1 reviews | Active since Jul 2017
FNB refusing to refund R57,829 despite confirmed account interception, foreign access and unauthorised internal transfers
I am posting this after FNB has issued a formal deadlock on my ***** dispute, despite clear internal evidence that my account was compromised by a third party.
On the evening of 9 December 2025, I attempted to make a small online purchase on Temu, but the FNB app kept displaying “server unavailable”. No transaction went through and no confirmation was received.
While I was asleep in the early hours of 10 December 2025, multiple SMS-based OTPs were sent to my phone. I did not request, enter or approve any of them. I also did not receive any Smart InContact push notifications on my device.
When I woke up shortly after 05:00, I saw that multiple transactions had been made. When I logged into my FNB app, the *****ulent transactions were still showing as “pending”, and I immediately contacted FNB ***** and had my cards cancelled. Despite this, the transactions were still allowed to process.
During this *****, money was moved internally between my Cheque Account, Savings Account and Money Maximiser without my authorisation to fund the *****ulent card purchases. The total amount taken was R57,829.01.
I was contacted by FNB ***** consultant Ronan Thomas on 22 and 23 December 2025, who reviewed the case in detail with me. He confirmed that:
• My account was accessed from another device
• It was accessed from a different location
• The access was done via a web browser, not my mobile app
• One of the purchases originated from Barcelona, Spain
• Activity logs showed a third party active on my account
• Internal transfers between my accounts were synchronised with the *****ulent purchases
• The activity pattern indicated account interception, not customer-initiated use
Despite this, FNB rejected my claim purely because OTP authentication was present, without proving that I entered the OTP, on my device, from my location.
This is totally unacceptable as:
An OTP being generated does not prove customer authorisation when:
• The account was accessed from another device
• From another location
• Via a web browser
• With foreign transactions
• With unauthorised internal fund movements
I reported the ***** immediately while transactions were still pending, yet FNB failed to block or reverse them.
FNB also promotes Money Protect for unauthorised digital *****, but they have refused to explain how it was assessed or app**** in my case, despite internal evidence of account compromise.
I am requesting:
A full reversal of the R57,829.01
A written explanation of how my OTP was compromised
Disclosure of the device, IP address and geolocation used for the *****ulent access
Clarification on why Money Protect was not honoured FNB has declared this matter at deadlock, and I have escalated it to the National Financial Ombud. I am now making this public because this represents a serious digital banking security failure.
I will update this review once FNB resolves the matter
