emails, fake payment pages, fraudulent phone calls, compromised websites or data leaks before using the information to make unauthorised purchases.

For businesses, this can result in fraudulent supplier payments, unauthorised online spending, misuse of company cards and financial losses that may be difficult to recover.

Absa is encouraging business owners to review how company cards are managed and to ensure that only authorised employees have access to them. Clear accountability should be in place for every card issued within a business.

The bank also warns businesses never to share card details, one-time passwords (OTPs), CVV numbers or banking credentials in response to unsolicited emails, text messages or phone calls, even if the request appears to come from a bank, supplier or service provider.

Businesses are advised to save card details only on trusted and verified merchant websites and payment platforms. Enabling transaction alerts and reconciling card activity daily can also help identify suspicious transactions, duplicate payments or unauthorised spending before signifi-cant losses occur.

Where possible, businesses should separate payment responsibilities by ensuring that different employees are responsible for initiating, approving and reconciling card transactions, particularly for high-value or recurring payments.

Absa further advises businesses to report any suspected card compromise, loss or unauthorised use immediately so that the card can be blocked and further fraudulent activity prevented.

With cybercrime continuing to evolve, the bank says strong internal controls, regular monitoring and ongoing employee awareness remain the best defence against increasingly sophisticated fraud attempts. (ANGELIQUE ERASMUS)