Quick answer
If someone has used your identity in South Africa, work on containment, correction, reporting and evidence at the same time. Secure the email account, mobile number and device that control password resets. Contact every affected bank, credit provider, mobile operator, retailer or platform through independently verified channels, open a fraud case and ask what can be frozen while it investigates. Report suspected identity theft at a police station and retain the CAS number. Obtain credit reports from current registered credit bureaus and dispute every unauthorised entry with the bureau that holds it.
Key takeaways
- If someone has used your identity in South Africa, work on containment, correction, reporting and evidence at the same time. Secure the email account, mobile number and device that control password resets. Contact every affected bank, credit provider, mobile operator, retailer or platform through independently verified channels, open a fraud case and ask what can be frozen while it investigates. Report suspected identity theft at a police station and retain the CAS number. Obtain credit reports from current registered credit bureaus and dispute every unauthorised entry with the bureau that holds it.
- Do not assume that a police case, a provider fraud reference or a South African Fraud Prevention Service registration will automatically correct every account. Each record holder may need its own written dispute and evidence. Preserve the application, messages, account history and authentication records where available; do not admit liability or make a payment merely to remove a fraudulent account. Court papers, debit orders, SIM changes, tax records and company-director changes have separate response routes and deadlines.
1. Confirm what has happened
Identity theft is not one administrative problem. A copied identity document may have been used to open credit, take over a mobile number, change an email recovery route, create a company relationship, redirect a payment or impersonate someone in communications. Start with verified facts rather than trying to reconstruct the entire scheme at once.
Create an incident table:
| Field | What to record |
|---|---|
| Discovery | Date, time and the alert, statement, call or document that revealed the problem |
| Affected service | Provider, account or application reference and independently sourced contact channel |
| Suspected act | New account, transaction, SIM change, profile amendment, credit enquiry or impersonation |
| Identity data used | Identity number, document image, address, phone, email, signature, selfie or other credential |
| Current risk | Money leaving, credit being extended, communications being intercepted or a deadline running |
| Action taken | Freeze, password reset, dispute, police report, affidavit, complaint or preservation request |
| Proof | Screenshot, statement, email, call reference, device log, application or correspondence |
| Next date | Provider response date, bureau dispute date, debit date, court deadline or escalation date |
Separate three things: an account you do not recognise, a transaction on a genuine account and a genuine account that another person has taken over. The provider may use different teams and evidence for each.
2. Secure the recovery chain first
An email inbox or mobile number can control password resets across several services. From a device you reasonably trust:
- change the primary email password and sign out unknown sessions;
- replace reused passwords on banking, mobile, cloud-storage and social accounts;
- enable the strongest multi-factor authentication the service supports;
- check recovery addresses, recovery numbers, forwarding rules and newly added devices;
- ask the mobile operator whether a SIM replacement, port or profile change occurred; and
- contact banks through the number on their official website or app, not a link in an unexpected message.
Record the time and reference for each call or digital action. Do not wipe a device, delete the suspicious message or reset an account before capturing the evidence that may explain how access occurred. If a device may be compromised, use another device for recovery and obtain technical advice where necessary.
3. Notify every affected provider in writing
Call urgently where money or access is at risk, then follow up in writing. Identify the account or application, state that it is disputed as unauthorised, explain how and when it was discovered, and attach only the evidence needed at that stage. Ask the provider to:
- issue a fraud or dispute reference;
- record that liability is disputed;
- stop or restrict further activity where its process permits;
- preserve the application, contact changes, device or channel records and communications;
- explain which documents it needs and the investigation timetable;
- provide the written outcome and reasons; and
- identify the route for escalating an unresolved complaint.
Use the provider’s current fraud or complaint channel. A genuine institution should not ask for a password, PIN or one-time password in order to “reverse” fraud. Preserve suspicious instructions and verify the institution independently.
Do not sign a broad settlement, acknowledge a debt or make a token payment before understanding the effect. A payment may complicate the factual dispute, and it does not establish that the provider has corrected the underlying application or credit record.
4. Obtain and compare current credit reports
Use the National Credit Regulator’s current register to identify registered credit bureaus rather than relying on an old online list. Obtain the reports relevant to you and compare:
- personal particulars, addresses, employers and contact details;
- recent credit enquiries and application dates;
- accounts, opening dates, balances and payment status;
- adverse information, judgments or collection activity; and
- duplicate or inconsistent records.
Save each report with its retrieval date. Mark every item as recognised, uncertain or disputed. The credit-bureau glossary explains the role of a bureau, while the credit and finance checklist can organise agreements, reports, statements and correspondence.
