Fraudulent "FACEBK" Transactions Hit Major Banks' cards in SA

FACEBK Hack hits Major South African accounts
South Africans with credit cards issued by First National Bank (FNB), Standard Bank, Nedbank, Capitec, and Absa are reporting fraudulent transactions  that appears to be processed by Facebook, which are depleting their accounts. StormWarning!, has become aware of Major Bank customers complaining of large amounts deducted from their cards. In each case, the transaction descriptions included the contraction “FACEBK.”

One Absa customer reported that their bank blocked the fraud attempt before any money was deducted. However, others were not as fortunate. One victim reported 19 fraudulent transactions, while another said they identified the fraud only after receiving an SMS notification.

Many affected customers stated they had not linked their cards to a Facebook account or made purchases on the platform. Social media platforms like Twitter/X and Reddit revealed numerous similar complaints, with victims reporting odd transaction amounts, such as R941.67, R1,596, R2,997.72, and R9,262.06.

Standard Bank also experienced a temporary outage, prompting speculation of a possible connection between the fraud and a cyberattack. However, StormWarning! found that this wave of card fraud is not limited to Standard Bank or FNB but is part of a global issue, with reports surfacing from as far as the Philippines.

Fraudulent Advertising Credits and Facebook Hacking Scams

Cybercriminals appear to be using stolen credit card information to purchase Facebook advertising credits. These credits are likely used to promote scams and other malicious activities. StormWarning! has previously reported an increase in Facebook account hacking, where compromised accounts are exploited for scams.

The fraudulent transactions bypassed 3D Secure authentication, a system that typically requires users to approve transactions via an app or multi-factor authentication. Large merchants like Facebook often opt out of 3D Secure to streamline transactions but assume the associated fraud risk. Victims should be eligible for refunds, although some banks make the claims process challenging.

How Card Details Are Being Compromised

It remains unclear how credit card details were stolen. One retired banker suggested toll booth operators could be responsible, citing an incident where their card was briefly out of sight at SANRAL toll gates. However, other possibilities include breaches at payment processors or leaks from multiple sources.

Bank Responses and Mitigation Strategies

FNB

Chris Boxall, FNB’s Head of Card Transact and Fraud, acknowledged fraudulent transactions from false Facebook merchants. He emphasized that impacted customers would be reimbursed once the fraud cases were resolved. FNB has introduced measures to mitigate such fraud and advised customers to use virtual cards with dynamic CVV numbers for added security.

Standard Bank

Standard Bank investigates fraud cases individually and highlighted the role of fraudsters using stolen cards to purchase online advertising. The bank called for stricter verification processes for advertisers and robust payment security measures, such as multi-factor authentication and machine learning-powered fraud detection.

Capitec

Capitec reported no significant increase in “FACEBK” fraud but stated it actively monitors such cases. If fraud occurs without secure authentication, Capitec assists clients with the chargeback process. It collaborates with other banks to share insights and improve fraud detection.

Absa

Absa confirmed it invests heavily in fraud prevention, enabling it to proactively block many suspicious transactions. Ally Mafunzwaini, Absa’s Executive: Fraud Solutions, highlighted the bank’s commitment to customer protection through advanced monitoring tools and a dedicated fraud team.

Nedbank

Nedbank stated its fraud detection system prevented a significant percentage of fraudulent transactions but acknowledged the difficulty in blocking legitimate Facebook advertising purchases. Victims are reimbursed through the chargeback process, except when disputes involve service delivery rather than unauthorized transactions.

Facebook Silent on the Issue

StormWarning! reached out to Facebook for comment but received no response before publication.

Conclusion

The fraud highlights the vulnerability of online transactions and the need for robust security measures by banks and merchants. Customers are encouraged to use secure payment methods and remain vigilant to protect themselves against fraud.

Storm Warning wh cloud 300

Protect Your Business and Customers from Cybercrime with StormWarning!

Is your business prepared to combat sophisticated fraud schemes like the
global "FACEBK" cybercrime wave targeting South Africans? Fraudulent
transactions are skyrocketing, exposing vulnerabilities in online payment
systems and customer data security.

With StormWarning!,
your organization gains the ultimate shield against cyber threats:
Automated NIST Cybersecurity Audits:
      Identify vulnerabilities before hackers do.

AI-Powered Risk Detection:
      Stay ahead of evolving fraud tactics.

Tailored Training Solutions:
      Empower your team with over 100 cybersecurity lessons.

Real-Time Fraud Mitigation:
      Protect sensitive data and financial systems proactively.

Stop fraud in its tracks before it drains your accounts or
damages your reputation. Protect what matters with StormWarning!

🔒 Secure Your Future Today
Contact StormWarning!  for a free consultation and see how we can fortify your defenses.

StormWarning! – Your Frontline Defense Against Cybercrime.
Protect. Prevent. Prevail.

PROTECT YOUR BUSINESS NOW!

 CYBER THREATS ARE ON THE RISE—ARE YOU PREPARED?

Over 2,200 cyberattacks happen every day—one every 39 seconds.

AI-driven phishing scams are on the rise—don't fall victim to them!

95% of breaches are due to human error. Strengthen your defenses now.

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.