Quick answer
Learn how to report cybercrime in South Africa, preserve digital evidence, notify the right organisations and recognise when legal help is needed.
Key takeaways
- Use a verified bank, platform or provider channel immediately where it can freeze funds, secure an account or preserve data.
- Preserve original digital material and context; a cropped screenshot is useful orientation but rarely the strongest record by itself.
- Report the crime at a SAPS station, provide a factual statement and retain the CAS number.
- Do not “hack back”, impersonate the suspect, pay a recovery agent or destroy a device to make it safe.
1. Decide whether the event may be criminal
The Cybercrimes Act creates several offences relevant to a complaint. The facts may involve:
- unlawful access to a computer system or storage medium;
- unlawful interception of data;
- unlawful interference with data, a computer program, storage medium or system;
- unlawful acquisition, possession, provision or use of passwords, access codes or similar authentication data for specified offences;
- cyber fraud, cyber forgery or cyber uttering;
- cyber extortion;
- theft of incorporeal property;
- a data message intended to incite property damage or violence;
- a data message threatening property damage or violence in the circumstances defined by section 15; or
- unlawful intentional disclosure of an intimate image without consent.
Not every harmful online event fits one of those offences. A supplier dispute, failed service, ordinary account error, defamatory statement, workplace-policy disagreement or privacy complaint may require a civil, contractual, labour, consumer or regulatory route instead of, or alongside, a criminal complaint. Conversely, conduct described casually as a “scam” may involve cyber fraud, common-law fraud, theft, identity misuse or several connected offences.
Do not delay a genuine complaint because you cannot choose the exact section. Describe what the person did, what system or account was affected, what representation or demand was made, what access was authorised, what loss or risk followed and which evidence supports each fact. SAPS and the prosecuting authority are responsible for the criminal investigation and charge decision.
2. Stabilise the incident without destroying evidence
The correct first technical step depends on the incident. A compromised email account, ransomware event, fraudulent bank transfer, stolen phone and threatening message do not have the same containment plan. Use these priorities.
Protect people first
If a message threatens imminent violence, someone is being located or followed, or a person is otherwise in immediate danger, call 10111 and move to a safer place where possible. Do not arrange a meeting with the sender to obtain proof.
Try to stop active financial loss
Contact the bank, card issuer, payment provider or relevant platform through a verified number or in-app channel. Ask what can be blocked, recalled, frozen or disputed and obtain a reference number. Do not wait for a lawyer's appointment or a completed police statement before telling the institution that funds or credentials may be at risk.
Use contact details obtained independently from the institution's official site, app or card. A number supplied in the suspicious message may lead back to the perpetrator.
Secure accounts from a clean device
Where it is safe and technically appropriate, use a known-clean device to change exposed passwords, end unfamiliar sessions, replace recovery details and enable multi-factor authentication. First record the relevant alerts, login history, sender details and account changes that remain visible. If a business system or administrator account is affected, let an incident-response professional coordinate the change so that logs and volatile evidence are not lost unnecessarily.
Isolate, do not improvise
Disconnecting an affected device or network segment may limit further harm, but shutting down, wiping, reinstalling, running “clean-up” tools or repeatedly logging in can alter evidence. Record the device, screen state, date, time and action taken. For ransomware, server compromise or a material business incident, use a qualified technical responder to decide what should be isolated, captured or left running.
Do not counter-attack
Do not enter a suspected perpetrator's account, deploy tracking code, impersonate another person, publish credentials or try to recover data by gaining unauthorised access. A complainant can create fresh legal exposure and contaminate the evidence by “hacking back”.
3. Preserve the evidence in its original context
Section 15 of the Electronic Communications and Transactions Act says a data message cannot be denied admissibility merely because it is electronic. Its evidential weight depends on matters including how it was generated, stored or communicated, how integrity was maintained and how the originator was identified. That makes context and provenance important.
Create a protected evidence folder and an index. Preserve, where available:
- original emails in their native format, including full headers and attachments;
- complete message or chat exports rather than selected screenshots only;
- the exact URL, profile URL, username, account identifier and visible post date;
- screenshots showing the full screen, app, date, time and surrounding exchange;
- login alerts, session histories, password-reset notices and provider security emails;
- bank statements, payment confirmations, beneficiary details and transaction references;
- call logs, voicemail or voice-note files and the number or account used;
- ransom notes, wallet addresses and payment demands without opening unsafe attachments;
- device names, serial numbers, phone numbers, SIM details and affected account addresses;
- system, firewall, access, audit and application logs held by the organisation or provider;
- contracts, authorisation records and access lists showing who was permitted to do what;
- notices sent to a bank, platform, insurer, employer, regulator or incident-response team; and
- every reference number, acknowledgement and response received.
Keep the first preserved copy unchanged and work from a duplicate. Record who exported, downloaded, copied or received each item, when they did so, from which source and where the protected original is stored. A forensic specialist may create verified images and cryptographic hashes for a material matter, but do not manufacture technical evidence or claim a chain of custody that was not maintained.
If the material may be illegal to possess or redistribute, including child sexual abuse material, do not download, forward or create extra copies merely to prove that it exists. Record the safest available location and account details, stop viewing it and obtain immediate reporting guidance from SAPS.
