PesaBridge
Yonke imininingwane
ComplianceSep 2026 · 11 imizuzu yokufunda

Mobile money fraud prevention: attacks, signals and controls

SIM swaps, social engineering, agent fraud and insider risk: how each attack works and the layered controls that stop it.

T
The PesaBridge team · Risk

Fraud arrives at a new mobile money service within weeks of launch, and it rarely looks like hacking. It looks like a friendly phone call, a message claiming money was sent by mistake, a SIM card replaced overnight, or an agent quietly bending the rules. Because mobile money is instant and final, prevention matters far more than recovery. This guide walks through the fraud schemes every operator must design against, the controls that stop them, and how to build a fraud programme that protects customers without making the service painful to use.

Why mobile money is targeted

  • Speed and finality: money moves in seconds and can be cashed out within minutes.
  • New users: many customers are new to digital finance and unfamiliar with scams.
  • Phone numbers as identity: control of a SIM can mean control of a wallet.
  • Distributed agents: thousands of independent businesses handle cash and customer data.
  • Scale: millions of small transactions make anomalies easy to hide without good monitoring.

The nine schemes to design against

1. Social engineering and impersonation

The most common fraud by far. A caller poses as customer care, the provider's "security team", a bank or even a relative, and persuades the victim to share their PIN, a one-time code, or to "reverse" a transaction by sending money.

Controls: repeated education that the provider never asks for a PIN; official sender IDs for SMS; in-app messages that cannot be spoofed; cooling-off periods and extra checks after a PIN reset; velocity rules on new payees.

2. "Money sent by mistake"

The victim receives a fake SMS claiming money arrived, followed by a call asking them to send it back. No money ever arrived.

Controls: teach customers to check the balance in the app or menu, not the SMS; make genuine receipts recognisable; provide a formal reversal route so customers never need to "send back" money themselves.

3. SIM swap

A fraudster obtains a replacement SIM for the victim's number, often with a forged ID or an insider at a retail outlet, then resets the PIN and drains the wallet.

Controls: integrate SIM-swap signals from the mobile network where available; block or limit transactions for a period after a SIM change; require additional verification for PIN resets; alert the customer through another channel; limit withdrawals immediately after a reset.

4. PIN theft and shoulder surfing

PINs observed at agents or on shared phones, or collected by fake agents.

Controls: PIN masking in every channel; wallet locking after repeated failed attempts; biometric sign-in and auto-lock in apps; per-transaction and daily limits.

5. Account takeover through the app

Stolen credentials or a stolen unlocked phone used to access the app.

Controls: PIN on every money action, not only at login; auto-lock when the app goes to the background; device registration with verification for new devices; alerts for new device logins.

6. Agent fraud

Agents may split transactions to earn more commission, charge unofficial fees, make direct deposits that bypass KYC, or collect customers' PINs. Fraudsters also target agents by posing as head office.

Controls: analytics on split transactions and unusual patterns; visible tariffs and SMS receipts showing the official fee; agent training; clear rules that head office never requests transfers; limits and monitoring per agent. More in agent banking explained.

7. Merchant fraud

Fake payment confirmations shown to merchants, refunds abused by staff, or merchants who are fronts for fraud collection.

Controls: merchants rely on in-app confirmations or balances; prompt-to-pay and dynamic QR so the merchant sets the amount; refunds only against original payments with approval; merchant due diligence and monitoring. See merchant payments.

8. Mule accounts

Accounts registered, often with borrowed or stolen IDs, to receive and move stolen funds quickly.

Controls: tiered KYC with low limits for minimally verified accounts; monitoring for accounts that receive from many unrelated senders and cash out immediately; limits on registrations per agent and per ID; link analysis across accounts, devices and agents.

9. Insider fraud

Staff with back-office access changing limits, reversing transactions or creating accounts improperly.

Controls: role-based access; maker-checker on sensitive actions such as reversals, limit changes and manual adjustments; immutable audit logs; regular access reviews.

Controls that belong in the platform, not the policy

A fraud policy is only as good as the system that enforces it. The following should be built into the platform:

ControlStops
PIN on every money action, wallet lock after failed attemptsStolen phones, guessed PINs
Per-transaction and daily limits linked to KYC tierMule accounts, large losses from any single compromise
Velocity and threshold rulesRapid draining, structuring, mule behaviour
Recipient name shown before confirmationMistaken and some fraudulent transfers
Biometric sign-in and auto-lock in appsCasual account takeover
Maker-checker in the back office and corporate accountsInsider and corporate fraud
Single, audited reversal engineManual adjustments without a trail
Signed webhooks for partnersFake payment notifications to integrated merchants
AML screening hooks and case managementSanctioned parties, laundering patterns

Transaction monitoring that works

Rules are the starting point for every monitoring programme. Useful mobile money rules include:

  • many incoming transfers from unrelated senders followed by an immediate cash-out;
  • transactions just under limits repeated in short windows;
  • a dormant account suddenly receiving and moving large sums;
  • activity immediately after a PIN reset or SIM change;
  • agents with unusual ratios of registrations to active customers;
  • many accounts registered with the same ID, device or agent in a short period.

