The danger in online shopping usually isn't the big, obvious scam — the fake store with the too-good-to-be-true price is easy to spot once you know to look. The real risk hides in the small moments of convenience where you trade a bit of caution for speed, and that's exactly where South African shoppers get caught most often.
The marketplace listing that isn't from the marketplace
Facebook Marketplace and WhatsApp groups have become a normal part of how South Africans buy secondhand goods, and scammers know it. A common pattern: a seller with a convincing profile lists something desirable at a fair (not suspiciously cheap) price, builds a bit of back-and-forth trust, then asks you to pay via EFT "to hold it" before you've seen the item in person. Once the money moves, the seller disappears. The safeguard isn't distrust of the platform — it's a simple rule: never pay in full for something you haven't seen or collected, and treat "pay now to reserve it" as a request to skip the one step that actually protects you.
Delivery-notification phishing
If you've bought anything online in the last year, you've also probably received a text or WhatsApp message claiming to be from a courier, asking you to pay a small "customs" or "redelivery" fee via a link. These messages spike deliberately around high-shopping periods because scammers know a real delivery is plausible at that exact moment. The tell is almost always the payment request itself — legitimate couriers in South Africa don't ask you to settle outstanding fees by clicking a link in an SMS. If in doubt, go to the courier's own tracking page directly rather than through the message.
Card details on unfamiliar checkout pages
Not every unfamiliar online store is a scam, but every unfamiliar checkout page deserves a thirty-second check before you type in a card number: is the URL actually the store's domain, is the connection secure, does the store have any presence beyond the page you're on right now. Where it makes sense, a virtual card number or a low-limit card kept specifically for online purchases limits the damage if a store's checkout turns out to be compromised rather than just unfamiliar.
Account takeovers through reused passwords
A quieter risk than any of the above: many South African shoppers reuse the same password across retail accounts, banking apps, and email. When one retailer's user database leaks — and this happens more often than most shoppers realise — that password gets tried against everything else you own. A shopping account breach becomes a banking problem entirely because of password reuse, not because of anything you did wrong at checkout.
The habit that covers most of this at once
If there's one change worth making, it's building a short pause into the moment right before you pay — not out of anxiety, but as a deliberate checkpoint: is this seller or store one I can verify, is this payment method reversible if something goes wrong, and is this password one I've used anywhere else. That pause costs you ten seconds and closes off most of the ways online shopping actually goes wrong.