<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security Archives - ProtectionWeb</title>
	<atom:link href="https://www.protectionweb.co.za/category/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.protectionweb.co.za/category/cyber-security/</link>
	<description>First with Security News</description>
	<lastBuildDate>Wed, 03 Dec 2025 08:17:48 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://www.protectionweb.co.za/wp-content/uploads/2024/04/cropped-ProtectionWebLogo-512x512-1-32x32.png</url>
	<title>Cyber Security Archives - ProtectionWeb</title>
	<link>https://www.protectionweb.co.za/category/cyber-security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Kaspersky detected half a million malicious files daily in 2025</title>
		<link>https://www.protectionweb.co.za/cyber-security/kaspersky-detected-half-a-million-malicious-files-daily-in-2025/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/kaspersky-detected-half-a-million-malicious-files-daily-in-2025/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Wed, 03 Dec 2025 08:17:48 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[malicious files]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=99093</guid>

					<description><![CDATA[<p>Kaspersky’s detection systems discovered an average of 500,000 malicious files per day in 2025, marking a 7% increase compared to the previous year. Certain types of threats saw growth globally – there was a 59% surge in password stealer detections, a 51% growth in spyware detections, and a 6% growth in backdoor detections compared to [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/kaspersky-detected-half-a-million-malicious-files-daily-in-2025/">Kaspersky detected half a million malicious files daily in 2025</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Kaspersky’s detection systems discovered an average of 500,000 malicious files per day in 2025, marking a 7% increase compared to the previous year. Certain types of threats saw growth globally – there was a 59% surge in password stealer detections, a 51% growth in spyware detections, and a 6% growth in backdoor detections compared to 2024.</p>
<p>These findings are part of the Kaspersky Security Bulletin series where we review the key cybersecurity trends of the past year.</p>
<p>Windows remains the primary target for cyberattacks. 48% of users on Windows were targeted by different types of threats throughout 2025. For Mac users, this figure stands at 29%.</p>
<p>Web threats</p>
<p>Globally, 27% of users were attacked with web threats – these refer to malware that targets users when they are online. Web threats are not limited to online activity, but ultimately involve the Internet at some stage for inflicted harm. In Latin America, 26% of users were attacked by web threats in 2025, while this share reached 25% in Africa, 21% in Europe and 19% in the Middle East.</p>
<p>On-device threats</p>
<p>33% of users were attacked with on-device threats. These include malware that is spread via removable USB drives, CDs and DVDs, or that initially makes its way onto the computer in non-open form (for example, programs in complex installers, encrypted files, etc.). Africa headed the rating with 41% of users attacked with this type of threat; APAC reached 33%, Middle East – 32%, Latin America – 30%, and Europe 20%.</p>
<p>“The current cyberthreat landscape is defined by increasingly sophisticated attacks on organisations and individuals around the world. One of the most significant revelations made by Kaspersky this year was the resurgence of the Hacking Team after its 2019 rebranding, with its commercial spyware Dante used in the ForumTroll APT campaign, incorporating zero-day exploits in Chrome and Firefox browsers. Vulnerabilities remain the most popular way for attackers to get into corporate networks, followed by using stolen credentials – hence the rise in password stealers and spyware we see this year. Supply chain attacks are also common, including attacks on open-source software. This year the number of such attacks increased significantly, and we even saw the first widespread NPM worm Shai-Hulud,” commented Alexander Liskin, Head of Threat Research at Kaspersky.</p>
<p>“This increasingly complex threat landscape makes implementing robust cybersecurity strategies vital for organisations, as failure to do so can lead to months of downtime in the event of attacks. Individual users should also always use reliable security solutions, otherwise they put not only their data and money at risk, but also those of the organisations where they work.”</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/kaspersky-detected-half-a-million-malicious-files-daily-in-2025/">Kaspersky detected half a million malicious files daily in 2025</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/kaspersky-detected-half-a-million-malicious-files-daily-in-2025/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Dark web attracts laid-off workers, teenagers, and elite talent</title>
		<link>https://www.protectionweb.co.za/cyber-security/dark-web-attracts-laid-off-workers-teenagers-and-elite-talent/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/dark-web-attracts-laid-off-workers-teenagers-and-elite-talent/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Mon, 01 Dec 2025 09:22:24 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[dark web]]></category>
		<category><![CDATA[shadow job market]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=99077</guid>

					<description><![CDATA[<p>There was a two-fold increase in the number of résumés and jobs posted on underground dark web forums in Q1 2024 compared to Q1 2023, and this number remained on the same level in Q1 2025, according to new research from Kaspersky. Overall, in 2025, résumés outnumber vacancies 55% to 45%, driven by global layoffs [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/dark-web-attracts-laid-off-workers-teenagers-and-elite-talent/">Dark web attracts laid-off workers, teenagers, and elite talent</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>There was a two-fold increase in the number of résumés and jobs posted on underground dark web forums in Q1 2024 compared to Q1 2023, and this number remained on the same level in Q1 2025, according to new research from Kaspersky.</p>
<p>Overall, in 2025, résumés outnumber vacancies 55% to 45%, driven by global layoffs and an influx of younger candidates. Age distribution among the candidates shows a median seeker age of just 24, with a marked teenager presence.</p>
<p>Jobs found on the dark web are predominantly related to cybercrime or other illegal activities, although some legitimate positions are present as well. Kaspersky findings show a shadow economy where 69% of job seekers did not specify a preferred field, openly signaling they’d take any paid opportunity – from programming to running scams or high-stakes cyber operations. The most in-demand IT roles posted by employers on the dark web reflect a mature criminal ecosystem:</p>