4. Build a complaint pack before going to SAPS
The SAPS public reporting page says a victim may go to the nearest police station to report a crime at no charge. A police official at the Community Service Centre interviews the complainant, takes a statement, registers the case in the Crime Administration System and supplies a CAS number for future enquiries.
A clear pack can reduce avoidable confusion. Prepare:
- Identity and authority: the complainant's identification and contact details, plus proof of authority where reporting for a company or another person.
- One-page incident summary: what happened, when it began, when it was discovered, what remains active and the immediate harm.
- Chronology: dated events with the time zone, action, account or device, person involved and supporting exhibit number.
- Access baseline: who had lawful access, what level of access each person had and when any authority ended.
- Loss schedule: each transaction, charge, business interruption or other claimed loss, separated from estimates that are not yet proved.
- Suspect indicators: names used, phone numbers, email addresses, profile links, account numbers, wallet addresses, domains and IP information actually available.
- Evidence index: a numbered list connecting each factual statement to an original or preserved copy.
- Containment record: password changes, account freezes, device isolation or provider actions and the time each occurred.
- Parallel reports: bank, platform, insurer, regulator and Cybersecurity Hub references.
- Open risks: disappearing logs, ongoing access, threatened publication, vulnerable people or an approaching contractual deadline.
Use neutral language. Separate what you directly observed from what another person told you and from what you infer. Do not inflate the loss, identify someone as the offender without evidence or sign a statement that you know is inaccurate.
5. What to obtain and keep after reporting
Ask for and preserve the CAS number. Keep the station name, date, time and a copy or accurate record of the statement and exhibits supplied. When a detective is allocated, keep the detective's details and use the CAS number in follow-up enquiries.
If additional evidence arrives, preserve it using the same method and tell the investigating officer rather than replacing the earlier version. Keep a delivery record for any device, drive or original document handed over, including what was delivered, to whom and when.
The criminal-lawyer directory is relevant where the complaint is legally complex, the complainant may also face allegations, or criminal procedure needs to be coordinated with another urgent remedy.
6. Make the necessary parallel reports
A SAPS case is the criminal route. Other reports may reduce loss, protect people or meet separate duties, but they have different functions.
Bank or payment provider
Notify the institution immediately through a verified fraud channel, follow its internal complaint process and retain every reference and written decision. If a customer has exhausted the bank's usual complaint process and remains dissatisfied, the Banking Division of the National Financial Ombud Scheme says it can consider areas including internet-banking and credit-card fraud for participating banks. Ombud review does not replace the criminal case.
Platform, email host or telecommunications provider
Use the provider's compromised-account, impersonation, abuse, preservation or takedown process that matches the incident. Preserve the content and identifiers before requesting removal where that can be done lawfully and safely. A platform report may secure an account or restrict content, but it does not create a SAPS case.
Cybersecurity Hub
The national Cybersecurity Hub accepts incident reports and coordinates or routes incidents to relevant authorities and sector response teams. Its published process says cybercrime or cyberbullying incidents are routed to SAPS. Use the Hub where coordination is useful, but do not rely on a Hub reference as a substitute for laying a criminal complaint at a police station.
Information Regulator
If an organisation is the responsible party for personal information that has been accessed or acquired by an unauthorised person, section 22 of POPIA may require notification to the Information Regulator and affected data subjects as soon as reasonably possible, subject to the statutory qualifications. The Regulator states that all security compromises must be reported and that, since 1 April 2025, notifications must use its eServices portal.
That is an organisational privacy duty, not a general duty imposed on every individual cybercrime victim. An individual who believes someone has violated their personal information may use the Regulator's POPIA complaint service, but should still report suspected crime to SAPS.
Insurer, employer or contractual counterparty
Cyber, crime, fidelity, professional-indemnity or other cover may have prompt notice and cooperation conditions. Employment, supplier and customer contracts may also require incident notice. Check the actual documents; do not invent a universal number of hours.
Protection from harassment
Where repeated or harmful electronic communication amounts to harassment, the Department of Justice says a person may apply at a magistrate's court under the Protection from Harassment Act. The process recognises electronic communication and can assist even where the respondent's identity is not yet known. Legal representation is not required, although advice may help in a complex, urgent or overlapping criminal matter.
7. Do not apply the printed 72-hour rule to every victim
Section 54 of the Cybercrimes Act is printed as a reporting duty for specified electronic communications service providers and financial institutions, with reporting without undue delay and, where feasible, within 72 hours for prescribed offence categories. It is not drafted as a general victim-reporting deadline.
More importantly, the official commencement record reviewed on 21 July 2026 still states that section 54 was excluded from the provisions brought into operation on 1 December 2021. The prescribed categories and reporting mechanics are part of that deferred framework. Do not tell an individual that the Cybercrimes Act gives them a universal 72-hour deadline, and do not advise a provider or institution that section 54 currently applies without confirming whether a later commencement and regulations have since taken effect.