Every alert needs an owner, a documented decision and, where required, a report to the financial intelligence unit. Over time, outcomes from reviewed alerts can train better scoring, but rules and good case management deliver most of the value early.

Real-time vs. after-the-fact

Some controls must act before money moves: limits, PIN checks, blocks after SIM swaps, velocity caps. Others work after the fact: alert review, investigations, account restrictions. Design both. Real-time controls stop the damage; after-the-fact review finds the patterns that the next real-time rule should catch.

Customer education: the cheapest control

Most fraud succeeds because a customer is persuaded to act. Education reduces it measurably when it is:

  • Repeated at key moments: registration, PIN reset, first large transfer.
  • Specific: "We will never call you to ask for your PIN" beats "stay safe."
  • Delivered in local languages and through agents, not only in the app.
  • Backed by the product: in-app warnings when sending to a new recipient for the first time, or right after a PIN change.

Handling victims well

How you treat fraud victims shapes trust in your brand. Provide a fast reporting channel, freeze recipient accounts quickly when fraud is reported and the funds are still there, investigate promptly, keep the customer informed, and use the controlled reversal process rather than informal fixes. Every reversal should leave a complete trail linked to the original transaction.

Anatomy of a SIM-swap attack, and where it can be stopped

Walking through a single attack shows why layered controls matter. Each step is a chance to stop it:

Attacker's stepControl that can stop it
Gathers the victim's name, ID number and phone number from social media or a data leakCustomer education about sharing ID details; data protection at agents
Obtains a replacement SIM at a retail outlet with a forged IDMobile network's SIM-swap verification; staff training at outlets
Victim's phone loses signal; attacker's phone now receives the victim's SMSAlert from the mobile network or wallet to the victim through another channel
Attacker requests a PIN reset on the walletSIM-change signal blocks or delays resets; additional identity questions or agent verification
Attacker logs into the app on a new deviceNew-device verification; alert to registered email or next of kin
Attacker sends the balance to several mule accountsHolds on transfers after a SIM change or PIN reset; velocity limits; new-payee limits
Mules cash out at agentsMonitoring for rapid cash-out after receipt; agent alerts; recipient freeze when fraud is reported

No single control is perfect, but an attacker must get through all of them. That is the principle of defence in depth, and it is why fraud prevention must be designed into the platform, the network operator relationship, the agent network and customer education at the same time.

Balancing friction and protection

Every control adds some friction. Too little, and fraud grows; too much, and genuine customers abandon transactions or the service. Useful principles:

  • Risk-based friction: add checks where risk is high, such as first transfer to a new payee, activity after a PIN reset or unusually large amounts, and keep routine transactions fast.
  • Limits instead of blocks: a temporary lower limit after a risky event protects the customer without stopping them from paying for essentials.
  • Explain the check: "For your security, transfers are limited for 24 hours after a PIN change" is accepted far more readily than an unexplained failure.
  • Measure false positives: track genuine customers affected by each rule, and tune rules that cause more pain than protection.

A 30-60-90 day fraud plan for a new wallet

Before launch

  • Configure KYC tiers and conservative limits for new accounts.
  • Enable wallet locking after failed PIN attempts and PIN on every money action.
  • Agree SIM-swap signal sharing with mobile network operators where possible.
  • Write customer and agent education messages in every launch language.
  • Define the fraud reporting channel and the freeze procedure.

First 30 days

  • Review every reported fraud case personally; map each to a scheme.
  • Switch on core monitoring rules: rapid cash-out after receipt, many senders to one recipient, activity after PIN reset.
  • Brief agents on the schemes already seen.

Days 31 to 60

  • Tune rules based on alert outcomes; retire those that only produce noise.
  • Add limits on new payees and first-time large transfers if social engineering is rising.
  • Start link analysis on accounts, devices and agents involved in confirmed cases.

Days 61 to 90

  • Publish a monthly fraud dashboard to management.
  • Run a mystery-shopping round on agents.
  • Review limits by KYC tier against actual customer needs and fraud patterns.