<p>Developers (accounted for 17% of vacancies) create attack tools;<br />
Penetration testers (12%) probe networks for weaknesses;<br />
Money launderers (11%) clean illicit funds through layered transactions;<br />
Carders (6%) steal and monetise payment data;<br />
Traffers (5%) drive victims to phishing sites or infected downloads.</p>
<p>Gender-specific patterns emerged in specialised applications. Female applicants predominantly sought interpersonal roles, including support, call-centre, and technical-assistance positions. Male applicants, by contrast, more frequently targeted technical and financial-crime roles – developers, money mules, or mule handlers.</p>
<p>Salary expectations varied sharply by specialisation. Reverse engineers commanded the highest compensation, averaging over $5,000 monthly, followed by penetration testers at $4,000 monthly and developers at $2,000. Fraudsters tended to receive a fixed percentage of a team’s income. Money launderers average 20%, while carders and traffers earn approximately 30% and 50% of the full income, respectively. These figures reflect a premium on scarce, high-impact skills within the shadow ecosystem.</p>
<p>“The shadow job market is no longer peripheral; it’s absorbing the unemployed, the underage, and the overqualified. Many arrive thinking that the dark web and the legal market are fundamentally alike, rewarding proven skills over diplomas, with the dark web even offering some benefits – like offers landing within 48 hours and no HR interviews. However, not many realise that working on the dark web can lead to prison,” comments Alexandra Fedosimova, Digital Footprint Analyst at Kaspersky.</p>
<p>Young individuals contemplating dark web employment must recognise that short-term earnings carry irreversible legal and reputational consequences. Parents, educators, and the community are urged to report suspicious online solicitations immediately. Children should be shown that there are multiple skill-building and career pathways in legitimate technology sectors, such as cybersecurity, Kaspersky said.</p>
<p>The Kaspersky analysis was based on 2,225 job-related posts – vacancies and resumes – published on dark web forums between January 2023 and June 2025. Some of the forums and resources reviewed may no longer be accessible at the time of publication.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/dark-web-attracts-laid-off-workers-teenagers-and-elite-talent/">Dark web attracts laid-off workers, teenagers, and elite talent</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/dark-web-attracts-laid-off-workers-teenagers-and-elite-talent/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Vulnerable SA retailers in for brutal peak as cyber criminals gear up for attack</title>
		<link>https://www.protectionweb.co.za/cyber-security/vulnerable-sa-retailers-in-for-brutal-peak-as-cyber-criminals-gear-up-for-attack/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/vulnerable-sa-retailers-in-for-brutal-peak-as-cyber-criminals-gear-up-for-attack/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Mon, 24 Nov 2025 05:24:38 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber criminals]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Mimecast SA]]></category>
		<category><![CDATA[retailers]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=99044</guid>

					<description><![CDATA[<p>South African retailers face a perfect cybersecurity storm as they gear up for an extended peak season. The busiest time of year will see head offices at their most vulnerable as cyber criminals target overworked staff who are desperate to ensure sales are maximised and customers kept happy. Black Friday, Festive and Back to School [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/vulnerable-sa-retailers-in-for-brutal-peak-as-cyber-criminals-gear-up-for-attack/">Vulnerable SA retailers in for brutal peak as cyber criminals gear up for attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>South African retailers face a perfect cybersecurity storm as they gear up for an extended peak season. The busiest time of year will see head offices at their most vulnerable as cyber criminals target overworked staff who are desperate to ensure sales are maximised and customers kept happy.</p>
<p>Black Friday, Festive and Back to School trading holidays have merged into a three-month peak that has placed a growing strain on local retailers, many of which also have less administrative support as employees take their annual leave over the summer holidays. What’s more, landmark retail breaches in the UK should be giving local retailers cause for concern.</p>
<p>“Ransomware attacks at UK retailers like Marks &amp; Spencer, Co-op, and Harrods have made headlines across the globe. While the circumstances of each incident may have varied, each case highlighted the fact that human error is still one of the most exploited vulnerabilities,” says Heino Gevers, Senior Director of Technical Support at Mimecast SA. “Rather than deploying groundbreaking malware or sophisticated technical exploits, criminals manipulated employees, impersonated IT staff and bypassed trust-based systems designed for convenience and speed.”</p>
<p>Odds stacked against local retailers</p>
<p>The effects of ransomware attacks are a growing threat to local businesses. According to 2025 research by Sophos, 60% of local companies hit by a ransomware attack had data encrypted. The median payment to retrieve their data came in at around R7.8 million, while the cost to recover from an attack averaged around R23 million.</p>
<p>The research further shows that email remains a major attack vector, with 23% of global retailers reporting phishing as the root cause, and a further 14% citing malicious email.</p>
<p>Human-factor still the biggest weakness</p>
<p>The UK retail breaches were a case study in how cyber attacks target an organisation’s weakest links.</p>
<p>The Marks &amp; Spencer attackers reportedly gained access using stolen credentials obtained via social engineering, allowing them to disrupt operations, with the damage expected to result in a 30% hit to profits. Co-op suffered a similar breach when IT staff were tricked into resetting a legitimate user’s password, giving criminals access to their network. The breach is alleged to have cost the retailer £206 million in lost sales. Harrods also fell victim to social engineering tactics with 403 000 customer records compromised.</p>
<p>“The amount of damage done to these retail juggernauts must be a cautionary tale for local retailers. Particularly since South African companies face additional challenges. While shop floors may be fully staffed, many administrative roles may be away on leave. The additional strain on overworked employees who are at the office can lead to very expensive errors,” Gevers says.</p>
<p>Gevers goes on to explain that the public visibility of the successful UK attacks is likely to have a copycat effect. What’s more, he points out that even less technically skilled attackers can now quickly and cheaply access tools and tactics (often enabled by AI), that allow them to build highly effective phishing campaigns or impersonate support teams at scale.</p>
