Standard Bank

Exclusive | Standard Bank Fraud Files Expose Troubling Gaps Between Bank Records, Customer Evidence and Ombud Findings

The two cases are striking for another reason: the bank’s explanations have evolved as customers produced more evidence.

JOHANNESBURG – Standard Bank is standing by its handling of two fraud disputes involving customers who collectively lost R435,350, despite documentary evidence that raises questions about how the bank’s own digital records were interpreted.

The two cases are striking for another reason: the bank’s explanations have evolved as customers produced more evidence.

In one case, Standard Bank initially maintained that a Google Wallet registration had been authenticated through the customer’s biometrics. After the customer pointed to the absence of corresponding Google records on his devices, the bank provided a different explanation: the wallet had allegedly been provisioned on a fraudster’s device after the customer was tricked into authenticating it.

In the other case, bank records appear to show a further R10,200 transaction after a fraud block had been activated. Standard Bank says there is no contradiction because the transaction was a credit into the account, not a debit.

The cases raise broader questions about the reliability and interpretation of digital banking records, how fraud investigations are conducted, and how much evidential weight customers can place on the systems banks use to reconstruct disputed transactions.

Both customers rejected partial “goodwill” settlements offered without an admission of liability.

Both were referred to the National Financial Ombud (NFO).

And while the NFO dismissed the Segers complaint, the Ombud has declined to publicly discuss the merits of individual complaints.

The African Chronicle put the specific discrepancies to Standard Bank and the NFO. Their responses are set out below.

R435,350 gone in three minutes

The first case began on 8 August 2025, when R435,350, described by the family as the life savings of Karen Segers’ mother, was transferred from her Standard Bank account in three transactions between 11:35am and 11:38am.

All three payments went to a single Discovery Bank/OVEX-linked beneficiary.

Standard Bank’s own audit records show that the account’s monthly payment limit was increased from R30,000 to R300,000 at 11:33am.

A new beneficiary was added one minute later.

At 11:36am, the payment limit was increased again, this time to R500,000.

The disputed payments followed almost immediately.

Then, at 11:40:03am, Standard Bank’s systems recorded a “soft block” on the card and activated its hot-card indicator.

A transaction attempted approximately a minute later was rejected with the system message:

“TRANS REJECTED – HOT CARD INDICATOR.”

At first glance, the sequence appears straightforward: the bank’s fraud controls detected suspicious activity, blocked the card and stopped further payments.

But another entry in the same audit trail complicates that account.

At 11:42:26am, the system records a further transaction of R10,200.

READ MORE: Warning Signs for Africa’s Economies as Top Currencies Come Under Pressure

That transaction occurred after the hot-card indicator had been activated.

The NFO subsequently concluded that the fraud controls had worked as intended.

In a ruling dated 15 July 2026, adjudicator Muhali Sekoaila wrote:

“The evidence shows that the soft lock successfully prevented further payments to third-party beneficiary accounts.”

But the family was left with another question: if the fraud alert was triggered at 11:40:03am, why did the first SMS notification only reach the client’s phone at 11:56am?

That was approximately 21 minutes after the final disputed payment had already gone through.

The “Android OS 36” mystery

The family also obtained Standard Bank records identifying the device used to authenticate the disputed transactions.

The device was recorded as running “Android OS 36.”

The same designation appeared against the same device identifier in records dating back to at least 15 July 2025, before the fraud occurred, and continued to appear afterwards.

The family questioned what the designation meant and whether it accurately identified the device’s operating system.

The NFO did not accept the argument as presented.

Standard Bank
Standard Bank’s Berea Centre branch. Picture: Standard Bank

Sekoaila told the family that the Android device classification had previously been explained and that the issue would only be reconsidered if they obtained confirmation from the manufacturer that the device did not have an internal software version identifier of OS 36.

Justin Segers, who has represented his mother in the dispute, says that response places an unreasonable burden on the victim.