Delay can still be harmful. Banks, insurers, platforms, contracts and POPIA have their own rules, and technical logs can be overwritten. Act promptly because containment and evidence are time-sensitive, not because every complainant is governed by the printed section 54 period.
8. Be careful with the Act's printed protection-order procedure
Sections 14 to 16 criminalise the defined malicious communications: incitement of property damage or violence, qualifying threats of property damage or violence, and non-consensual disclosure of an intimate image. Those offences were included in the operative portion of Chapter 2.
The Act also prints a Part VI procedure for a complainant to seek a magistrate's-court order restricting further disclosure or requiring a provider to remove or disable access to a data message. However, Part VI was expressly excluded from the 1 December 2021 commencement proclamation, and the current official Act page reviewed for this guide does not record a later commencement.
Do not promise that specific Cybercrimes Act application as an available current remedy without updated verification. Depending on the relationship and conduct, an operative Protection from Harassment Act or Domestic Violence Act process, a platform remedy, a civil interdict or another statutory route may be relevant. The correct route and evidence should be assessed urgently where safety, intimate material or threatened publication is involved.
9. When a lawyer should be involved early
Prioritise legal help where:
- a threat suggests immediate physical harm or continued stalking;
- intimate images are disclosed or threatened;
- ransomware or cyber extortion affects access to systems or data;
- a bank transfer, card transaction or crypto transfer is disputed and recovery steps are contested;
- a platform, provider or overseas entity holds data that may soon be deleted;
- the incident affects customers, employees or other data subjects and POPIA duties may apply;
- an employee, contractor, director or service provider is suspected;
- disciplinary action, suspension, device access or workplace monitoring is contemplated;
- an insurer reserves rights, rejects cover or requires a formal loss submission;
- the conduct crosses borders or uses foreign platforms, accounts or infrastructure;
- the complainant accessed systems, shared credentials, paid an extortion demand or took countermeasures that may create exposure;
- the facts combine criminal, civil, contractual, employment, privacy or intellectual-property issues;
- SAPS reporting has failed to produce a usable record of the complaint;
- a child or vulnerable person is affected; or
- public statements about the incident could prejudice the investigation or create defamation, privacy or contractual risk.
A lawyer can define the scope of the instruction, identify the relevant routes, organise the complaint and loss material, coordinate an independent forensic specialist, advise on notices and preservation requests, and assess urgent court relief. The lawyer should not alter the technical record, promise a prosecution or describe a disputed suspect as guilty.
The cyber-crime lawyer route supports specialised discovery. For a wider comparison, use the lawyer directory or law-firm directory, and ask specifically about cybercrime complaints, digital evidence, urgent applications, POPIA and any bank, employment or commercial overlap.
FAQs
Can I report cybercrime at any local police station?
The SAPS public guidance directs victims of computer crime, identity theft and commercial scams to a local police station. The general crime-reporting page says the complaint is taken at the Community Service Centre, registered in the Crime Administration System and given a CAS number. Call 10111 for an emergency.
Must I know the exact Cybercrimes Act offence before reporting?
No. Give SAPS a truthful account of the access, communication, transaction, interference or demand, the authority that existed and the harm that followed. Organise the supporting evidence and avoid asserting facts you cannot prove. Police and prosecutors determine the legal classification.
Are screenshots enough evidence?
Screenshots can show what was visible, but preserve the original email, message export, header, URL, profile identifier, transaction record, log or file where possible. Electronic evidence carries more weight when its generation, storage, integrity and origin can be explained.
Is there a 72-hour deadline to report cybercrime?
There is no universal 72-hour Cybercrimes Act deadline for every victim. Printed section 54 concerns specified providers and financial institutions, not all complainants, and the official commencement record reviewed for this guide says section 54 was excluded from commencement. Separate bank, insurer, platform, contractual and POPIA timing rules may still require immediate action.
Does reporting to the Cybersecurity Hub replace a SAPS case?
No. The Hub coordinates and routes incidents; its published process says cybercrime incidents are routed to SAPS for resolution. Lay the criminal complaint at a police station and retain the CAS number. Keep the Hub reference as a separate coordination record.
When is a lawyer more useful than handling the complaint alone?
Legal help is particularly useful where safety, intimate material, disappearing provider data, material financial loss, business systems, POPIA, employees, insurers, cross-border actors, urgent court relief or the complainant's own possible exposure are involved. A routine factual complaint can still be reported directly to SAPS without waiting for a lawyer.
Related Lexuno paths
Source notes
- South African Government: Cybercrimes Act 19 of 2020
- Department of Justice: Cybercrimes Act 19 of 2020 PDF
- South African Government: Proclamation 42 of 2021
- South African Police Service: Report a crime
- South African Police Service: Cybercrime prevention and reporting guidance
- SAFLII: Electronic Communications and Transactions Act 25 of 2002
- Information Regulator: POPIA security-compromise guidance
- Cybersecurity Hub: Report an incident
- Cybersecurity Hub: Incident management process
- National Financial Ombud Scheme: Banking Division
- Department of Justice: Protection from Harassment Act guidance and forms
Legal note
This article is general legal information for South African readers. It is not legal advice. Speak to a qualified legal professional about your specific facts before taking action.