<p>Gevers says the threat intelligence team at Mimecast has tracked over 150 000 phishing campaigns since February this year, all bearing the hallmarks of these tactics. While many seem simple in nature, such as fake CAPTCHAs, spoofed portals, and MFA prompts, they remain effective because they exploit trust, not code.</p>
<p>Keeping customers happy adds layers of threat</p>
<p>To further complicate things, local retailers will be facing a particularly challenging time this peak as overburdened support teams struggle to deal with increased customer support demands. This will be the case both on the shop floor and online as ecommerce continues to surge.</p>
<p>“Great customer support lies at the heart of ecommerce growth. Unfortunately attackers know this, and they are now increasingly targeting support desks, managed service providers, and third-party vendors. These teams are trained to solve problems quickly, reset credentials and keep operations moving. And it’s precisely these qualities that make them attractive entry points for social engineers,” Gevers shares.</p>
<p>Gevers also warns that business email compromise (BEC) remains one of the most successful forms of attack today, because it bypasses technology altogether. “A well-crafted email from a ‘colleague’ asking for an invoice payment or password reset can be all it takes,” he says.</p>
<p>Identify the areas of weakness and help shore up the gaps</p>
<p>Gevers says recent research from Mimecast reveals that 95% of data breaches are caused by human error but that just 8% of employees account for 80% of security incidents.</p>
<p>He says organisations must prioritise identifying high-risk individuals and implementing targeted training to mitigate these vulnerabilities. Additionally, with over 90% of threats delivered via email, he says it’s crucial to focus on blocking these entry points to prevent attackers from gaining access to credentials and moving laterally within systems.</p>
<p>“As cybercriminals evolve, the battle has moved into inboxes, helpdesks and chat windows. South African retailers must act now to ensure their teams have all the necessary support to get through their busiest time of the year. Retailers can make anything from 20% to 50% of their revenue during peak season and, while they must remain laser-focused on making the most of this time, this past year in the UK has shown us just how devastating a ransomware attack can be,” Gevers says.</p>
<p>Online brand protection is everyone’s responsibility</p>
<p>To keep consumers safe over the peak, Mimecast teams devised a list of tips for retailers:<br />
1. Deploy Domain-based Message Authentication, Reporting and Conformance (DMARC), as a first step. The DMARC protocol prevents cybercriminals from sending harmful emails that appear to come from the business’s domain and is one of the ploys often used by cybercriminals during busy sale days when consumers are expecting communications from stores they have purchased from.<br />
2. Monitor and analyse email activity to identify illegitimate senders, then quarantine or reject suspicious emails before they reach consumers<br />
3. Deploy third-party brand protection services that use advanced scanning and ML to detect and neutralise imitation or spoofed websites and actively block brand impersonation attempts.<br />
4. Establish strong collaboration between marketing and cybersecurity teams to ensure brand protection is addressed from both a reputation and a technical security perspective.<br />
5. Be transparent and communicate with customers, especially regarding incidents, proactive protection steps, and general information security advice.<br />
6. Respond swiftly to attacks by investigating, remediating, and compensating affected customers to maintain the trust that has often taken years to build.<br />
7. Treat online brand protection (including defense against domain spoofing and fake websites) as integral to overall brand management and consumer trust.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/vulnerable-sa-retailers-in-for-brutal-peak-as-cyber-criminals-gear-up-for-attack/">Vulnerable SA retailers in for brutal peak as cyber criminals gear up for attack</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/vulnerable-sa-retailers-in-for-brutal-peak-as-cyber-criminals-gear-up-for-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CSIR develops web-based reporting tool for cybercrimes</title>
		<link>https://www.protectionweb.co.za/cyber-security/csir-develops-web-based-reporting-tool-for-cybercrimes/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/csir-develops-web-based-reporting-tool-for-cybercrimes/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Fri, 07 Nov 2025 07:28:04 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Council for Scientific and Industrial Research]]></category>
		<category><![CDATA[CSIR]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[SAPS]]></category>
		<category><![CDATA[South African Police Service]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98935</guid>

					<description><![CDATA[<p>The Council for Scientific and Industrial Research (CSIR) has developed a web-based tool that enables financial and electronic communications service providers to report cybercrimes directly to the South African Police Service (SAPS). In line with the Cybercrimes Act, 2020 (Act 19 of 2020), a Cybercrimes Designated Point of Contact has been established through a collaboration [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/csir-develops-web-based-reporting-tool-for-cybercrimes/">CSIR develops web-based reporting tool for cybercrimes</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The Council for Scientific and Industrial Research (CSIR) has developed a web-based tool that enables financial and electronic communications service providers to report cybercrimes directly to the South African Police Service (SAPS).</p>
<p>In line with the Cybercrimes Act, 2020 (Act 19 of 2020), a Cybercrimes Designated Point of Contact has been established through a collaboration between the CSIR and SAPS. The facility is located at the CSIR in Pretoria. The Act requires all financial and electronic communications service providers to report cybercrimes directly to this designated point of contact, the CSIR said in its 2024/25 annual report.</p>
<p>“As the use of digital systems for communication and online transactions becomes increasingly widespread, so do the risks to the safety and security of user&#8217;s personal information. Previously, there was no dedicated mechanism or platform to report cybercrimes. In response, the CSIR developed a secure, web-based reporting platform that allows service providers to report cybercrimes directly to the SAPS Designated Point of Contact, hereby supporting cybercrime investigation and response efforts.”</p>
