Security Guides
A caller who knows your ID and account number is not the bank: what to do after the Standard Bank data breach
Standard Bank of South Africa says names, ID or company registration numbers, contact details and account numbers were accessed and now appear to have been published. What clients should do: fake bank calls, SAFPS, credit checks.
For: current and former clients of The Standard Bank of South Africa (personal and business, including foreign-owned companies operating in South Africa), and anyone receiving calls "from the bank" from someone who knows their ID or account number. This article is based on Standard Bank's own statements and guidance from the Southern African Fraud Prevention Service (SAFPS), the Information Regulator and South African government consumer information. It does not cover how the attack was carried out.
What clients should do today
Hang up on any 'bank' call that asks you to do something, and call back yourself
Standard Bank's own advice is to verify any unexpected email, SMS or call asking for sensitive information by contacting the bank through trusted channels. In practice: end the call, then dial a number you found yourself, such as the one on the back of your card. The fraud line in South Africa is 0800 222 050 (international +27 10 824 2090). Never call back a number the caller or a text message gave you.
Never give out an OTP, PIN or password, whoever is asking
Standard Bank tells clients to never share passwords and PINs when asked by anyone via phone, fax, text messages or email. In an earlier security article, the bank also says it will never ask for your digital banking credentials, including OTPs, over the phone, and will never call to ask you to move money to an account you don't know. A one-time PIN approves a transaction; reading it out is the same as approving the scammer's payment.
Register with SAFPS Protective Registration (free)
The bank recommends registering with the Southern African Fraud Prevention Service (SAFPS). According to SAFPS, Protective Registration is free and flags your identity so that member credit providers take extra precautions: the bank's notice puts it this way, if someone applies for a banking product with your ID number, it will be declined or referred for further review. SAFPS says you can apply online, by email or by requesting a call-back, with a certified copy of your ID and proof of address, and that a reference number is issued within 48 hours.
Check your credit report for accounts you didn't open
South Africa's National Credit Act lets you request your credit report free of charge every 12 months from the registered credit bureaux, according to government consumer information. Look for enquiries or accounts you don't recognise; if a bureau shows an enquiry you did not consent to, you can dispute it with that bureau. Standard Bank says it is itself monitoring credit bureau activity for affected clients, but your own check covers every lender, not just one.
Update your banking passwords and switch on in-app security
The bank asks all clients to update their banking passwords on its digital platforms and on social media, to use strong, unique passwords, and to enable biometric authentication in the Standard Bank app. If you reused a banking password anywhere else, change it there too. A password manager makes unique passwords easy.
Business clients: confirm every change of payment details by phone
The published fields include company registration numbers, VAT numbers, B-BBEE categorisation and account numbers. For a business, that is enough to make a fake invoice, a "new bank details" letter or a call to your finance team look real. Make it a rule that a change of a supplier's or your own bank details is confirmed by calling a number already on file, never one in the email. The same applies to "urgent" payment instructions between a head office abroad and its South African subsidiary. Corporate & Investment Banking clients are told to contact their service consultant or relationship manager.
If fraud happens: the bank, SAFPS and the Information Regulator
Report the incident to the bank's fraud line at once and ask it to stop further transactions. If your identity was used, SAFPS offers a Victim of Impersonation registration in addition to Protective Registration. For complaints about how your personal information was handled, South Africa's data protection authority is the Information Regulator, which accepts POPIA complaints through its online eServices portal.
What the caller may know (leaked)
Your name · ID or company registration number · phone, email, physical address · account number · VAT number, B-BBEE category
→ Proves nothing. Don't trust a call because of it
What the bank says it will never ask
Your password · your PIN · your OTP · to move money to an account you don't know
→ If asked: hang up, call 0800 222 050 yourself
Not leaked, per the bank: access to transactional banking and core systems
What happened (per Standard Bank)
The following comes from Standard Bank's statements on its newsroom. The bank has not published how many clients were affected.
23 March 2026
Standard Bank says it has identified an incident involving unauthorised access to select data, took immediate steps to secure its environment, and launched a full investigation with expert support. It says its transactional systems remain secure and it will directly notify affected clients.2 April
The bank's first update lists names, ID numbers and company registration numbers, says it has reported the incident to the regulatory authorities, and recommends protective steps including SAFPS registration. On 13 April it adds contact details and account numbers.14 April
A further update says the affected systems were internal administrative and document filing systems, and that client and company-related data "now appears to have been published". The data list later adds B-BBEE categorisation and VAT registration numbers (marked "as at 16 April").Mid-April
South African media report that the Information Regulator is assessing the incident and has asked the bank for more information. As of 30 September 2026, this site found no findings on the incident published by the Regulator.
- Affected (may differ per person)
- Names; ID numbers or company registration numbers; contact details (phone numbers, physical and/or email addresses); account numbers; B-BBEE categorisation and VAT registration number
- Systems affected
- Internal administrative and document filing systems
- Not affected
- Transactional banking and core operating systems "were not accessed"; the bank says no clients' funds are affected
- Cards
- In limited cases involving card details, the bank says affected clients are being contacted directly and their cards replaced
- Bank's measures
- Enhanced monitoring of credit bureau activity and SIM-swap activity, additional transaction monitoring, 24/7 fraud teams, more device-based and in-app verification
- Authorities
- The bank says it has complied with regulatory notification requirements
- Official contact
- Personal/Private Banking 0860 123 000 · Business Banking 0860 109 075 · Fraud line 0800 222 050
How to read it: 'core systems were not accessed' does not mean 'no risk to you'
Standard Bank's own update names the risk: someone could use the information to impersonate you or contact you fraudulently, with emails, messages or calls that appear genuine, or try to use your details without your permission. An ID number and an account number can't be changed like a password, so this risk doesn't fade after a few weeks. Plan to keep the habits below for years, not days.
