Sylvia Walker | 21 August 2026
Sylvia Walker is a financial planner at Andrew Prior Consultants. She spent many years in a senior management position at Old Mutual before venturing out of the corporate world. She is also a freelance finance writer and author of several non-fiction books.
Browsing and buying online has become second nature to many of us, but it has the potential to wreak havoc with your finances if you fall victim to fraud. It’s easy to unknowingly send your personal information into cyberspace and right into the hands of a criminal. Here’s what you can do to protect yourself.
|
TIP To be secure, always download apps from an official app store, such as Google Play, the Apple App Store or Samsung Galaxy Store. |
Overlooking critical safety aspects leaves you vulnerable. Your information can be stolen at various points, so start by shopping on secure websites. Then understand how transactions are authorised, and what else you can do to protect your data.
You may think that shopping on a retailer app is safer, but it is no different to shopping on their website. The important aspect is the level of security, which includes how payment information is protected and whether transactions are authenticated. Using the official app of a retailer can reduce the risk of inadvertently entering card details into a convincing fake website.
A secure website ensures a safe connection between your web browser and the website itself. It encrypts data such as your personal information and card number so that it can’t be intercepted. These sites use HTTPS encryption and the HTTPS prefix appears in a website’s URL, and a padlock symbol is often displayed in the browser bar.
An unsecure site uses an HTTP prefix. “This means that your data travels without encryption, and your browser may display a "not secure" warning on these sites,” Eugene Vivier, head of card processing channels at Capitec, explains.
“So before entering any payment information, always look for the padlock and the HTTPS prefix. If either is missing, don't proceed.”
You can also check if a website is secure by visiting www.yima.org.za. The site was developed by the Southern African Fraud Prevention Services to protect consumers from scams and cybercrime. You can also install the Yima web browser plug-in to scan a website directly from the search engine results.
Once you enter your debit or credit card details to pay, the transaction must be processed by your bank.
Three-Domain Secure, commonly known as 3-D Secure, provides an extra layer of security to safeguard against fraudulent transactions. It involves three parties: the merchant, the cardholder, and the bank.
After you click the pay button, the system confirms that you are the correct cardholder by sending an authentication request to the bank, which verifies you via one of several authentication methods. This verification may be done through your banking app, biometric verification, USSD or a one-time password (OTP) that is sent to you. If the verification is successful, the bank authorises the transaction.
All South African online merchants have to use 3-D Secure, as mandated by the Payments Association of South Africa (PASA). International merchants don’t have to comply, which leaves consumers shopping on international sites vulnerable to fraud.
Not all South African merchants comply either, though, according to Tumelo Ramugondo, Standard Bank’s head of Personal and Private Banking Credit Card.
“If a local merchant doesn’t use 3D Secure, they will be liable for any fraudulent transactions.,” Ramugondo says
When a merchant does not use 3-D Secure authentication, a bank uses sophisticated fraud-detection systems and advanced analytics to identify transactions on your card that deviate from your normal behaviour or that match known fraud patterns.
Banks can’t guarantee that they will identify every attempt to fraudulently use your card with these controls, so unauthorised transactions may be processed.
To add further complexity, even if a site uses a 3-D Secure process, it’s not always followed, particularly if you have a history of authenticated online transactions with a particular merchant.
You may not be prompted to authenticate every online transaction, even if 3-D Secure is in place, Sobahle Mtshali, head of enterprise risk management at Discovery Bank, explains. The bank may approve the transaction without your verification, increasing the risk of unauthorised transactions, despite fraud-monitoring controls being in place.
If a transaction like this is reported as fraudulent, your bank should be notified immediately so that they can investigate thoroughly. Responsibility for the loss will depend on the facts of the case and the applicable card-scheme and dispute rules, according to Ramugondo.
|
|
Merchants that use services such as Visa Secure or Mastercard Identity Check support 3-D Secure authentication. A payment gateway, such as PayPal, Payfast, or Ozow, provides an additional layer of security because card details are not provided directly to the merchant but rather through 3-D Secure authentication.
However, if none of this is in place, you won’t know whether there is 3-D Secure authentication until you click “pay now”.
If an online transaction was completed without 3-D Secure and you dispute the transaction, the card scheme rules from Visa and Mastercard state that the merchant is liable for the transactions, Ramugondo says.
“This means that where a customer is defrauded on a non-3-D Secure site, the bank can recover the funds and return this to the customer,” he explains. “As long as the fraud is reported timeously so we can investigate thoroughly and follow a proper dispute process.”
Apart from card theft and payment fraud, online shopping exposes you to a host of other potential pitfalls, including non-delivery of goods, counterfeit products, or poor customer service.
The risk is heightened if you are shopping on websites that lack a credible reputation or recognised security measures.
Unless a website clearly states that they use 3-D Secure or a secure payment gateway or you pay via your banking app, you are putting yourself at risk. However, there are several ways you can protect yourself:
|
Unlike physical cards, virtual cards have a dynamic CVV. This means that this number changes regularly so even if someone obtains your virtual card details from a previous transaction, the CVV that they capture will be invalid. This dynamic CVV is implemented in different ways depending on your bank, but it significantly reduces the risk of fraud. |
Don’t shop online while connected to public Wi-Fi networks if you are unsure of the website’s security, Vivier warns. Your card details could be intercepted if there is no encryption to protect you.
If your bank offers a digital payment tool, such as Nedbank Pay, ABSA Pay, or Capitec Pay, use it. “You don’t need to enter bank card details or share banking login information,” says Vivier. “You only need to enter your cellphone, account, or ID number, and you’ll receive a prompt on your banking app to approve the payment.”
Use a virtual card issued by your bank when shopping online. A virtual card is a digital payment card inside your banking app. It is independent from your physical card, and has its own card number, expiry date and dynamic CVV. It can be used for online purchases and through digital wallets for in-store payments.
If you’re contacted by phone, SMS or email and requested to share your card details, one-time pin or approve requests via your banking app, don’t oblige. It’s probably a fraudster, and if it seems suspicious, stop and contact your bank immediately using their official fraud number. Remember the bank will never request this sensitive information from you.
Ultimately you need to protect yourself with knowledge, good shopping habits, and security tools provided by your bank.
“While technology is helpful in preventing fraud, vigilance remains one of the most effective forms of protection,” Mtshali concludes.