<p>The tool has been fully developed over the past two years and is ready for deployment in a live environment. It will undergo final testing, security assessments and penetration testing before being rolled out nationally for use by all financial and electronic communications service providers in South Africa, the CSIR said.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/csir-develops-web-based-reporting-tool-for-cybercrimes/">CSIR develops web-based reporting tool for cybercrimes</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/csir-develops-web-based-reporting-tool-for-cybercrimes/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
			</item>
		<item>
		<title>Limpopo ICT Forum, DCDT and CSIR hosting three-day Cybersecurity Awareness Webinar</title>
		<link>https://www.protectionweb.co.za/cyber-security/limpopo-ict-forum-dcdt-and-csir-hosting-three-day-cybersecurity-awareness-webinar/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/limpopo-ict-forum-dcdt-and-csir-hosting-three-day-cybersecurity-awareness-webinar/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Thu, 30 Oct 2025 08:04:35 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Council for Scientific and Industrial Research]]></category>
		<category><![CDATA[CSIR]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[Cybersecurity Awareness Webinar Series]]></category>
		<category><![CDATA[Department of Communications and Digital Technologies]]></category>
		<category><![CDATA[Limpopo ICT Forum]]></category>
		<category><![CDATA[romance scam]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98884</guid>

					<description><![CDATA[<p>In today’s connected world, data has become one of our most valuable assets. Every click, share and download shapes our digital footprint and with that comes the responsibility to protect it. As cyber threats become increasingly organised and sophisticated, individuals must remain vigilant in managing their personal information online. To support this effort, the Limpopo [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/limpopo-ict-forum-dcdt-and-csir-hosting-three-day-cybersecurity-awareness-webinar/">Limpopo ICT Forum, DCDT and CSIR hosting three-day Cybersecurity Awareness Webinar</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In today’s connected world, data has become one of our most valuable assets. Every click, share and download shapes our digital footprint and with that comes the responsibility to protect it. As cyber threats become increasingly organised and sophisticated, individuals must remain vigilant in managing their personal information online.</p>
<p>To support this effort, the Limpopo ICT Forum, Department of Communications and Digital Technologies (DCDT) and the Council for Scientific and Industrial Research (CSIR) are jointly host a three-day Cybersecurity Awareness Webinar Series under the theme “Your Data, Your Power: Hlayiseka!” The phrase Hlayiseka!, meaning “Be Safe”, is a call to action for all citizens to take ownership of their digital safety. The theme serves as a reminder that personal data is power and protecting it is not only a technical responsibility but also a personal and social one, the CSIR said.</p>
<p>This initiative forms part of Cybersecurity Awareness Month (October), which is celebrated globally to promote safer online practices and to build a culture of digital responsibility. The webinars bring together cybersecurity experts, educators, parents and members of the public to learn and engage on practical ways to stay safe online and safeguard their digital identities.</p>
<p>The Cybersecurity Awareness Webinar Series aims to:</p>
<p>Promote awareness of personal data protection and responsible digital behaviour;</p>
<p>Educate citizens on how to identify and respond to common online threats;</p>
<p>Strengthen child online protection and digital rights awareness; and</p>
<p>Foster collaboration between government, industry, academia and communities to enhance national cyber resilience.</p>
<p>Day three (30 October 2025 from 18:00 – 19:00) will focus on romance scams and online relationship fraud (phishing and catfishing). It will be hosted by Siphokazi Novukuza, Director, Cybersecurity Operations, DCDT. Presenters will include Thuli Mkhwanazi: Senior Cybersecurity Researcher, CSIR; Danielle Badenhorst: Cybersecurity Specialist, CSIR; and Matsebe Phasha, Committee Member, Secretary, Limpopo ICT Forum.</p>
<p>To join, participants can click on this <a href="https://events.teams.microsoft.com/event/e2fd0f0f-5288-468d-be06-13988392cd75@2fd3c5d5-ddb2-4ed3-9803-f89675928df4">Teams link</a>.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/limpopo-ict-forum-dcdt-and-csir-hosting-three-day-cybersecurity-awareness-webinar/">Limpopo ICT Forum, DCDT and CSIR hosting three-day Cybersecurity Awareness Webinar</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/limpopo-ict-forum-dcdt-and-csir-hosting-three-day-cybersecurity-awareness-webinar/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Kaspersky finds security flaws that threaten vehicle safety</title>
		<link>https://www.protectionweb.co.za/cyber-security/kaspersky-finds-security-flaws-that-threaten-vehicle-safety/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/kaspersky-finds-security-flaws-that-threaten-vehicle-safety/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Wed, 29 Oct 2025 08:00:44 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[vehicle safety]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98880</guid>

					<description><![CDATA[<p>At the Security Analyst Summit 2025, Kaspersky presented the results of a security audit that has exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer. By exploiting a zero-day vulnerability in a contractor’s publicly accessible application, it was possible to gain control over the vehicle telematics system, compromising [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/kaspersky-finds-security-flaws-that-threaten-vehicle-safety/">Kaspersky finds security flaws that threaten vehicle safety</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>At the Security Analyst Summit 2025, Kaspersky presented the results of a security audit that has exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.</p>
<p>By exploiting a zero-day vulnerability in a contractor’s publicly accessible application, it was possible to gain control over the vehicle telematics system, compromising the physical safety of drivers and passengers. For instance, attackers could force gear shifts or turn off the engine when the vehicle is driving. The findings highlight potential cybersecurity weaknesses in the automotive industry, prompting calls for enhanced security measures, Kaspersky said.</p>