Why this combination is the perfect script for a fake bank call
Most leaks give a scammer one half of a convincing story. This one gives both halves at once. An ID number is what a real bank uses to confirm who you are, and an account number is what it uses to talk about your money. A caller who says "I'm from Standard Bank's fraud department, I can see your account ending in 1234, and I just need to confirm your ID number, which I have as..." sounds exactly like the bank, because until now only the bank would have known those numbers together.
Signs of a fake 'bank' call
- Opens by reading out your ID or account number to "verify" you
- Says your account is at risk and there is no time to lose
- Asks you to read out an OTP, PIN or password
- Asks you to move money to a "safe" account
- Tells you not to hang up or not to tell anyone
What Standard Bank says
- Never share passwords or PINs with anyone who asks
- The bank will never ask for OTPs or credentials over the phone
- The bank will never ask you to move money to an unknown account
- If a call sounds suspicious, hang up and call the fraud line
- Verify unexpected messages through trusted channels
The lesson isn't "learn to spot a scammer's voice". It's moving the moment of trust: never decide whether a call is real while you're still on that call. The bank already knows your ID; a real bank call will survive you hanging up and phoning back.
This site's view: agree on a 'call-back rule' at home and at work
Decide in advance, with your family and your finance team, that any call asking you to do something with money gets a call-back on a number you look up yourself. No exceptions for callers who "already know everything". This removes the one thing the leaked data adds: credibility. If your company has a head office abroad, apply the same rule to its "urgent transfer" requests. For companies holding ID and account numbers, the other side of the lesson is to limit who can see such records and how many at once; we cover that in the minimum security baseline for organizations.
The closest parallel this year is the Odido breach in the Netherlands, where ID and bank account numbers also leaked, and the Endesa breach in Spain, where the same "the caller knows my details" problem drove the advice. For how fake calls and messages work, see what is phishing?.
Sources (public record)
The facts in this article are based on the public sources below. Attacker claims and unpublished figures are not used.
- Standard Bank, "A message from Standard Bank" (23 March 2026, with FAQ of 24 March) — standardbank.co.za
- Standard Bank, "An Important Data Incident Update" (2 April 2026, as updated 13 April) — standardbank.co.za
- Standard Bank, "An Important Data Incident Update - 14 April" (with FAQ) — standardbank.co.za
- Standard Bank, "Scammers turn to phone calls as banks clamp down on fraud" (6 August 2024) — standardbank.co.za
- Southern African Fraud Prevention Service, "Apply for Protective Registration" — safps.org.za
- Information Regulator, "How to Lodge a Complaint" — inforegulator.org.za
- Vuk'uzenzele (South African government), "You are entitled to a free credit report" (May 2023) — vukuzenzele.gov.za
- IOL, "What you need to know about the Standard Bank data breach investigation" (15 April 2026; used only for the Information Regulator's reported comments) — iol.co.za
Update history
2026-09-30: First version, based on Standard Bank's statements of 23 March, 2 April (updated 13 April) and 14 April 2026 (as checked on 30 September 2026; no affected count published), and guidance from SAFPS, the Information Regulator and South African government consumer information.
Read next
- The closest parallels: The Odido data breach (ID and bank account numbers) / The Endesa data breach (DNI and IBAN)
- Fake calls and messages: What is phishing? / Fake virus warnings (tech-support scams)
- Protecting your accounts: Choosing a password manager / Choosing multi-factor authentication
- Other 2026 incidents: List of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations
FAQ
QWhat data was leaked in the Standard Bank breach?
According to Standard Bank's 14 April 2026 update, the affected information may differ from person to person and, based on what the bank knew at that stage, includes names, ID numbers or registration numbers, contact details such as phone numbers, physical and/or email addresses, and account numbers. B-BBEE categorisation and VAT registration numbers were added to the list later (marked 'as at 16 April'). The bank says it will notify clients directly if they are affected beyond these fields.
QWas my money affected?
Standard Bank says the affected systems were internal administrative and document filing systems, and that its transactional banking and core operating systems were not accessed, remain secure and are available. As a result, it says, no clients' funds are affected and accounts remain secure. The risk it warns about is that someone could use the information to impersonate you or contact you fraudulently.
QHas the data been published?
In its 14 April 2026 update, Standard Bank said it had been preparing for the possibility of client and company-related data being made public, 'which now appears to have been published'. This article does not link to or describe where; treat your details as known to strangers.
QHow many clients were affected?
Standard Bank has not published a number of affected clients in its statements. Figures circulating online come from the people claiming the attack and are unconfirmed, so this article does not use them.
QHow can I tell whether a call from 'Standard Bank' is real?
You can't tell from the call itself, because a scammer may now know your real ID and account number. Standard Bank says never to share passwords or PINs with anyone who asks by phone, fax, text or email, and that the bank will never ask for your digital banking credentials, including OTPs, over the phone or call to ask you to move money to an account you don't know. Hang up and call the bank on a number you find yourself, such as the one on your card; the fraud line in South Africa is 0800 222 050.
QWhat is SAFPS Protective Registration, and should I do it?
Standard Bank recommends it. Protective Registration with the Southern African Fraud Prevention Service is free and flags your identity number so that member credit providers take extra care before approving products in your name. SAFPS says you can apply online, by email or by requesting a call-back, with a certified copy of your ID and proof of address, and that a reference number is issued within 48 hours.