An email arrives saying your business banking profile must be updated today. The logo looks like your bank's. The link says "secure login." A WhatsApp message offers an unexpected tax refund. An SMS warns that a delivery will be cancelled unless you confirm details immediately.
These messages may be phishing, attempts to trick you into clicking a link, sharing information or making a payment. Phishing works because it looks ordinary. It arrives on channels you already use: email, SMS, WhatsApp and social media.
What phishing tries to do
Phishing is a method, not one fixed scam. The message is designed to make you act without thinking, by clicking a link, downloading a file, entering a password, sharing an OTP, approving a payment or revealing business information.
One click from one person can expose payment systems, email accounts and customer records.
Definition
Phishing
A scam where a criminal sends a message, by email, SMS, WhatsApp or social media, designed to trick you into clicking a link, opening a file, sharing security codes or revealing information that gives access to money or accounts.
The urgent banking "security update"
You receive an email that appears to come from your bank. It says your business online banking access will be suspended unless you verify your details within two hours.
The email includes a link to a page that looks like the bank's login screen. You enter your username and password. The page then asks for an OTP that arrives on your phone.
Later, you notice payments you did not approve. The email and website were fake. The scammer captured your login details and OTP.
Warning signs to recognise
Phishing messages often share patterns even when the story changes. Learning the patterns helps you pause before you click.
Be careful when a message creates panic or urgency, says your account will be blocked or closed, offers an unexpected refund, prize or tax repayment, asks for login details or an OTP, includes a link that does not match the real organisation's website, uses spelling or grammar that differs from official communication, comes from an unusual email address or phone number, includes an attachment you were not expecting or asks you to keep the request secret from colleagues or your bank.
Urgency and secrecy are especially common. Scammers want you to act alone and act fast.
Check before you click
When a message asks you to click, download, log in or share information, slow down. Phishing succeeds in seconds. Verification takes minutes.
Ask whether you expected the message. A bank will not usually email you out of the blue asking for your password. A supplier will not normally change banking details without prior conversation. If the request is unexpected, treat it as unconfirmed.
Check the sender carefully. Email addresses may look similar to real ones with small changes, an extra letter, a different domain or a free email service instead of the company's domain. On WhatsApp, check whether the number matches your saved contact.
Do not trust logos alone. Scammers copy them. If you need to log in or check an account, open the official app or type the website address yourself, do not use the link in the message.
Protect the whole business
Phishing is not only a problem for the business owner. Anyone who handles admin, customer messages, supplier payments or social media for the business can receive a convincing message.
Train staff, family members and partners who help with the business. Share the same rules: do not share OTPs, do not click unexpected links, verify changed banking details on a known number and report suspicious messages before acting. Not everyone needs login access to every system.
FAQ
Yes. Phishing uses any channel your business already trusts. Apply the same pause-and-check routine on WhatsApp, SMS and social media.
Scammers often include partial real details to seem credible. Still verify through an official channel before clicking or sharing codes.
If you clicked a suspicious link
If you clicked a link, opened an attachment, entered a password or shared an OTP, act quickly. Do not continue using the suspicious message or website.
Disconnect from the network if a file is downloading or something unfamiliar is installing. Change passwords for affected accounts, starting with banking and email. Contact your bank immediately if banking details or approvals were involved. Check account activity and recent beneficiaries. Warn staff or partners. Save evidence, the message, link, sender details and screenshots. Report the incident through your bank, insurer or relevant authority.
A common mistake
The most common mistake is clicking links in messages that create urgency before checking the sender. "Act now" messages are designed to bypass your normal caution. Another mistake is assuming phishing only happens by email, WhatsApp and SMS are equally common in South African business life.
Your next step
Before your next busy day, save official contact numbers for your bank, insurer and main suppliers in your phone, separate from any message that arrives unexpectedly. Use those numbers when a message feels wrong.
Keep learning
The final topic in this hub explains the first steps to take when you suspect that fraud has already happened.
Knowing how to spot phishing reduces risk. Knowing how to respond when something goes wrong limits further damage.