<p>The security audit was conducted remotely and targeted the manufacturer’s publicly accessible services and the contractor’s infrastructure. Kaspersky identified several exposed web services. First, through a zero-day SQL injection vulnerability in the wiki application (a web-based platform that allows users to collaboratively create, edit, and manage content), the researchers were able to extract a list of users on the contractor’s side with password hashes, some of which were guessed due to a weak password policy. This breach provided access to the contractor’s issue tracking system (a software tool used to manage and track tasks, bugs, or issues within a project), which contained sensitive configuration details about the manufacturer’s telematics infrastructure, including a file with hashed passwords of users of one of the manufacturer’s vehicle telematics servers. In a modern car, telematics enables the collection, transmission, analysis, and utilisation of various data (e.g., speed, geolocation, etc.) from connected vehicles.</p>
<p>On the connected vehicle side, Kaspersky discovered a misconfigured firewall exposing internal servers. Using a previously acquired service account password, the researchers accessed the server’s file system and uncovered credentials for another contractor, granting full control over the telematics infrastructure. Most alarmingly, the researchers discovered a firmware update command that allowed them to upload modified firmware to the Telematics Control Unit (TCU), Kaspersky said. This provided access to the vehicle’s CAN (Controller Area Network) bus – a system that connects different parts of the vehicle, like the engine and sensors. Afterwards, various other systems were accessed, including the engine, transmission, etc. This enabled potential manipulation of a range of critical vehicle functions, which could endanger driver and passenger safety.</p>
<p>“The security flaws stem from issues that are quite common in the automotive industry: publicly accessible web services, weak passwords, lack of two-factor authentication (2FA), and unencrypted sensitive data storage. This breach demonstrates how a single weak link in a contractor’s infrastructure can cascade into a full compromise of all of the connected vehicles. The automotive industry must prioritise robust cybersecurity practices, especially for third-party systems, to protect drivers and maintain trust in connected vehicle technologies,” said Artem Zinenko, Head of Kaspersky ICS CERT Vulnerability Research and Assessment.</p>
<p>Kaspersky recommends that contractors restrict Internet access to web services via VPN, isolate services from corporate networks, enforce strict password policies, implement 2FA, encrypt sensitive data, and integrate logging with a SIEM system for real-time monitoring.</p>
<p>For the automotive manufacturer, Kaspersky advises restricting telematics platform access from the vehicle network segment, using allowlists for network interactions, disabling SSH password authentication, running services with minimal privileges, and ensuring command authenticity in TCUs, alongside SIEM integration.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/kaspersky-finds-security-flaws-that-threaten-vehicle-safety/">Kaspersky finds security flaws that threaten vehicle safety</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/kaspersky-finds-security-flaws-that-threaten-vehicle-safety/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title>Legal guardrails needed for smart ID roll-out in South Africa</title>
		<link>https://www.protectionweb.co.za/cyber-security/legal-guardrails-needed-for-smart-id-roll-out-in-south-africa/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/legal-guardrails-needed-for-smart-id-roll-out-in-south-africa/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Mon, 20 Oct 2025 07:00:34 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[smart ID]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98822</guid>

					<description><![CDATA[<p>South Africa’s public sector is rapidly adopting biometric and algorithmic tools to improve service delivery. From Home Affairs’ Smart ID rollout to SASSA’s recent mandatory biometric enrolment for grant processing, governments are rightly chasing efficiency and fraud reduction. But without tight legal guardrails, these technologies concentrate administrative power, create new vectors for exclusion and erode [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/legal-guardrails-needed-for-smart-id-roll-out-in-south-africa/">Legal guardrails needed for smart ID roll-out in South Africa</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>South Africa’s public sector is rapidly adopting biometric and algorithmic tools to improve service delivery. From Home Affairs’ Smart ID rollout to SASSA’s recent mandatory biometric enrolment for grant processing, governments are rightly chasing efficiency and fraud reduction. But without tight legal guardrails, these technologies concentrate administrative power, create new vectors for exclusion and erode due‑process protections that underpin the rule of law.</p>
<p>Biometric IDs and automated decision systems can speed verification and cut obvious fraud. But they also shift crucial decisions from people to opaque systems. Practical harms are already visible: failed enrolments blocking grant access, incorrect automated de‑duplication removing legitimate beneficiaries, and weak appeal routes when a machine says “no”. Biometric data is uniquely sensitive – if compromised it cannot be reissued like a password – and the administrative use of such data often proceeds without clear limits on retention, sharing, or independent oversight. In a country with high poverty, spatial inequality and heavy reliance on social grants, these failures risk converting technical glitches into violations of fundamental socio‑economic rights.</p>
<p>POPIA (the Protection of Personal Information Act) establishes important principles for processing personal data, but it is broad and primarily oriented to private‑sector compliance. Administrative uses of biometric and algorithmic systems raise distinct concerns:</p>
<p>Decisions taken by public agencies affect access to entitlements and liberty; they therefore require stronger procedural safeguards than commercial profiling.<br />
There is often no meaningful right-of‑review or quick remedy when an automated process wrongly denies a benefit.<br />
National rollout decisions (for ID cards, biometric enrolment or facial recognition) are framed as technical upgrades, leaving democratic debate and parliamentary scrutiny behind.</p>
<p>South Africa should enact a narrow ADPA that sits alongside POPIA, designed specifically to govern government use of biometric, identity and algorithmic systems. Its core features should be minimalist but enforceable:</p>
<p>Biometrics and identity data may be collected only where strictly necessary to achieve a specified administrative purpose (e.g., fraud prevention in grant payments), and only after less intrusive alternatives are exhausted. Mandatory impact assessments (pre‑deployment) must show proportionality and non‑discriminatory effect.</p>
<p>Default retention periods for biometric templates must be short and justified; continuous retention requires strong legal basis and periodic review.</p>
