There was a time when phishing emails were easy to identify. Bad spelling, strange grammar, a suspicious email address and a request that made no sense.
Your staff learned to spot them. You trained them to be careful. For a while, that helped.
That time is over.
Phishing emails hitting South African inboxes are now more polished, more personal and much harder to separate from the real thing. Attackers can use AI tools to write fluent messages, copy the tone of suppliers, reference real people and make routine requests look normal.
What modern phishing actually looks like
Imagine your accounts manager receives an email from what appears to be your regular stationery supplier.
The email address looks familiar. The logo looks right. The tone matches every other email from that supplier. The message says there has been a change in banking details and asks that future payments be made to a new account.
No obvious malware. No strange spelling. No dramatic warning.
Just a request that looks completely routine.
By the time the fraud is discovered, the payment may be gone. The real supplier may have no idea what happened.
This is business email compromise, and it is one of the most damaging attack types for SMEs because it attacks trust and process, not only technology.
Why training alone is not enough
Security awareness still matters. Your staff should know what phishing is, why it happens and what to do when something feels off.
But training cannot carry the whole burden anymore.
Attackers do their homework. They look at LinkedIn for staff names and roles. They study your website. They learn your suppliers, your wording and your approval habits. A targeted email to your finance manager can reference real people, real relationships and real processes.
No generic training session fully prepares someone for that.
What actually reduces your risk
The businesses that handle these attacks well are not the ones that expect staff to be perfect. They are the ones with layers underneath the human decision.
Email filtering should block obvious phishing, malware and impersonation before it reaches the inbox.
Multi-factor authentication should make stolen passwords less useful.
Payment changes should require confirmation through a trusted channel, not only an email reply.
Mailbox rules and unusual logins should be monitored.
Admin accounts should be protected and limited.
And when something looks wrong, someone should know what to check.
Your staff are not the weakness
People are busy. They work quickly. They trust familiar names. That is exactly what attackers exploit.
The weakness is assuming human vigilance alone can defend the business against AI-assisted attacks.
A managed IT provider does not replace your staff's judgement. It creates a safety net underneath it, so that when something slips through, the damage is contained.
The threat has changed. Your defences need to change with it.