“A functioning security protocol does not selectively bypass an active fraud block.”

He also said:

“They are forcing a 60-year-old fraud victim to prove a negative to clear her name.”

Segers accused the NFO of failing to properly engage with what he regards as significant evidence, including hardware identifiers and delayed notifications.

The NFO ultimately dismissed the complaint.

“On the available evidence, we are unable to conclude that the Bank acted improperly… Accordingly, we are unable to uphold your complaint.”

Standard Bank’s explanation: the R10,200 was money coming in

The bank’s response to the apparent post-block transaction is unequivocal.

The R10,200 was not a fraudulent debit, it says. It was a credit into the account.

Standard Bank explained that blocking a card prevents further debits but does not prevent money from being credited to the underlying account.

That explanation resolves the apparent contradiction in the bank’s view.

But it also illustrates the central difficulty running through the case: the same raw digital record can look materially different depending on how the bank classifies the transaction.

The family’s concern was not simply whether R10,200 left the account. It was why a transaction appeared in the audit trail after a security control had supposedly been activated.

Why did the fraud alert take 21 minutes?

Standard Bank also disputes the suggestion that the customer simply waited 21 minutes for the bank to alert her.

It says its fraud response is layered and does not depend solely on SMS notifications.

According to the bank, it attempted to call Segers’ mother at 11:40:24am and 11:40:36am, but both calls went to voicemail.

Further attempts were made at 12:08:11pm and 12:33:05pm.

The SMS messages formed part of that broader contact process, the bank said.

The client eventually called the bank at 5:22pm to confirm the fraud.

Who authorised the payment-limit increases?

Another critical question concerns the two payment-limit increases that occurred in the minutes immediately before the fraudulent transfers.

Why did the system allow the limits to jump from R30,000 to R300,000 and then R500,000 without requiring an OTP?

Standard Bank says the answer lies in its trusted-device system.

READ MORE: ECOWAS, World Bank Advance West Africa Digital Identity Integration

The bank said the device was already recognised and trusted through its DigiMe authentication platform.

“The system recognised the payment limit increase as being performed from the customer’s authenticated and trusted device.”

That explanation is significant because the fraudulent payments were then made from the same authenticated customer profile.

Standard Bank says the customer’s device itself had been compromised.

Bank blames malware for the fraud

After reviewing the evidence, Standard Bank said it found no authentication bypass, security-control failure or systemic weakness.

Instead, it believes a Remote Access Trojan (RAT) had been installed on the customer’s device.

According to the bank, the malware allowed fraudsters to operate through the customer’s legitimate banking profile.

Standard Bank
Standard Bank’s online banking platform. Picture: Standard Bank

“Based on all the evidence reviewed, the Bank has not identified any authentication bypass, security control failure or systemic weakness.”

The bank said its conclusion was corroborated by the customer’s affidavit.

It also said it has since introduced additional malware detection capable of blocking app logins where known malware is detected, as well as in-app approval and decline prompts for risky transactions.

The family’s dispute, however, remains centred on what happened during the original transactions and whether the available evidence conclusively supports the bank’s reconstruction.

Second case: the Google Wallet transaction trail

The second case raises a different, but potentially equally important, question.

Sean Noble’s dispute centres on Standard Bank Case Number 66836310 and a Google Wallet token that the bank says was added to his card on 17 June 2026.

Standard Bank initially told Noble that the wallet registration had been authenticated through his biometrics.

Complaint Resolution Centre Manager Soraya Gamsu said the authentication requests were delivered to the device registered on Noble’s banking profile and that the wallet provisioning process was completed.

The bank also said two SMS notifications confirming the Google Pay registration had been delivered.

Noble says none of that happened.

“No authentication was done via my handset. It was in my possession the whole time.”

He says he did not receive the SMS messages and that his own records support his position.

That evidence became particularly significant when his Gmail history was examined.

Google records show notifications when payment cards were legitimately added to his Google Account in April 2020, February 2021, June 2022, November 2023 and 24 May 2026.