<p>Technical standards for secure storage and breach notification are mandatory; irreversible hashing or template techniques must be preferred over raw image storage.</p>
<p>An independent Administrative Appeals Office (AAO) with powers to conduct expedited reviews of ID‑related denials (temporary relief within days) must be established, with specialist technical capacity to audit algorithms and biometric matches.</p>
<p>Citizens must be given clear, accessible notice when a decision relied on automated processing, and a human‑review right on request.</p>
<p>All public algorithms used for eligibility or exclusion must publish a non‑proprietary “decision manifesto”: data sources, key variables, error‑rates, and known biases. This balances security with public accountability.</p>
<p>Regular, machine‑readable disclosure of aggregated failure/appeal statistics (by region and programme) enables civic monitoring and targeted fixes.</p>
<p>The ADPA should create enforceable penalties for agencies that negligently deny benefits through untested automated systems and mandate remediation for affected individuals, including expedited payments and reputational remedies.</p>
<p>An ADPA targeted at administrative uses preserves the gains from digital IDs – reduced fraud, faster processing, possible cost savings – while protecting the most vulnerable. It reframes the problem: not “stop digitisation” but “design government systems so that technology augments, not substitutes, accountable public administration.” The emphasis on short retention, independent review and transparency speaks directly to South Africa’s context where exclusion from grants or ID verification failures can mean loss of shelter, food or school fees.</p>
<ul>
<li>Require parliamentary scrutiny of major ID/biometric programmes with mandatory public impact statements.</li>
<li>Pilot biometric measures in defined districts with external evaluation before national rollout.</li>
<li>Fund and staff an Administrative Appeals Office with clear timelines for emergency relief in benefits cases.</li>
</ul>
<p>The rapid adoption of biometric and algorithmic tools in South Africa&#8217;s public sector, aimed at enhancing service delivery, often overlooks critical civil liberties, raising concerns about potential governmental misuse for political or ideological ends. As these technologies concentrate administrative power, they create opportunities for abuse, such as discriminatory targeting or the manipulation of data to marginalise specific groups. The absence of stringent oversight not only threatens the rights of individuals but also undermines the very principles of democracy and accountability. If implemented without robust legal frameworks, there is a risk that these systems could be weaponised, where the government might exploit data to stifle dissent or bolster its authority, ultimately eroding the trust citizens place in public institutions. This dual threat of exclusion and authoritarianism underscores the urgent need for a legal framework, like the proposed Administrative Data Protection Act (ADPA), that enshrines the values of proportionality, transparency, and accountability in the deployment of such powerful technologies.</p>
<p>South Africa need not choose between modernising public services and protecting citizens’ rights. A tightly scoped Administrative Data Protection Act would anchor biometric and algorithmic deployments in rule‑of‑law principles: necessity, proportionality, transparency and remedy. That modest legal intervention would allow the state to use powerful identification tools without turning administrative efficiency into a new source of exclusion and arbitrary power.</p>
<p><em>About the author: Mukundi Budeli is a final year LLB student at the University of Witwatersrand and an Associate of the Free Market Foundation.</em></p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/legal-guardrails-needed-for-smart-id-roll-out-in-south-africa/">Legal guardrails needed for smart ID roll-out in South Africa</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/legal-guardrails-needed-for-smart-id-roll-out-in-south-africa/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
			</item>
		<item>
		<title>Employees’ social media habits create costly security gaps for SA businesses</title>
		<link>https://www.protectionweb.co.za/cyber-security/employees-social-media-habits-create-costly-security-gaps-for-sa-businesses/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/employees-social-media-habits-create-costly-security-gaps-for-sa-businesses/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Tue, 14 Oct 2025 07:08:07 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyberbattack]]></category>
		<category><![CDATA[data breache]]></category>
		<category><![CDATA[ESET Southern Africa]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[South Africa]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98790</guid>

					<description><![CDATA[<p>The use of social media at work – especially on devices connected to internal networks – is putting South African businesses at risk of data breaches and cyberattacks. With no specific laws governing social media use in the workplace, many businesses operate without cybersecurity policies for online platforms. From Facebook updates and WhatsApp conversations to [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/employees-social-media-habits-create-costly-security-gaps-for-sa-businesses/">Employees’ social media habits create costly security gaps for SA businesses</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The use of social media at work – especially on devices connected to internal networks – is putting South African businesses at risk of data breaches and cyberattacks. With no specific laws governing social media use in the workplace, many businesses operate without cybersecurity policies for online platforms. From Facebook updates and WhatsApp conversations to LinkedIn networking, this leaves the door wide open for cybercriminals looking to exploit employees who have their guard down.</p>
<p>“This Cybersecurity Awareness Month, we’re raising awareness around unregulated use of social media platforms in the office,” said Carey van Vlaanderen, Group CEO at ESET Southern Africa. “There are two main risks when it comes to employees using social media at work. The first is sharing sensitive data &#8211; like client details, financial figures, and even login credentials &#8211; on platforms that weren’t designed with corporate cybersecurity in mind, and the second is being tricked into clicking on malicious links via fraudulent ads or direct messages.”</p>
<p>South Africans are among the most exposed to high-risk and fraudulent financial ads online, according to research by forex broker analysts at BrokerChooser. Each time employees access social platforms on corporate devices, a single click can introduce malware, trigger phishing attacks, or compromise sensitive information. “What starts as an individual mistake can rapidly escalate into a company-wide vulnerability,” says van Vlaanderen.</p>
