Due to a recent attempted cyber fraud incident involving our client, we thought it would be valuable to revisit this important topic. Over the past few years, we have seen a growing number of attempted cyberfraud incidents involving our clients. With the rapid rise in AI-driven tools, these attempts are becoming more sophisticated, more convincing, and far harder to detect. While we at Stone Wealth Management have implemented extensive safeguards to protect our systems, our clients may not have the same level of technical protection. For example, a fraudster could access a client’s email account and send a message that appears to come from Stone Wealth Management. While our email systems are secure, they cannot protect your personal inbox. Your email security is therefore just as important, and we have provided several practical suggestions below to help strengthen it.

A recent attempted cyber fraud

One of our clients recently received an email that appeared to come from one of our staff members and was ‘copied’ to the relevant financial planner. See the extract of the email below. Fortunately, the attempted fraud was identified by the client before any action was taken, but the consequences could have been catastrophic had the client acted on the email.

The displayed email addresses appeared legitimate. The fraudster altered a single element in the address, making it look authentic. Even the same font was used. Despite this, the email did not originate from our systems or from our team.

However, it is important to note that, although it didn’t happen in this instance, it is now possible for the email to appear to come from the same address as our staff.

How email spoofing works

Criminals manipulate the “from” field of an email so that it looks as though it was sent from a trusted person, even though it was not. In this instance, the email requested payment to new bank details and provided a plausible explanation involving system and platform changes. Fortunately, the client checked with our office before making any payment, preventing a loss.

Our policy on payments

This is a global problem affecting any business involved in fund transfers. This includes investment institutions, conveyancing practices, SARS, etc., all of which are frequent targets of cybercriminals.

Since 2020, we have proactively educated our clients by discussing these risks directly, including them in our Record of Advice, incorporating a fraud warning in every email, and circulating educational articles.

Again, as a reminder, this incident highlights an important rule. We, at Stone Wealth Management, will never provide bank account details via email without additional verification measures.

Most transfers to investment institutions are made using either pre-loaded beneficiaries on your banking app or a once-off debit order facilitated by the investment institution. For institutions that are not preloaded beneficiaries, such as Glacier International or Investec CCM accounts, Stone Wealth Management will WhatsApp the banking details to their clients to verify against the email address. The WhatsApp number is 031 832 4555.

What should you do

1. Be cautious with links and attachments. Phishing is one of the most common cyberattack methods. It involves criminals sending emails that look legitimate to trick you into clicking a malicious link, opening a harmful attachment, or revealing personal information such as passwords or banking details.

2. To be safe, always assume that all emails related to fund transfers may have been tampered with.

3. Verify independently by contacting Stone Wealth Management directly by telephone. Please make sure that you use the telephone number reflected on our official Stone Wealth Management website https://stonewealthmanagement.co.za/contact-us/.

4. Use a strong login password (for both your email account and the device you use to access it) that includes a combination of special characters, numbers, upper- and lower-case letters and remember to change the password regularly*.

5. Contact an IT specialist who will assist with, inter alia:

  • Encryption process – ensure that your emails are encrypted so that they cannot be intercepted or accessed by unauthorised parties.
  • Logging in process – enable multi-factor authentication (MFA)*, which typically requires a second verification step, such as a pin sent to your phone when logging in. This makes it much harder for attackers to access your account even if they obtain your password.

*Many email services, including web‑based platforms like Gmail, as well as desktop and mobile apps, often keep you logged in using a secure token. This means you may not be asked for your password or MFA every time you check your email. However, MFA is still essential. It protects your account whenever someone tries to access it from a new device, reset your password, or log in remotely without your permission.

6. Use secure Wi‑Fi to access your emails and avoid accessing email over public Wi‑Fi.

7. We also encourage you to share this information with friends and family, particularly those who may not receive regular direction from their financial advisers.

Extract

Below is the extract of the actual email sent to the client. We have included this for awareness.

Email

Remember

When it comes to cybercrime, familiar names and correct email addresses are no longer proof of authenticity. Verification remains the strongest defence. Please share this information with friends, families and colleagues.

Disclaimer

The opinions expressed in this article are those of the author and do not necessarily reflect the views of Stone Wealth Management. The content is provided for general information purposes only and should not be construed as advice. Readers should seek appropriate professional advice before acting on any information or opinions expressed.

Share This