The fraud operating model

Even small operators need clear ownership. A typical model:

  • Fraud analysts monitor alerts and investigate cases daily.
  • A fraud lead owns rules, metrics and liaison with mobile network operators and law enforcement.
  • Customer care is trained to recognise fraud reports and trigger freezes immediately, day or night.
  • Compliance handles suspicious transaction reports and regulatory communication.
  • Agent network managers handle agent-related cases and training.

The most important operational commitment is speed: a fraud report at 10 pm must lead to a freeze within minutes, not the next morning, because stolen funds are often cashed out within the hour.

Metrics for a fraud programme

  • fraud losses as a share of transaction value;
  • number of reported frauds per million transactions, by type;
  • time from report to account freeze;
  • share of losses recovered;
  • alert volumes and true positive rates by rule;
  • customer complaints about false blocks, which show where controls are too tight.

Signals worth collecting from day one

Good fraud decisions depend on data you can only use if you collected it. From launch, make sure the platform records:

  • Device identifiers and the date each device was first seen on an account;
  • SIM change events where the mobile network shares them;
  • PIN resets and failed PIN attempts, with timestamps and channels;
  • Payee history: when each recipient was first paid by each customer;
  • Channel and location context: USSD, app or agent, and the agent involved;
  • Registration context: which agent registered the account, with which ID, and how quickly it became active.

With these, rules such as "large transfer to a new payee within 24 hours of a PIN reset on a new device" become simple to write and highly effective. Without them, investigators are left reconstructing events from call logs.

Common mistakes in fraud programmes

  • Blocking too much. Rules that stop many genuine customers push them back to cash and generate support costs. Measure false positives as carefully as losses.
  • Rules without owners. Every rule needs someone who reviews its results and tunes it.
  • Slow response to reports. Stolen money moves in minutes. A victim's report must lead to action within minutes, not days.
  • Ignoring insiders. Staff and agent fraud is often larger than customer fraud. Separation of duties and audit trails apply inside the company too.

Key terms in mobile money fraud

TermMeaning
SIM swapMoving a customer's phone number to a new SIM card, sometimes fraudulently, to take over their account.
Social engineeringTricking a person into revealing a PIN or code, or into sending money.
Account takeoverA criminal gaining control of a genuine customer's wallet.
Mule accountA wallet used to receive and move stolen funds, often registered with borrowed or bought IDs.
Velocity ruleA rule that limits or flags the number or value of transactions in a short period.
False positiveA genuine transaction wrongly flagged or blocked as suspicious.
Step-up checkAn extra verification, such as a call-back or a second code, required for risky actions.
Separation of dutiesMaking sure no single person can both initiate and approve a sensitive action.

Frequently asked questions

What is the most common mobile money fraud?

Social engineering: persuading customers to share their PIN or send money, often by impersonating customer care or claiming money was sent by mistake.

How does SIM-swap fraud work?

A fraudster obtains a replacement SIM for the victim's number, then uses it to reset the wallet PIN and move funds. Operators counter it with SIM-change signals, holds after a SIM change and stronger PIN-reset checks.

Can a fraudulent transfer be reversed?

If the funds are still in the recipient account, the provider can often freeze and reverse them through a controlled process. Once cashed out, recovery is much harder, which is why prevention matters.

Do KYC tiers reduce fraud?

Yes. Low limits on minimally verified accounts reduce the value of mule accounts and cap losses from any single compromise.


PesaBridge puts these controls in the core: PIN on every money action, wallet locking after failed attempts, per-transaction and daily ceilings by KYC tier, biometric sign-in and auto-lock in the apps, AML screening hooks with velocity and threshold rules, maker-checker in the back office and a single audited reversal engine. See security and compliance or talk to our team.

Izikhwama ezigcina inani Inethiwekhi yabameli Izinkokhelo zomthengisi USSD I-API yabathuthukisi Isicelo-sokukhokha Amazinga e-KYC Ukubuyisela Ukusabalalisa i-float Ukubhadala Ama-webhook asayiniwe White-label Izikhwama ezigcina inani Inethiwekhi yabameli Izinkokhelo zomthengisi USSD I-API yabathuthukisi Isicelo-sokukhokha Amazinga e-KYC Ukubuyisela Ukusabalalisa i-float Ukubhadala Ama-webhook asayiniwe White-label

Usukulungele ukwethula isikhwama sakho?

Bhuka idemo bese sisungula ibhrendi, izwe nama-rail akho — futhi sikuhambise kuwo ama-app, i-admin ne-API.

Ungathanda ukukhuluma? Shayela +254 746 883809