Back to all articles

Banking App Safety: What South African Banks Actually Ask (and Never Ask)

Almost every successful banking scam depends on one thing: the victim believing the bank itself made contact. Here's what your bank will never actually ask for.

Almost every successful banking scam depends on one specific belief taking hold: that the bank itself made contact. Once that belief is in place, everything that follows feels reasonable to the person being scammed. Here's what South African banks actually do and don't do, so that belief is easier to catch and question.

What your bank will never ask for

  • Your full PIN or online banking password, over the phone, by SMS, or via email — ever, for any reason, including "verification" or "fraud prevention."
  • A one-time PIN (OTP) read out to someone on a call. An OTP exists specifically to confirm that you, and only you, are authorising a transaction. Anyone asking you to read one out is asking you to authorise something on their behalf — which is the scam.
  • Payment to a "safe account" to protect your funds from fraud. This specific script has become common enough to have a name: the caller claims your account is compromised and that moving your money to a new "secure" account will protect it. Banks do not do this. It is always a request to move your own money into the scammer's account.
  • Remote access to your device to "fix" a banking app issue, via a screen-sharing app the caller talks you into installing.

What legitimate bank contact actually looks like

Real fraud alerts from your bank are typically short, don't ask you to do anything on the call itself beyond confirming yes/no about a specific transaction, and never ask you to move money, share an OTP, or install anything. If a call ever creates pressure to act immediately, that urgency is itself a signal — genuine fraud teams work through your existing account safeguards, not through convincing you to bypass them.

The verification habit that closes almost all of this off

If you receive any call, SMS, or email claiming to be your bank and it asks you to do anything at all — click a link, confirm details, move money — hang up or close the message, and contact the bank yourself using the number on the back of your card or their official app. Never use a number or link provided in the suspicious message itself, since a convincing fake can provide its own "verification" number that just reconnects you to the scammer.

Securing the app itself

  • Enable biometric login (fingerprint or face) where your banking app supports it — it's both more convenient and harder to phish than a typed password.
  • Set transaction notifications on, so you see every movement on your account in real time rather than discovering something days later on a statement.
  • Never install your banking app from anywhere other than the official app store listing — fake banking apps that mimic real ones do circulate, usually pushed through links in phishing messages rather than found by searching.

The short version

South African banks have converged on the same core rule for a reason: they will never ask you to reveal a PIN, read out an OTP, or move money to protect it. Any message or call that asks for one of those three things is not your bank, regardless of how convincing the caller ID or the tone sounds.