Cybercrime in South Africa is reaching new heights in 2025, with attacks becoming increasingly sophisticated and frequent. According to industry estimates, cybercrime is projected to cost the South African economy over R2.2 billion annually.[1] This surge highlights the urgent need for stronger digital defences across all industry sectors.
Traditionally legacy-driven and financially robust, family businesses are no exception. These enterprises often handle sensitive financial, operational and personal data across a portfolio of investments making them high value targets.
Cyber threats to the extended family
For privately-owned family businesses, the risk considerations are not only for the business, but also for the family members behind the business. Personal information and online behaviour can expose families to physical threats and reputational damage, which in turn can impact the business.
Threats are not contained to the digital space unfortunately. In recent years, South African crime syndicates have adapted their kidnapping and extortion tactics, increasingly using cryptocurrency for ransom demands to minimise the risk of arrest and enhance the anonymity of transactions.
Common cyber threats
-
Ransomware
Ransomware is a type of malicious software designed to restrict access to a victim’s system or data until a ransom is paid. These attacks can be devastating, often targeting both business-critical and personal information. Phishing emails or compromised links are common entry points. Once activated, the malware locks users out and demands payment under the threat of data loss or public exposure.
A prominent example occurred in 2019, when Amazon CEO Jeff Bezos was reportedly hacked after receiving a malicious WhatsApp file from an account linked to Saudi Crown Prince Mohammed bin Salman, as reported by CNN Business.
-
Identity theft
Identity theft involves the unauthorised acquisition and use of personal or corporate information – such as banking credentials or identification numbers – for financial gain. In family businesses, where personal and professional identities often overlap, such breaches can lead to unauthorised transactions, creation of fraudulent accounts or resale of information on the dark web.
-
Deepfakes and AI-based impersonation
Thanks to advances in Artificial Intelligence (AI), attackers can now create deepfake videos, audio messages or images that convincingly impersonate real individuals. In a business context, this could involve a fake video call appearing to come from a company director, requesting an urgent fund transfer or sensitive data. These high-stakes impersonations are increasingly difficult to detect without advanced verification systems.
-
Social engineering and Business Email Compromise (BEC)
Social engineering techniques manipulate individuals into revealing confidential information or authorising fraudulent transactions. Business Email Compromise (BEC) scams are on the rise in South Africa, where attackers gain access to or spoof executive email accounts to issue fake instructions, often targeting finance departments within small firms.
Proactive measures for building cyber resilience
To mitigate these risks, family businesses should practice strong cyber hygiene and adopting a robust cybersecurity strategy.
This should include but not be limited to:…
![]() |
|
|
Gustav D’Assonville | Senior Manager | mail me | |
Fatih Isik | Senior Analyst | mail me | |
The full article is reserved for our subscribers!
Read the full article by Gustav D’Assonville, Senior Manager and Fatih Isik, Senior Analyst, KPMG Southern Africa | as well as a host of other topical management articles written by professionals, consultants and academics in the June/July 2025 edition of BusinessBrief.
admin@bbrief.co.za | +27 (0)11 788 0880 |





























