
An appeal is made to all businesses to be aware of a scam doing the rounds.
Businesses receive what appears to be a confirmed tender proposal on the letterhead of a government department. Afterwards, they are contacted and payment arrangements are made.
However, the business person is advised to make a deposit directly into the account of the supplier and told that a delivery note will be forwarded to them once the goods are received. Once the business person makes payment into the ‘supplier’ account provided, a delivery note is faxed to them.
The business person only discovers the fraud when they demand payment from that government department, only to be told that there was in fact no tender authorised or sent out.
At face value, the documents appear legitimate… Therefore it is important for businesses to verify the documentation they receive for a government tender. They must call the government office to verify the tender, but should not use any numbers depicted on the tender documents because these may in fact be those of the fraudsters.
Furthermore, do not use Internet search engines, since you may also fall victim to “phishing”, which is explained below. Rather get numbers from the telephone directory.
Also read: Beware of new WhatsApp scam doing the rounds in South Africa
Also read: Beware of carjacking scam
Also read: Beware of ‘Wangiri’ phone call scam
Every business must be wise when entering into any business deal, tender or Internet transaction. Use caution and do not accept anything at face value.
“Phishing” is an email-based attack when a malicious email is sent to you with the purpose of getting you to disclose sensitive information about yourself or the business. It is also the most common means of obtaining information to attack an organisation or unsuspecting users.
These false emails often look surprisingly legitimate and even the web pages, where you are asked to enter your information, might look genuine. However, the URL in the address field can alert you as to whether the page you have been directed to is valid or not.
Different emails are being sent to attract victims. Some emails might refer to your personal information that needs to be updated or validated, and being asked to enter your username and password.
Other emails might even ask you to enter more information, such as your full name, address, phone number and credit card numbers. By just visiting the false website and entering your username and password, the “phisher” might be able to gain access to more information by logging into your account.
How to deal with “phishing” scams :
- Do not trust poorly-written emails with spelling errors or incorrect grammar. Legitimate corporate companies have quality control measures in place that prevent these mistakes from creeping in.
- Do not click on any links in the emails. Rather navigate directly to the website in question.
- If you are uncertain about the authenticity of an email, rather ask your service provider directly whether it is valid or not.
- If possible, visit the company personally or phone the customer contact centre number of their official website (remember not to trust phone numbers in a suspicious email!)
- Only provide personal or financial information through an organisation’s website when you have typed in the web address yourself and have seen indicators that the site is secure, such as a URL that begins with “https” (the “s” stands for secure). Unfortunately, an indicator is not a total guarantee that a site is secure; some “phishers” use forged security icons.
- Review your credit card and bank account statements as soon as you receive them to check for unauthorised charges. If your statement is late by more than a couple of days, call the bank to confirm your billing address and account balances.
- Be cautious about opening attachments and downloading files from emails, regardless of who sent them. These files might contain viruses or other malware that can weaken your computer’s security.
- Use trusted security software and set it to update automatically.
- Do not send personal or financial information in an email, as it is not a secure manner of transmitting confidential information.



