The most dangerous part of an online scam is often not the technology. It is the relationship the criminal constructs before asking for money or information.
On 11 September 2026, Reuters reported that South Africa had agreed to extradite six alleged members of the Black Axe network to the United States. US authorities accuse them of wire fraud and money laundering connected to online romance scams that allegedly defrauded more than 100 victims. The accusations will still need to be tested through the legal process. Reuters’ report provides the case details.
Romance scams and business payment fraud are not identical. The useful connection is the method: establish credibility, control communication, create urgency and convert trust into a transaction.
A believable identity is not proof
Criminals can assemble a persuasive profile from public websites, social media and leaked data. They may know a director’s name, the company’s suppliers and which employee processes payments.
They can also compromise a real mailbox or messaging account. A message coming from the correct address therefore does not always mean the legitimate owner sent it.
Staff should judge high-risk requests through an agreed process, not through confidence in the sender’s writing style or profile photograph.
Slow down the transaction
Social engineering often uses urgency: a payment must happen before close of business, the supplier’s bank account has suddenly changed, or an executive is “in a meeting” and cannot take a call.
The business needs rules that remain in force when someone applies pressure. Require independent verification for:
- New or changed banking details
- Unusual payment destinations
- Confidential payroll or customer records
- MFA codes or login approvals
- Requests to install remote-access software
- Exceptions to normal approval limits
Do not verify using the phone number supplied in the suspicious message. Use a trusted number already recorded in the accounting system, contract or official directory.
Separate request, approval and payment
Where practical, one person should not be able to receive a request, change supplier details and release the payment alone. Dual approval creates a second opportunity to notice an inconsistency.
Record who confirmed the change, which number was called and when approval occurred. A clear audit trail helps staff follow the rule consistently rather than relying on memory.
Protect the communication accounts
Process controls work best with secure accounts. Enable multifactor authentication, use separate administrator accounts, remove former employees promptly and investigate unexpected forwarding rules or login alerts.
Train employees to report mistakes immediately. If someone approved a suspicious login or sent information, a fast report gives administrators a better chance to revoke sessions and limit damage. Punishing the first person who reports a mistake teaches everyone else to hide the next incident.
Respond quickly to suspected fraud
Contact the bank immediately through an official channel, preserve messages and transaction information, and involve the IT provider to check whether email or other accounts were compromised. Obtain appropriate legal, insurance and law-enforcement guidance for the circumstances.
RandTech IT helps South African SMEs secure Microsoft 365, investigate suspicious access and implement practical security-awareness procedures. Trust is essential to business, but payments and confidential data need verification that does not depend on trust alone.