5. Dispute fraudulent credit information with the bureau
The National Credit Act and the NCR’s current complaint guidance provide a route for challenging inaccurate consumer-credit information. Start with the registered credit bureau that displays the entry. Give it the disputed account, the reason, supporting evidence and a safe contact method, and obtain a dispute reference.
The NCR’s Guideline 005/2024 says the bureau should mask the challenged information while it investigates and has 20 business days to resolve the dispute. The NCR’s December 2025 evidence guideline emphasises credible evidence from the source of the information and says a bare confirmation is not enough. Follow the date and process in the bureau’s actual acknowledgement, preserve the version of the report before and after the dispute, and do not treat masking as a final deletion decision.
If the bureau does not resolve the dispute satisfactorily, the NCR guideline describes escalation to the NCR using Form 29 and the bureau reference. It currently states that the consumer should lodge the NCR complaint within 20 business days after receiving the bureau’s evidence or outcome. Because forms and procedural guidance can change, confirm the current NCR requirement when escalating. An identity-theft affidavit or CAS number can support a dispute, but it does not replace the record-specific evidence and investigation.
6. Report suspected identity theft to SAPS
The South African Police Service says suspected identity theft or a commercial scam should be reported at a local police station. Give a clear statement and request the CAS number. The general crime-reporting guidance says reporting is free and that a registered case receives a case reference.
Take an indexed summary rather than an unfiltered device dump:
- identification and safe contact details;
- a one-page chronology;
- affected providers and account or application references;
- fraudulent messages, applications, transactions or profile changes;
- provider and bureau dispute references;
- known financial loss and current risk; and
- the location of original electronic evidence.
Ask how additional evidence should be supplied and record the investigating officer’s details when assigned. Do not claim that a person committed the offence unless the evidence supports that identification. A criminal investigation is separate from provider, credit-bureau, POPIA and court processes.
7. Consider SAFPS protective or victim registration
The South African Fraud Prevention Service offers consumer services including Protective Registration for lost or stolen identity documents and Victim of Impersonation support where a person’s identity has been fraudulently used. Its current guidance says a victim should contact the affected provider and report the matter to SAPS; supporting records may include a CAS number.
Use only the current SAFPS website and verify what information is requested. Keep any registration number securely and provide it to institutions where relevant. Registration may help participating organisations identify risk, but it does not cancel a fraudulent agreement, decide liability, correct every bureau entry or replace a provider dispute.
8. Use POPIA rights for inaccurate or unlawfully held data
Sections 23 and 24 of the Protection of Personal Information Act provide routes to request access to personal information and to ask a responsible party to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained. A request should identify the specific record and include credible supporting evidence.
Send a focused request to the organisation holding the disputed information. Ask what data it holds, the source and use where the applicable access right permits, and the correction or deletion sought. Keep delivery proof and the response. Do not use a correction request as a demand to erase accurate records that an organisation must lawfully retain.
The Information Regulator publishes POPIA forms, including Form 2 for correction or deletion and Form 5 for complaints, as well as an online complaints service. Its complaint categories include unauthorised sharing, security failures and failure to respond to a correction, deletion or objection request. Confirm the current form and portal before submission. The POPIA response checklist is useful for organising data categories and notices, although it does not replace this identity-recovery workflow.
9. Follow the route for the record that was changed
Some identity misuse creates a specialist problem:
| Record or event | Immediate route to investigate |
|---|---|
| Bank account, card, payment or debit order | Bank fraud and complaint channels; preserve statements, transaction data and call references. An external ombud route may exist only after the bank’s internal process and within its jurisdiction. |
| Mobile number, SIM or port | Mobile operator fraud and security process; secure email and banking recovery routes in parallel. |
| Credit account or enquiry | Provider fraud dispute plus each bureau displaying the information, followed by the NCR route where applicable. |
| Company or director information | CIPC customer and fraud channels; verify the company record and use the relevant statutory complaint or correction route. |
| Tax, grant, employment or benefit record | The responsible authority’s identity, fraud and record-correction process; protect any objection or appeal period. |
| Lost or stolen identity document | Report the document and follow the issuing authority’s current replacement or status process; consider SAFPS Protective Registration. |
Do not send one identity-document copy indiscriminately to every contact found online. Confirm the recipient, redact irrelevant data where accepted and use the organisation’s secure channel.
10. Build an evidence bundle that can be reconciled
Keep original files unchanged. Export working copies and create an index linking each item to the incident table. Useful categories include:
- the first alert, report or statement revealing the misuse;
- copies of the genuine identification data relevant to the dispute;
- provider applications, statements, transaction records and profile-change notices;
- emails, messages, call recordings or logs lawfully available to you;
- device, login or location information with its source and time zone;
- SAPS, SAFPS, provider, bureau, NCR and Regulator references;
- copies of every submitted form and delivery receipt; and
- a loss schedule separating confirmed, reversed and still-disputed amounts.