<p>In 2024, analysts estimated that the average cost of recovering from a data breach in South Africa reached R53-million &#8211; up roughly R4-million from the previous year; “The cost of human error can be extremely high. Without reliable safeguards and an understanding of what to look out for, employees face the constant challenge of distinguishing what’s legitimate from what’s not. With AI boosting the social engineering capacity of cybercriminals, this is getting harder and harder to do,” said van Vlaanderen.</p>
<p>Rising security concerns have prompted action from the platforms themselves. Earlier this year, Meta removed more than six million scam-linked WhatsApp accounts globally. Instead of retreating, attackers doubled down &#8211; most recently exploiting a glitch in the platform to infiltrate victims&#8217; phones and steal data. This creates a perfect storm: WhatsApp is the go-to tool for workplace communication, with more than 90% of employees across Africa using it daily &#8211; surpassing both email and Microsoft Teams.</p>
<p>“These platforms were built for consumers, not corporations &#8211; so they don’t offer the same level of security and privacy protection that purpose-designed systems guarantee. Operating outside formal safety controls, risky cyber activity can easily bypass protections and go unnoticed,” said van Vlaanderen.</p>
<p>“Even just sharing details about work, clients, and colleagues online can be risky, since it provides cybercriminals with all the information they need to impersonate managers in business phishing emails. From employee through to CEO, everyone needs to remain vigilant and be thoughtful about what they are posting online,” said van Vlaanderen. “These are all things that can be included in a business&#8217;s social media policy.”</p>
<p>From a business perspective, the biggest vulnerability isn’t unsecure platforms &#8211; it’s people; “Equipping your team with the tools to identify risks on their own is critical to keeping up with rapidly evolving threats. Speak to your provider about cybersecurity awareness training that can help build practical, real-world skills through immersive, scenario-based programmes,” said van Vlaanderen. “This kind of investment not only protects your assets but also strengthens the resilience of the entire corporation.”</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/employees-social-media-habits-create-costly-security-gaps-for-sa-businesses/">Employees’ social media habits create costly security gaps for SA businesses</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/employees-social-media-habits-create-costly-security-gaps-for-sa-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Office of the Tax Ombud invites public comment on eFiling Profile Hijacking</title>
		<link>https://www.protectionweb.co.za/cyber-security/office-of-the-tax-ombud-invites-public-comment-on-efiling-profile-hijacking/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/office-of-the-tax-ombud-invites-public-comment-on-efiling-profile-hijacking/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Thu, 02 Oct 2025 08:32:20 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[eFiling Profile Hijacking]]></category>
		<category><![CDATA[Office of the Tax Ombud]]></category>
		<category><![CDATA[OTO]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98713</guid>

					<description><![CDATA[<p>The Office of the Tax Ombud (OTO) has invited the public to comment on its Draft Report into alleged eFiling Profile Hijacking. “The OTO hereby invites written comments on the eFiling profile hijacking draft report. By inviting public participation, the OTO aims to develop a robust and effective response to eFiling profile hijacking, thereby ensuring [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/office-of-the-tax-ombud-invites-public-comment-on-efiling-profile-hijacking/">Office of the Tax Ombud invites public comment on eFiling Profile Hijacking</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The Office of the Tax Ombud (OTO) has invited the public to comment on its Draft Report into alleged eFiling Profile Hijacking.</p>
<p>“The OTO hereby invites written comments on the eFiling profile hijacking draft report. By inviting public participation, the OTO aims to develop a robust and effective response to eFiling profile hijacking, thereby ensuring protection of taxpayers’ rights and enhancing trust in South Africa’s tax administration system,” the OTO said in a statement on Wednesday 1 October 2025.</p>
<p>The draft report was drafted by the ombud following its investigation into alleged eFiling profile hijacking.</p>
<p>“Between 3 February and 5 March 2025, the OTO conducted the eFiling Profile Hijacking Survey to capture taxpayers’ experiences and challenges related to eFiling profile hijacking. Preliminary findings from the survey were presented during a public workshop held on 28 May 2025.</p>
<p>“Initially, the OTO planned to publish the draft report for public comment in July 2025. However, SARS formally requested additional time to respond to the draft report and its recommendations. Consequently, on 2 July 2025, the OTO announced that the publication of the draft report would be postponed to 31 August 2025. Due to ongoing and extensive engagements with SARS, the publication was further delayed,” the statement read.</p>
<p>The report’s key findings include:<br />
• eFiling profile hijacking is most prevalent among tax practitioners and individual taxpayers.<br />
• The majority of cases involve Personal Income Tax and Value-Added Tax (VAT).<br />
• Fraudulent transactions typically involve amounts under R10 000 but can reach up to R100 000.<br />
• Vulnerabilities include inadequate authentication processes, challenges in fraud detection, delayed SARS response times, insider threats, and low digital security awareness among taxpayers.</p>
<p>The key recommendations include:<br />
• South African Revenue Service (SARS): Enhance authentication protocols, improve fraud detection and refund verification systems, boost taxpayer education, and strengthen collaboration with banks, the Companies and Intellectual Property Commission (CIPC), and the South African Police Service (SAPS).<br />
• Tax Practitioners: Implement stricter controls on third-party access and uphold high professional conduct standards.<br />
• Taxpayers: Use strong passwords, activate two-factor authentication, and regularly monitor eFiling profile activities.<br />
• National Treasury: Amend certain provisions in the Tax Administration Act and establish an Inspector-General as recommended by the Nugent Commission of inquiry.<br />
• South African Reserve Bank: Investigate banking irregularities linked to eFiling profile hijacking.</p>
<p>The draft report can be accessed at https://www.taxombud.gov.za/oto-draft-report-on-the-investigation-into-alleged-efiling-profile-hijacking/</p>
