Phishing in 2026: why South African inboxes are still the weakest link | Liyatech Solutions

Security

Phishing in 2026: why South African inboxes are still the weakest link

Cyber Security Team·August 2026

Most cyberattacks against South African businesses still start in the same place they always have — the inbox. What's changed is how convincing that first email has become.

Email remains the entry point for the overwhelming majority of attacks against South African organisations. What used to be a badly-worded message asking you to "verify your account" has become something far harder to spot on sight.

What today's phishing actually looks like

Generative AI has removed the tell-tale signs staff were once trained to look for — the odd phrasing, the spelling mistakes, the generic greeting. Modern phishing emails are personalised, grammatically clean, and can be produced in minutes rather than hours. Attackers have also broadened beyond email itself: fake QR codes, SMS-based smishing, and voice-based vishing calls impersonating a senior colleague are all now part of the same campaign, often arriving within days of each other and referencing the same fabricated "urgent" scenario.

The gap most businesses don't know they have

A large share of organisations still haven't properly configured DMARC, SPF and DKIM — the technical controls that stop someone from sending an email that appears to come from your own domain. Without them, a well-crafted spoof of a supplier or an executive slips through looking exactly like the real thing, because nothing at the mail-server level is checking whether it's allowed to claim your domain at all.

The controls that catch it before staff have to

Good email security doesn't rely on someone noticing something felt "off." Domain authentication stops spoofed sender addresses before they reach an inbox. Advanced filtering flags anomalies in sending patterns, not just known-bad senders. Multi-factor authentication means a stolen password alone isn't enough to get in, closing off the single most common outcome of a successful phish. Layered together, these controls take the decision out of a tired employee's hands on a Friday afternoon.

Where people still matter

Technical controls catch what they're built to catch, but business email compromise — a convincing request to change banking details or rush a payment — often has no malicious link or attachment to flag at all. That's where a simple habit like verifying unusual payment requests by phone, on a known number, closes a gap no filter can. It's also why phishing and staff awareness sit so close together in practice; see our piece on Security Awareness Training that actually changes behaviourfor how we build that habit properly.

The best-crafted phishing email today has no spelling mistakes, no odd phrasing, and no reason to raise an eyebrow. That's exactly why the filtering has to happen before it reaches anyone.Liyatech Cyber Security Team

Keep reading

_____


Staff Training

Security awareness training that actually changes behaviour

Read more
Security

What managed detection and response actually catches (that antivirus doesn't)

Read more
Incident Response

Incident response planning: what to do in the first hour

Read more