For years, the default headline in cybersecurity was ransomware, criminals break in, encrypt, demand payment. That story still matters, but the centre of gravity has moved. In 2026, CEOs now rank cyber enabled fraud and phishing ahead of ransomware as their top concern, according to the World Economic Forum’s Global Cybersecurity Outlook 2026. This is the strongest signal of what is hottest right now, because it shows leadership anxiety shifting away from purely technical compromise, and toward something more corrosive, the manipulation of decision making itself.
Cyber enabled fraud is powerful because it is designed to pass as business as usual. It hides inside familiar workflows, supplier onboarding, urgent payment approvals, invoice changes, password resets, executive requests, logistics updates. When it succeeds, it does not look like a breach, it looks like a process that happened too quickly, with too much trust, and too little verification. That is why fraud should be understood as a security issue and a governance issue, because it exploits the rules of how the organisation says yes.
Fraud is not new, but it is hotter now because the economics of deception have changed. The WEF reports that AI is anticipated to be the most significant driver of change in cybersecurity, cited by 94 percent of survey respondents. When persuasion can be generated, localised, iterated, and personalised cheaply, the human cues that used to protect us, tone, familiarity, apparent confidence, become unreliable. It becomes easier to impersonate, easier to pressure, and easier to target the exact person who can approve, override, or expedite. In that world, “it sounded right” is no longer evidence.
Most leaders still talk about cybersecurity as protecting systems, yet fraud makes a more accurate point, organisations run on permissions. Someone approves, someone authorises, someone confirms, someone releases funds, someone grants access, someone changes a record. Attackers no longer need to beat your strongest technical control if they can borrow your permissions through social engineering, compromised accounts, or supplier pathways. This is why Gartner’s 2024 trends emphasise insecure employee behaviour, third party risks, and identity first approaches, the vulnerabilities are increasingly socio technical, not purely technical.
Cloud services, remote work, SaaS sprawl, and constant integration have made “inside the network” a weak definition of trust. Fraud thrives where identity is weakly verified and privileges are overly broad, because a compromised identity can perform legitimate actions at speed. The modern defensive posture is therefore identity centred, strong authentication, least privilege, continuous access review, and special attention to high privilege pathways. This direction is reinforced by Gartner’s framing of identity first security and continuous exposure practices as leading trends, because they match how organisations actually operate now.
Fraud is increasingly amplified by third party dependency. A spoofed supplier request is more believable when it matches real supplier workflows. A compromised vendor portal can be used to alter payment details quietly. A small outsourced provider can be used to impersonate a larger enterprise convincingly. This is why supply chain and third party risk keep appearing in top level trend narratives, the ecosystem is the attack surface, not only your internal estate.
Africa’s digital economy is scaling quickly, particularly through mobile first services, digital payments, e commerce, and digitised public services. Attackers follow value, and the region has seen sharp increases in attack volume. Check Point research reported that Africa experienced the highest average weekly cyberattacks per organisation in Q2 2024, averaging 2,960 attacks per week, a 37 percent increase year on year. Volume does not equal success, but high volume increases the chance that one message, one call, one compromised credential, finds the right seam in a process. In fast digitising markets, the trust consequences can be larger, because trust is still being earned at scale.
Where the phone is the bank branch, the identity token, and the commerce gateway, fraud does not merely steal money, it damages confidence in the platform itself. If users expect scams, they avoid digital channels, revert to cash, or limit usage, which quietly undermines inclusion and growth. This is the strategic heart of the fraud problem in many African contexts, cybersecurity is not only about preventing loss, it is about sustaining trust in the rails of digitisation.
South Africa’s connectivity and sophisticated financial, retail, and logistics systems make it an attractive target environment, and attack pressure has been widely reported in recent years. One analysis citing 2024 figures noted South African organisations and government agencies experienced very high average weekly attack volumes. In such an environment, cyber enabled fraud becomes board level quickly, because it intersects directly with revenue, payments, suppliers, and public trust, and because a single successful fraud event can create regulatory, reputational, and operational fallout simultaneously.
In South Africa, finance is often a leading indicator of where trust will be priced. When regulators formalise cybersecurity and cyber resilience requirements, boards pay attention, and suppliers eventually feel the pull through procurement and third party assurance requirements. The broader point is not compliance for its own sake, it is that governance is shifting from “do you have controls” to “can you prove integrity, detection, response, and recovery”.
Fraud resilience is built where authority moves. The high value interventions are therefore structural. Require strong verification for supplier banking changes and urgent payments. Separate duties so that no single identity can create and approve high risk actions. Reduce privilege creep through continuous access reviews. Treat machine credentials and integrations as first class identities, because attackers love quiet, over privileged access. Adopt continuous exposure practices so you are not relying on annual reassurance in a weekly threat reality.
Cyber enabled fraud is hottest right now because it attacks the core mechanism of modern organisations, trust under time pressure. AI has made deception scalable. Ecosystem dependency has multiplied pathways. Digital transformation has increased the number of moments where a single approval can move money, data, and reputation. The organisations that lead from 2024 to 2028 will not be the ones that claim they are secure, they will be the ones that can demonstrate integrity and continuity, because in the fraud era, trust is not a sentiment, it is an operating capability.