There is no corresponding notification for 17 June 2026, the date Standard Bank says the disputed wallet was provisioned.

His Google Wallet and Google Pay histories likewise contain no transactions corresponding to those the bank says were processed through the wallet.

Noble therefore asked a simple question: if the wallet was legitimately registered to his device, where is the digital trail?

Standard Bank’s account changes

When The African Chronicle put that discrepancy to Standard Bank, the bank maintained that the wallet had been legitimately provisioned.

But it also provided an explanation that had not appeared in its earlier account.

The wallet, Standard Bank now says, was provisioned on another device belonging to the fraudster.

“Since this wallet was provisioned on another device (fraudster’s device) those transactions would not necessarily appear in Mr Noble’s own Google Wallet history.”

The bank says Noble was allegedly tricked into authenticating the wallet himself during a voice-based phishing attack, known as “vishing”.

Under that explanation, the customer’s authentication was legitimate from the bank’s perspective, but the device receiving the wallet token was controlled by the fraudster.

That distinction is central to the dispute.

READ MORE: Ethiopia Begins $12.5 Billion Construction of ‘Africa’s Biggest Airport’

Noble says he did not authorise the wallet registration and has asked the bank to provide IP information that could help establish where the authentication requests originated.

Standard Bank says it did not interrogate that information at the time because the wallet had passed its authentication checks.

“Unfortunately, since the wallet and card were provisioned by the customers via authentication, we trusted the transactions and had no reason to review this.”

The bank says IP addresses may also be unreliable depending on network configuration and that privacy obligations prevent it from releasing information that could identify third-party devices or credentials.

It declined to disclose details of its fraud-detection and anomaly systems.

Noble says there is no trace on his devices

Noble remains unconvinced.

His position is that his phone was in his possession and that the absence of expected Google notifications and wallet records raises questions about the bank’s account.

He also alleges that further fraudulent transactions were attempted after he had moved money from the account and blocked his card.

Standard Bank says its review found no evidence of any successful transaction after the block was applied.

It acknowledged that fraudsters may continue attempting transactions after a card has been blocked.

Noble has described his experience as part of a pattern.

“I have personally fallen victim four times… After every time, I was blamed by Standard Bank and offered peanuts in compensation.”

He has called for affected customers to consider a collective response to the bank’s executive leadership.

The bank admits more protection is needed

Despite defending its handling of the Noble case, Standard Bank acknowledged that digital wallets present an area where further protections are needed.

“We acknowledge that more can be done to better protect customers who utilise wallet based transactions.”

The bank said it has already increased protection for this scenario.

That admission does not amount to an acknowledgement that its systems failed in Noble’s case.

But it does underline the growing importance of digital-wallet security as banking fraud moves beyond traditional card and account compromises.

Standard Bank rejects any systemic failure

In both cases, Standard Bank’s central position remains the same: its security systems were not bypassed and there was no systemic weakness responsible for the losses.

In the Segers case, the bank attributes the fraud to malware on the customer’s device.

In Noble’s case, it says the customer was allegedly manipulated into authenticating the wallet through a vishing attack, after which the wallet was provisioned on a fraudster’s device.

The bank also maintains that its goodwill offers were made without an admission of liability.

The Segers family’s 25% offer, made on 14 October 2025, is no longer available, Standard Bank said, because it was not accepted and the matter has since been reviewed internally and by the NFO.

NFO refuses to adjudicate through the media

The National Financial Ombud declined to debate the individual complaints publicly.

Its position is that it does not comment on the merits, evidence, findings or status of individual cases in the media.

The NFO said the Segers family can still seek an internal review or escalation if it remains dissatisfied or obtains new information that could materially affect the outcome.

In Noble’s case, the NFO said it could not confirm whether a complaint had been lodged without a reference number.

It also pointed out that its jurisdiction does not extend to third parties such as Google, meaning it cannot compel Google to provide information.

