Abstract
Following the COVID-19 pandemic, global reliance on digital platforms increased significantly, reshaping how individuals and institutions communicate, transact, and conduct business. This digital transformation created new opportunities for cybercriminals to exploit systemic vulnerabilities. Among the most damaging forms of cyber-enabled fraud is Business Email Compromise (BEC), which does not rely on technical breaches but instead manipulates trust, urgency, and procedural gaps. These attacks are rooted in psychological manipulation and social engineering, making the human factor the most vulnerable link in cybersecurity.
This research examines the South African legal framework governing BEC, with a particular focus on judicial developments in the financial, legal, and commercial sectors. Through an analysis of case law, the study identifies emerging principles relating to civil liability, verification duties, and the completion of payment. These principles provide practical guidance in the absence of comprehensive legislation and reflect a growing awareness of digital risk within the judiciary.
To contextualise South Africa’s position, the study includes a comparative analysis of legal responses in the United Kingdom and the African Union. The United Kingdom has adopted a proactive approach through legislative reforms such as the Economic Crime and Corporate Transparency Act 2023 and mandatory reimbursement for authorised push payment fraud. These measures promote corporate accountability and preventative compliance. In contrast, the African Union’s Malabo Convention offers a foundational framework but lacks detailed provisions addressing social engineering and enforcement capacity across member states.
Despite progress, South Africa continues to face significant challenges in mitigating BEC. These include fragmented regulation, limited criminal prosecution, and the underutilisation of alternative dispute resolution mechanisms. The study proposes a multi-dimensional strategy that includes legal reform, sector-specific cybersecurity regulation, enhanced prosecutorial capacity, and behavioural awareness initiatives...