South Africa's major telecom operators lost R198.9 million to subscription fraud in the year to April 2026.
Cases rose 307% to 14,897 even as the average loss per incident fell sharply, showing fraud is scaling through volume.
The response now depends on shared intelligence, stronger identity controls and customer awareness across telecoms, banking and digital services.
Fraud Volume Overwhelms Falling Loss Size
MTN, Vodacom, Telkom, Cell C and Liquid Telecom lost R198.9 million, about US$12.5 million, to subscription fraud in South Africa during the 12 months to April 2026, according to figures from the Communications Risk and Information Centre reported by BusinessDay.
The number of cases jumped 307% year on year to 14,897.
This pattern is a warning for every digital business.
- Average loss per case fell 75% to about R13,400; however, total losses remained severe because syndicates multiplied the number of attacks.
- March recorded 2,475 cases, the highest monthly total.
Fraud has become a large-scale business:
- Smaller transactions, repeated often, can overwhelm controls designed mainly to catch exceptional high-value events.
Authentic Documents Now Enable False Customers
Subscription fraud occurs when people obtain telecom services without intending to pay.
- What makes the latest wave harder to stop is the use of genuine identity documents and bank statements.
- COMRiC chief executive Thokozani Mvelase said syndicates are even paying account holders for their banking information, allowing fraudulent applications to appear legitimate during onboarding.
That weakness reaches beyond unpaid phone contracts.
- COMRiC recorded 383 new SIM-swap cases with losses of R4.26 million.
- Once criminals control a mobile number, they can intercept one-time passwords and target bank accounts, messaging profiles and other services.
The mobile identity has become a gateway into a wider financial and social ecosystem.

Shared Intelligence Can Rebuild Digital Trust
Operators are now sharing information on suspected fraudsters and building a cross-sector database because a criminal rejected by one network can move quickly to another.
- The approach recognises that competition cannot become a barrier to collective security.
- Shared warning signals, consistent risk markers and rapid escalation can make repeated attacks harder to industrialise.
However, databases also create governance duties.
- Telecom companies must use lawful, accurate and appealable processes so legitimate customers are not unfairly excluded.
- Stronger controls should combine document verification, behavioural analytics, bank confirmation and human review, while minimising unnecessary collection of personal data.
Security and privacy must advance together.
Identity checks also need to look beyond whether a document is genuine.
- A valid bank statement can still be used in a fraudulent transaction if the account holder has sold access or is being manipulated.
- Risk models should therefore examine consent, device history, address consistency, payment behaviour and links to known applications.
False positives must be reviewed quickly, because poorly designed controls can lock low-income customers out of essential connectivity and deepen digital exclusion.
Treat Identity Fraud As System Risk
COMRiC estimates telecom-related fraud costs South Africa's economy about R5.3 billion annually.
- That burden ultimately affects service prices, credit decisions, customer friction and investment.
- It also intersects with ransomware and social engineering; BusinessDay cited Interpol's 2026 assessment that South Africa accounted for 92% of ransomware detections in Africa.
Telecom operators, banks and regulators should therefore treat identity fraud as a critical-infrastructure risk.
Customers need clear warnings about selling or sharing account information, and companies need rapid channels for victims to report compromised numbers.
- The goal is not simply to decline more applications.
- It is to identify networks behind the fraud before they move across companies and sectors.
Boards should receive regular reporting on fraud losses, attempted cases, control failures, customer remediation and data-sharing outcomes.
- Those indicators belong alongside network uptime and revenue because trust is part of service continuity.
Regulators can support common definitions and lawful information exchange, while independent oversight checks whether prevention systems discriminate or retain data longer than necessary.
Path Forward – Build Collective Digital Defences
Operators should combine shared intelligence, stronger onboarding controls and fast victim support with clear privacy safeguards.
Regulators must encourage cross-sector coordination so fraudulent identities cannot move freely between telecom, banking and platform services.
Culled from: MTN, Vodacom, Telkom, Cell C lose R199m to South Africa subscription fraud - Businessday NG