Case study
/
Financial Services
Date:
August 24, 2026

Retail centre closes payment fraud gaps after R500,000 loss

Client:
A South African retail centre
POPIA & Governance
Baseline Security Assessment
Awareness Training
Managed Security
Clive Conlon
Clive Conlon
Head of Operations
Do you have any thoughts or inquiries?
We'd love to hear from you.
Retail centre closes payment fraud gaps after R500,000 loss
At a glance
  • A fraudulent email changed a supplier's banking details mid-project, and roughly R500,000 went to the wrong account
  • The money was never recovered, and the real supplier still had to be paid
  • The decisive failure wasn't technical. Nobody phoned the supplier on a number they already had
  • Olerin ran the investigation, then assessed the whole environment and closed the gaps across policy, process, staff awareness, and technical configuration

What Happened

A supplier working on a capital project emailed to say their banking details had changed. The email came with an invoice and a bank confirmation letter, both showing the new account, and it arrived in the middle of an active thread about that exact payment. Nothing about it stood out.

Nothing about it was real either. The email came from outside the supplier's actual domain, both documents were fabricated, and the account belonged to someone else. The payment went through the centre's normal approval workflow and was released.

The fraud surfaced days later when the genuine supplier sent an automated reminder that the invoice was still outstanding. By then roughly R500,000 had left the account. A criminal case was opened and the bank was engaged within hours of discovery, but the funds were never recovered. The centre also had to settle the legitimate invoice, which meant carrying the cost twice on a project that was already tightly funded.

What the investigation found

Olerin reconstructed the payment timeline from raw email artefacts, internal approval communications, and banking records.

The useful part was what it ruled out. No compromised mailbox. No attacker inside the environment. No malware. This was impersonation, and it worked because the email landed inside a conversation where everyone was already expecting an invoice.

The decisive failure was that nobody independently verified the new account before the payment was released. The approval process worked exactly as designed. It confirmed the amount was right and the project work was certified. It never asked whether the account belonged to the supplier.

That distinction matters. Receiving a fraudulent email is not a control failure. The loss happened because there was no requirement to phone a number the centre already had on file and ask one question.

The investigation also ran into a wall worth naming. By the time forensic access was granted, the identity and mailbox audit logs covering the incident had already aged out of retention. A mailbox compromise couldn't be positively excluded, only left open. Short log retention doesn't cause incidents. It decides how much you can prove afterwards.

What we did about it

The centre didn't need an enterprise security programme. It needed the specific gaps closed, and enough of a documented baseline that an insurer would take it seriously.

We started with a full baseline security assessment covering identity, email, financial workflow, endpoints, data protection, governance, and incident readiness. That produced a prioritised list rather than a catalogue, so leadership could see what mattered first instead of drowning in findings.

Then we worked through it. Payment approval authority was documented, with a mandatory out-of-band verification step for any supplier banking change and a rule that screenshots and forwarded emails aren't evidence of anything. A risk register was set up with named owners, so payment fraud stopped being nobody's job in particular. We built a response playbook covering who calls the bank, who preserves the logs, and in what order.

On the technical side we hardened email against impersonation, enforced multi-factor authentication properly, brought devices under management, and extended logging so a future investigation wouldn't hit the same blank wall. Awareness training focused on payment fraud specifically rather than generic phishing, because the people involved here weren't careless. They were doing their jobs against a well-built forgery.

Where it stands

The money is still gone. No amount of remediation changes that, and it would be dishonest to write this up as a recovery story.

What changed is that the same email arriving today would run into a required phone call before anything moved. The centre can show an insurer a documented control environment rather than a good intention. And the people who process payments now know exactly what this attack looks like, because they've seen it up close.

Nothing sophisticated happened here. A convincing email and a missing phone call cost half a million rand.

What happens next

If your business pays suppliers by EFT and someone can change banking details by email, you have the exposure this client had.

Olerin's Baseline Security Assessment finds gaps like this before they cost anything and gives you a short, prioritised list of what to fix first. Our Awareness Training then makes sure the people approving payments recognise the pattern, because the control only works if someone remembers to use it.

Senior practitioners, in-house, sized for a business your size. Get in touch at info@olerincyber.com to arrange a short scoping call.

Subscribe to the Olerin blog

Keep in touch with Olerin and get the latest blog posts delivered straight to your inbox.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Olerin will manage your data in accordance with its privacy policy.