<p>Written comments can be sent via: communications@taxombud.gov.za and for more information, visit www.taxombud.gov.za before the deadline on 31 October 2025.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/office-of-the-tax-ombud-invites-public-comment-on-efiling-profile-hijacking/">Office of the Tax Ombud invites public comment on eFiling Profile Hijacking</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/office-of-the-tax-ombud-invites-public-comment-on-efiling-profile-hijacking/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Phishing evolves with AI and stealth</title>
		<link>https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/</link>
					<comments>https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/#disqus_thread</comments>
		
		<dc:creator><![CDATA[Guy Martin]]></dc:creator>
		<pubDate>Tue, 30 Sep 2025 06:37:35 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[voice cloning]]></category>
		<guid isPermaLink="false">https://www.protectionweb.co.za/?p=98696</guid>

					<description><![CDATA[<p>Currently, phishing is going through a shift driven by sophisticated AI-powered deception techniques and innovative evasion methods. Cybercriminals are exploiting deepfakes, voice cloning and trusted platforms like Telegram and Google Translate to steal sensitive data, including biometrics, electronic signatures and handwritten signatures, posing unprecedented risks to individuals and businesses. This is according to cybersecurity and [&#8230;]</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/">Phishing evolves with AI and stealth</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Currently, phishing is going through a shift driven by sophisticated AI-powered deception techniques and innovative evasion methods. Cybercriminals are exploiting deepfakes, voice cloning and trusted platforms like Telegram and Google Translate to steal sensitive data, including biometrics, electronic signatures and handwritten signatures, posing unprecedented risks to individuals and businesses.</p>
<p>This is according to cybersecurity and digital privacy company Kaspersky, which said it detected and blocked over 142 million phishing link clicks in Q2 2025, a 3.3% increase globally and a 25.7% increase in Africa from Q1.</p>
<p>AI has elevated phishing into a highly personalised threat, Kaspersky said. Large language models (LLMs) enable attackers to craft convincing emails, messages and websites that mimic legitimate sources, eliminating grammatical errors that once exposed scams. AI-driven bots on social media and messaging apps impersonate real users, engaging victims in prolonged conversations to build trust. These bots often fuel romantic or investment scams, luring victims into fake opportunities with AI-generated audio messages or deepfake videos.</p>
<p>Attackers also create realistic audio and video deepfake impersonations of trusted figures — colleagues, celebrities or even bank officials — to promote fake giveaways or extract sensitive information. For instance, automated calls mimicking bank security teams use AI-generated voices to trick users into sharing two-factor authentication (2FA) codes, enabling account access or fraudulent transactions. Additionally, AI-powered tools analyse public data from social media or corporate websites to launch targeted attacks, such as HR-themed emails or fake calls referencing personal details.</p>
<p>Employing new tactics to bypass detection</p>
<p>Phishers are deploying sophisticated methods to gain trust, exploiting legitimate services to prolong their campaigns. For instance, Telegram’s Telegraph platform, a tool to publish long texts, is used to host phishing content. Google Translate’s page translation feature generates links that look like https://site-to-translate-com.translate.goog/&#8230; and are used by attackers to bypass security solutions’ filters.</p>
<p>Attackers now also integrate CAPTCHA, a common anti-bot mechanism, into phishing sites before directing users to the malicious page itself. By using CAPTCHA, these fraudulent pages deflect anti-phishing algorithms, as the presence of CAPTCHA is often associated with trusted platforms, lowering the likelihood of detection.</p>
<p>A switch in hunting: From logins and passwords to biometrics and signatures</p>
<p>The focus has shifted from passwords to immutable data. Attackers target biometric data through fraudulent sites that request smartphone camera access under pretexts like account verification, capturing facial or other biometric identifiers that cannot be changed. These are used for unauthorised access to sensitive accounts or sold on the dark web. Similarly, electronic and handwritten signatures, critical for legal and financial transactions, are stolen via phishing campaigns impersonating platforms like DocuSign or prompting users to upload signatures to fraudulent sites, posing significant reputational and financial risks to businesses.</p>
<p>“The convergence of AI and evasive tactics has turned phishing into a near-native mimic of legitimate communication, challenging even the most vigilant users. Attackers are no longer satisfied with stealing passwords — they’re targeting biometric data, electronic and handwritten signatures, potentially creating devastating, long-term consequences. By exploiting trusted platforms like Telegram and Google Translate, and co-opting tools like CAPTCHA, attackers are outpacing traditional defences. Users must stay increasingly sceptical and proactive to avoid falling victim,” said Olga Altukhova, security expert at Kaspersky.</p>
<p>Earlier in 2025 Kaspersky detected a sophisticated targeted phishing campaign which was dubbed Operation ForumTroll, as attackers sent personalised phishing emails inviting recipients to the “Primakov Readings” forum. These lures targeted media outlets, educational institutions and government organisations in Russia. After clicking on the link in the email, no additional action was needed to compromise their systems: the exploit leveraged a previously unknown vulnerability in the latest version of Google Chrome. The malicious links were extremely short-lived to evade detection and in most cases ultimately redirected to the legitimate website for “Primakov Readings” once the exploit was taken down.</p>
<p>To be protected from phishing, Kaspersky recommends:</p>
<p>Verify unsolicited messages, calls, or links, even if they appear legitimate. Never share 2FA codes.<br />
Scrutinise videos for unnatural movements or overly generous offers, which may indicate deepfakes.<br />
Deny camera access requests from unverified sites and avoid uploading signatures to unknown platforms.<br />
Limit sharing sensitive details online, such as document photos or sensitive work information.</p>
<p>The post <a href="https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/">Phishing evolves with AI and stealth</a> appeared first on <a href="https://www.protectionweb.co.za">ProtectionWeb</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.protectionweb.co.za/cyber-security/phishing-evolves-with-ai-and-stealth/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