Record facts that do not fit the theory as well as those that do. Evidence that an address, device or authentication step is unfamiliar may be important, but it does not by itself prove who acted.
11. Treat collection letters and court papers as separate deadlines
A provider investigation or bureau dispute does not automatically suspend a debit order, collection step or court deadline. If a summons is served, verify the court and case details, preserve proof of service and follow the response period in the actual process. The summons response checklist helps control that separate task.
Obtain prompt legal help where money is still moving, a provider alleges that its authentication proves consent, a summons or judgment exists, a company or tax record has changed, evidence may disappear, urgent relief is needed, or several institutions reject responsibility. The cyber-crime lawyer route supports specialist discovery; ask the practitioner to scope the immediate protective step separately from the longer correction and recovery work.
Recovery checklist
- Record the first discovery and create an affected-account table.
- Secure primary email, mobile, devices and recovery settings.
- Contact each provider through independently verified channels.
- Obtain a reference and written outcome for every dispute.
- Preserve applications, authentication records, messages and statements.
- Obtain current credit reports and mark every unauthorised entry.
- Dispute each entry with the bureau and track its 20-business-day stage.
- Report suspected identity theft to SAPS and retain the CAS number.
- Consider the appropriate SAFPS registration without treating it as a cure-all.
- Use focused POPIA access, correction or complaint routes where applicable.
- Follow separate CIPC, mobile, tax, benefit or document-issuer routes.
- Protect debit, collection, summons, objection and appeal deadlines.
Sources
- SAPS: Reporting crime supports the local police-station reporting process, statement, registration and case reference.
- SAPS: Cybercrime prevention tips identifies suspected identity theft and commercial scams as matters to report at a local police station.
- National Credit Act 34 of 2005 supports consumer-credit information access and challenge rights.
- NCR Guideline 005/2024 supports the bureau-first dispute, masking, 20-business-day investigation and Form 29 escalation sequence.
- NCR credible-evidence guideline, December 2025 explains the evidence expected from a credit-information source during a dispute.
- NCR register of credit bureaus is the current official register reviewed for bureau identification.
- SAFPS: Protective Registration supports the current protective and victim-registration context and the need to contact providers and SAPS.
- Protection of Personal Information Act 4 of 2013 supports sections 23 and 24 access, correction and deletion rights.
- Information Regulator: Complaints, POPIA forms and online services support the current correction and complaint routes.
- CIPC fraud hotline and Companies Act complaint route support the specialist branch where company or director information is implicated.
FAQs
Is a police case enough to remove a fraudulent account from my credit report?
No. A CAS number is important evidence, but the provider and each credit bureau may still need a record-specific dispute and supporting information. Track the criminal case and correction processes separately.
Should I pay an identity-theft debt to protect my credit score?
Do not make a payment merely to make a disputed account disappear. First obtain advice on the effect, dispute the account in writing and protect any court deadline. A payment does not guarantee correction and may complicate the dispute.
How long does a credit-bureau dispute take?
The NCR’s current Guideline 005/2024 gives the bureau 20 business days to resolve a consumer-credit information dispute. Use the date and reference in the bureau’s acknowledgement and confirm the current NCR escalation requirements if the outcome is unsatisfactory.
Can SAFPS cancel an account opened in my name?
SAFPS registration can help participating organisations identify a protective or victim filing, but it does not itself cancel an agreement or decide liability. Continue the provider, bureau, SAPS and any regulator or court process.
Can I ask an organisation to delete my personal information under POPIA?
You may request correction or deletion on the grounds in section 24, including where information is inaccurate, misleading or unlawfully obtained. The organisation may need credible evidence and may lawfully retain some accurate records. Identify the exact record and requested change.
What if I receive a summons for an account I did not open?
Do not wait for the provider’s fraud team to finish. Verify the court process, calculate the response date from the actual summons, preserve service proof and obtain urgent advice on the required filing and evidence.
Related Lexuno paths
Source notes
- SAPS: Reporting crime
- SAPS: Cybercrime prevention tips
- National Credit Act 34 of 2005
- NCR Guideline 005/2024
- NCR Guidelines for the Submission of Credible Evidence, December 2025
- NCR register of credit bureaus
- SAFPS Protective Registration
- Protection of Personal Information Act 4 of 2013
- Information Regulator complaints
- Information Regulator POPIA forms
- Information Regulator online services
- CIPC fraud hotline
- CIPC Companies Act complaint route
Legal note
This article is general legal information for South African readers. It is not legal advice. Speak to a qualified legal professional about your specific facts before taking action.