What the documents leave unanswered

The two cases do not establish that Standard Bank’s systems failed.

Nor do they, on the evidence available, establish that either customer’s account of events is definitively correct.

READ MORE: Retired teacher loses R1.2m in scam, Nedbank responds with R20k ‘goodwill’ payout

But the documents raise questions that deserve scrutiny.

In the Segers case:

  • Why were the payment limits increased dramatically within minutes of the disputed transfers?
  • Why did the system recognise the device as trusted?
  • What precisely triggered the fraud controls at 11:40:03am?
  • Why does the audit trail show a further R10,200 transaction afterwards?
  • Why did the first SMS notification only arrive at 11:56am?
  • What exactly does “Android OS 36” represent in the bank’s records?
  • And what evidence supports the bank’s conclusion that malware was responsible?

Standard Bank has provided explanations for each of these issues.

But the fact that those explanations rely heavily on technical classifications, trusted-device authentication and alleged malware creates another challenge for customers: how can an ordinary banking customer independently test the bank’s reconstruction of events when the underlying systems are controlled by the bank?

The Noble case raises a similar question.

If the wallet was provisioned on a fraudster’s device, as Standard Bank now says, then the absence of the transaction history on Noble’s device may be explainable.

Standard Bank
People walk past a Standard Bank banner in Johannesburg. Picture: Getty Images

But the dispute then turns on a different evidential question: what independent evidence proves that Noble himself authenticated the wallet registration?

The bank says its records show that authentication took place.

Noble says he did not authorise it.

The requested IP information could potentially help establish where the authentication activity originated, but Standard Bank says it did not interrogate that information at the time and will not provide information that could expose third-party devices or credentials.

Two customers. Two explanations. One recurring problem.

What emerges from both cases is not proof of a banking-system failure, but a troubling evidential imbalance.

The bank controls the authentication systems, device records, fraud-monitoring platforms and transaction logs used to reconstruct disputed events.

Customers are then expected to challenge those records using evidence they can independently obtain from their phones, Google accounts, SMS records and other third-party sources.

In both disputes, customers say that evidence does not neatly fit the bank’s account.

Standard Bank says it has investigated the cases and found no security-control failure.

The NFO has either dismissed the complaint or declined to discuss its merits publicly.

And the customers remain dissatisfied.

READ MORE: ‘This is not good enough’: Harrismith woman rejects R16,000 offer from Standard Bank after R60,000 fraud

For Segers, the issue is whether the evidence used to blame malware adequately explains the sequence recorded in the bank’s own systems.

For Noble, it is whether the bank can demonstrate that he actually authorised a Google Wallet registration that he says never happened.

Both customers rejected goodwill settlements.

Neither received an admission of liability.

And in both cases, the final explanation places responsibility for the fraud on the customer’s compromised device or alleged authentication behaviour rather than on a failure of the bank’s security controls.

That leaves the central question unresolved:

When a bank’s digital records contradict a customer’s experience, who gets to decide what the evidence means?

Bheki Dlamini

Bheki Dlamini

Subscribe to Our Newsletter

Keep in touch with our news & offers

Thank you for subscribing to the newsletter.

Oops. Something went wrong. Please try again later.

Also listen on

D

Enjoy Unlimited Digital Access

Read trusted, award-winning journalism. Just $2 for 6 months.
Already a subscriber?
What to read next...
Kovsies Striker Omphemetse Athibeng Set for Botswana Move Amid PSL Interest

Kovsies Striker Omphemetse Athibeng Set for Botswana Move Amid PSL Interest

University of the Free State (UFS) star forward Omphemetse Athibeng looks set to take the next big step in his blossoming football career. Despite drawing significant interest from local Premier Soccer League (PSL) and Motsepe Foundation Championship sides, reports indicate that the dynamic Kovsies marksman is on the verge of securing a move to the …

Leave a Reply

Your email address will not be published. Required fields are marked *