ZA
Zakira A

1 reviews | Active since Jul 2017

11 Jan 2026, 13:33

FNB refusing to refund R57,829 despite confirmed account interception, foreign access and unauthorised internal transfers

I am posting this after FNB has issued a formal deadlock on my ***** dispute, despite clear internal evidence that my account was compromised by a third party.

On the evening of 9 December 2025, I attempted to make a small online purchase on Temu, but the FNB app kept displaying “server unavailable”. No transaction went through and no confirmation was received.

While I was asleep in the early hours of 10 December 2025, multiple SMS-based OTPs were sent to my phone. I did not request, enter or approve any of them. I also did not receive any Smart InContact push notifications on my device.

When I woke up shortly after 05:00, I saw that multiple transactions had been made. When I logged into my FNB app, the *****ulent transactions were still showing as “pending”, and I immediately contacted FNB ***** and had my cards cancelled. Despite this, the transactions were still allowed to process.

During this *****, money was moved internally between my Cheque Account, Savings Account and Money Maximiser without my authorisation to fund the *****ulent card purchases. The total amount taken was R57,829.01.

I was contacted by FNB ***** consultant Ronan Thomas on 22 and 23 December 2025, who reviewed the case in detail with me. He confirmed that:

• My account was accessed from another device

• It was accessed from a different location

• The access was done via a web browser, not my mobile app

• One of the purchases originated from Barcelona, Spain

• Activity logs showed a third party active on my account

• Internal transfers between my accounts were synchronised with the *****ulent purchases

• The activity pattern indicated account interception, not customer-initiated use

Despite this, FNB rejected my claim purely because OTP authentication was present, without proving that I entered the OTP, on my device, from my location.

This is totally unacceptable as:

An OTP being generated does not prove customer authorisation when:

• The account was accessed from another device

• From another location

• Via a web browser

• With foreign transactions

• With unauthorised internal fund movements

I reported the ***** immediately while transactions were still pending, yet FNB failed to block or reverse them.

FNB also promotes Money Protect for unauthorised digital *****, but they have refused to explain how it was assessed or app**** in my case, despite internal evidence of account compromise.

I am requesting:

A full reversal of the R57,829.01

A written explanation of how my OTP was compromised

Disclosure of the device, IP address and geolocation used for the *****ulent access

Clarification on why Money Protect was not honoured FNB has declared this matter at deadlock, and I have escalated it to the National Financial Ombud. I am now making this public because this represents a serious digital banking security failure.

I will update this review once FNB resolves the matter

0
Replies (1)
ZA
Zakira A's update13 Jan 2026, 12:23
Reviewer Update
Thank you for the response. This matter has already been formally declared deadlocked by FNB following the bank’s refusal to refund the *****ulent transactions on my account. I have now referred the matter to the National Financial Ombud for independent adjudication. Your response does not address the core issue, namely how an OTP sent to my device was accessed and used by a *****ster without my knowledge or authorisation. This reply will form part of my Ombud submission.