Trust, but Verify: Protecting Your Assets in an Age of Impersonation
- bespoke62
- 18 minutes ago
- 6 min read
Your investments are well protected while they remain inside a regulated investment fund. The greater vulnerability often arises when money moves, particularly when a fraudulent instruction looks or sounds genuine. As impersonation becomes more convincing in a world of AI and ‘deepfakes’, recognising a familiar name, voice, or logo is no longer enough. The stronger control is independent verification.
In January 2024, a finance employee at a multinational firm’s Hong Kong office received an email asking him to make a confidential payment. He hesitated, rightly. Then he joined a video call with his CFO and several familiar colleagues, all speaking and behaving much as they usually did. Reassured, he authorised fifteen transfers totalling roughly US$25.6 million. Everyone on the call turned out to be an AI-generated ‘deep’ fake, built from public footage of the real executives. There was no hack or stolen password. He trusted what he could see and hear, and it had been manufactured well enough to fool him.
What has changed
In the past, protecting investments often meant guarding against familiar threats: weak passwords, suspicious emails, stolen cards or direct theft. Those risks have not gone away, but the tools available to fraudsters are now more accessible and far more convincing. The Actuarial Society of South Africa has warned that AI systems built specifically for cybercrime make it easier to produce a credible phishing email or a believable fake call. This means an apparently credible request is worth double-checking before you act on it. According to Interpol’s 2026 assessment of cybercrime across the continent, South Africa is one of the most heavily targeted countries in Africa, largely because it’s also one of the most digitally advanced.
Researchers have also described a distinct pattern in how elderly South Africans are approached. Criminals lean on trust, isolation and the value of a lifetime's savings, often posing as SARS, a bank or a government agency to get past normal caution. The pattern seen internationally is that losses tend to rise with age: US data shows victims over 80 lose more per incident than any other age group and are significantly more likely to be defrauded repeatedly rather than once. This article explains how regulated investments are protected by design, and what you can do personally to reduce that risk further.
For many retirees, daily life already involves one-time PINs, app logins and verification calls from email accounts, banks, medical aids and retirement funds. It is easy to lose track of what you have approved, and for whom. That noise is exactly where a fraudulent request hides best. A familiar voice, a face on a screen or an email that looks right is a useful signal, but none of them proves on its own that a request is genuine.
That leaves three practical questions:
Where is your money held once you invest?
Who checks that those safeguards are being followed?
What can you do personally when an instruction looks or sounds genuine?
Where your money is held, and who keeps it secure
In South Africa, most investor savings sit within regulated investment vehicles: for individuals, typically a unit trust fund directly; for retirement savings, typically a pension fund or retirement annuity that itself invests in underlying unit trust funds.
Each fund has a manager (e.g. Coronation, Allan Gray, Ninety One) who decides on what to invest in, and an administrator who keeps the fund’s accounting records. Separately, an independent custodian, typically a bank or specialist custody firm (e.g. Standard Bank, RMB), physically holds the fund’s assets. And a trustee independently checks that the manager is following the rules. Regulators require your money to be kept apart from the manager’s own assets, and payments leaving the fund typically need sign-off from more than one of these parties before they are reconciled and released.
If you invest through an investment platform (e.g. Glacier, Allan Gray, Prescient), that’s a further separate layer. The platform holds your personal account and instructions, but the underlying assets still sit with the fund’s custodian, not the platform.
Who checks the checkers
The administrator keeps its own record of what the fund owns, but that record must match the custodian's every day. If it doesn't, the mismatch shows up immediately, which is the point: neither party can misstate what is there without the other one noticing.
On top of that daily checking, each fund's financial records must be audited by an independent firm every year and the trustee is required to report annually to the regulator on how well the manager has administered the fund, covering compliance and safekeeping. That's two separate outside reviews, on top of the day-to-day reconciliation.
Regulation is also tightening. The Conduct of Financial Institutions Bill, which is working its way through Parliament, will make it a legal requirement for client money and investments to be clearly identifiable and not commingled with the manager's own assets. Companies will need to prove this in practice.
Our view is that custody risk for a typical South African investor in a regulated fund remains low. That view would change if there were a serious systems breach at a custodian, or evidence that the new rules were not being applied consistently once in force. In the meantime, a simple check is to ask your adviser or platform who the independent custodian is, and how that separation is confirmed in practice.
How money and duties flow from you to the underlying investments, and who checks the structure independently.

Moving the money
The important distinction is that regulated structures are designed to protect assets while they are inside the fund. They do not remove the need for care when money is paid in, withdrawn, or redirected. That is where impersonation risk needs the most care.
Over the past year, South Africa’s Financial Sector Conduct Authority has repeatedly warned the public that well-known, licensed asset managers are being impersonated on WhatsApp and Telegram to solicit money into schemes that those firms have nothing to do with. Several of these cases used a real firm’s genuine licence number and branding, which means a licence check alone would not have caught them. A familiar name on a message, or even a licence number that checks out, is a good sign, but it works best alongside independent verification rather than instead of it.
Good habits outplay bad actors
A useful rule of thumb is to separate recognition from verification. Recognition is when something looks familiar: a logo, a name, a voice, or a convincing email address. Verification is when you confirm the instruction through a channel you chose yourself, using details you already had before the request arrived.
The strongest control is a consistent habit: verify independently every time money moves or when banking details change, using a number or channel you already know rather than one you have just been given. Treat urgency and secrecy as warning signs, not signs of importance, because genuine requests rarely need to happen immediately. Do not enter a password, PIN or one-time code after clicking a link in an email or SMS; go directly to the platform instead. If a call, email or message asks you to move money or change account details, put the phone down and call your adviser or bank back on a number you already have on file.
Accurate personal information can feel reassuring, but it isn’t proof of anything on its own: verify independently regardless, since fraudsters increasingly do their homework.
What is the industry doing?
Since June 2025, South African financial institutions, including asset managers and administrators, have been legally required to meet minimum cybersecurity standards covering how they detect fraud, respond to incidents and verify unusual instructions before acting on them.
Custodians and trustees are required by law to compensate you directly for any loss caused by their own carelessness or wrongdoing, which is part of why the custody structure described earlier holds up well. Banks do not have an equivalent automatic compensation requirement.
Where you were tricked into authorising a payment yourself, rather than someone moving money without your knowledge, South African law currently provides no automatic protection, although there are live proposals to change that.
The question that matters
The finance employee in Hong Kong was not careless. He questioned the request and sought reassurance, yet he was still caught out because the fraud had been built well enough to survive exactly that kind of scrutiny. The lesson is not to trust less, but to verify differently: a habit that works no matter how convincing a request looks or sounds.
The moment that deserves your attention is the moment money moves. Always pause and verify who is asking, not only what they are asking for, and use a channel you chose yourself before the request arrived. That is really the answer to the question of who to trust.







Comments