Your payment app shows strangers what you bought, and a strong password will not stop it
A South African who keeps a unique passphrase and switches on two-factor authentication can still have the amount, the note and the name of the person paid visible to anyone who looks.
A strong passphrase keeps a stranger out of your payment app. It does not stop the stranger who is already inside from reading what you sent, to whom, for how much, and when.
That gap is the subject of reporting by Ventureburn on 17 September 2026 into how password advice and account privacy are treated as one problem when they are two. A unique login protects access to an account. Privacy controls decide what is visible around the activity once access is legitimate, and the two need different settings and different attention.
For anyone paying a landlord in Randburg, sending money to a child at university in Stellenbosch or splitting a bill at a restaurant in Durban, the second setting is the one that decides whether a transaction becomes public information.
Two jobs, one login screen
Payment apps generally offer a choice of audiences for each transaction. Public activity can be seen by anyone on the internet. A friends-only setting narrows that circle. A private setting is the most restrictive option, limiting what is shown to the user’s own feed and to the other person in the payment.
Private is not the same as invisible. The two people involved in a payment can still see the amount, the note attached to it, the sender’s name, the recipient’s name and the time it was made. That is the part most users never think about, because the login screen is where all the security advice points.
Discoverability is a third, separate control. An account can be set so that it cannot be found by someone searching a phone number or an email address, and the visibility of a friends list is governed by yet another setting. Each one decides a different question about who can see what.
What the standards bodies actually say
The National Institute of Standards and Technology in the United States recommends long, unique passphrases, and it points out that a password manager can generate and hold a separate credential for every account. That advice carries a privacy benefit of its own. When one service is breached, a reused password does not open the door to the next one.
The master passphrase for the manager itself then becomes the most valuable secret a person holds, because it guards everything in the vault.
The Cybersecurity and Infrastructure Security Agency, also in the United States, goes further. Its position is that a password on its own is insufficient protection now, and that a second factor during sign-in is what keeps an account intact when a password has already been compromised.
Payment platforms have built that in. Venmo, for example, offers two-factor authentication at sign-in and states that it will not ask for a six-digit security code by phone call, text message, email or chat. That last point matters in South Africa, where the same message pattern is used by criminals who call a person, claim to be from the bank or the payment provider, and ask for the code that has just arrived on the phone.
The routine that closes the gap
A purchase or a payment goes more safely when it starts in the official app or at a web address typed in by hand rather than tapped from a message. Confirm which account is being used and check the details of what is being bought before paying. Keep the login details and any one-time code away from anyone who asks for them, however official the request sounds.
Before the money moves, choose the audience that matches how much visibility the sender is comfortable with. That single step, taken at the moment of payment rather than buried in a settings menu afterwards, is where most of the exposure is decided.
For South Africans, the practical stakes are concrete. A payment note that names a school, a medical practice or a family member becomes a small piece of information that can be read by people the payer never intended to include. Fraudsters who already have a name, a rough location and a pattern of payments have a better opening than one who has none of it.
The country’s banks and payment providers have spent years building authentication into their apps, and the second-factor requirement is now standard across the major institutions. That work is real and it has raised the cost of a straightforward account takeover. The remaining exposure is not in the lock. It is in what the app shows once the lock has been opened legitimately.
Ventureburn’s reporting sets out the distinction plainly. Privacy controls deserve the same attention as password strength, not a lesser role, because the two address different parts of the same account.
The Enquirer has asked the Payments Association of South Africa and the major banks whether transaction visibility settings are explained to customers at sign-up or only buried in a privacy menu, and what guidance they give on the audience settings that decide who can see a payment.
Source: Ventureburn, Does Account Privacy Carry Equal Weight Alongside Password Strength in Digital Purchases
- Police find fifth woman's body near Kempton Park as search for missing jogger continues 2026-09-14
- Sixth woman found in Ekurhuleni as ex-SAPS profiler calls for serial killer investigation 2026-09-15
- Gauteng police confirm six women found dead in Ekurhuleni as Kekana appeals for information 2026-09-15
- Police task team probes five Kempton Park deaths as family identifies runner Elizabeth Moselakgomo 2026-09-15
- Seven women found dead in Ekurhuleni as top police and ministers meet in Parktown 2026-09-15
- Police confirm eighth body in Ekurhuleni and offer R400 000 for information 2026-09-15
- Police put R400 000 on the table in Kempton Park murders probe 2026-09-15
- Police form high-level team as eighth body found in Ekurhuleni 2026-09-15
- Seven women found dead in Gauteng in two months as safety audit is demanded 2026-09-15
- Police raise Ekurhuleni toll to seven women as task team hunts suspects 2026-09-16

