Capitec says its payment screening system protected 113,410 clients from losing more than R699-million to fraud between July 2025 and June 2026. The bank also says it blocked over 131,000 suspicious beneficiary accounts, including 64,000 mule accounts, and warned clients against more than 394,000 scam payments. All the figures come from Capitec and are not independently audited.
Interesting insights on Capitec fraud prevention
The mechanism is more interesting than the number. Before an EFT leaves an account, Capitec scores the beneficiary in real time using reports from other clients who have previously flagged that same recipient. The client sees the rating, reviews the details and chooses whether to proceed, with no time limit and no pressure.
Across 26 million clients, that makes the customer base itself the detection network, and every report makes the next score better. For independent scale, SABRIC recorded R2.4-billion in actual digital banking losses across the industry in 2025, up 29.2% on 2024, from 110,074 reported incidents at an average of roughly R21,865 each, with banking app crime accounting for more than 70% of those losses.
SABRIC specifically named mule accounts and synthetic identities as continuing risks, which is what Capitec's 64,000 figure speaks to. Note that three of the eight features Capitec listed are not fully live yet: Trusted Approver is still in development, and Scam Scanner arrives in the coming weeks.
What others are saying about Capitec fraud prevention
TechFinancials carried Capitec's statement, including Blessing Mgaga's point that financial crime moves fast and the bank is trying to disrupt the flow rather than respond after the fact. SABRIC's 2025 report, summarised by the Banking Association, put digital banking losses at R2.4-billion and card fraud up 18% to R1.7-billion. BusinessTech worked out the average loss per reported incident.
Your users know things you are not using
One feature is a direct answer to a story we ran last month. Capitec's malware detection tool scans a client's phone for software installed to intercept banking credentials, which is exactly what the campaign using fake Takealot, DStv and SARS sites was doing to read SMS one-time PINs.
The bank is now checking the device because nobody can secure the network. But the beneficiary scoring is the part worth studying. Capitec did not buy better detection. It aggregated what 26 million clients already knew and handed it back as a score, which no smaller competitor can copy.
That is a moat made of customer reports rather than technology, and it sits in the same place AI financial crime keeps outrunning compliance. Worth asking what your own users tell you that you currently discard.
You might also like our piece on the Lego South Africa data breach and who stays liable, the stolen browser cookies circulating locally, and how Capitec home broadband extends the same client base into telecoms.
Get more SA tech and business news and subscribe to The Open Letter.


