Mobile money fraud: the social-engineering patterns behind the losses

This is an analysis of publicly documented patterns, not a report on any single incident. It draws on the GSMA's State of the Industry reports on mobile money, INTERPOL's African Cyberthreat Assessment (2024) and published operator and regulator guidance across African markets.

The pattern

Mobile money is one of Africa's great financial-inclusion successes — the GSMA's industry reporting shows the continent carrying the clear majority of the world's mobile money activity, with hundreds of millions of registered accounts. That success created a new fraud surface with a distinctive property: the security perimeter is a conversation. Most documented mobile money fraud does not break the platform; it talks a human — a customer, an agent, or an employee managing a corporate wallet — into using the platform against themselves. INTERPOL's 2024 assessment places online and mobile-enabled scams among the most reported cyber-enabled crimes in Africa, and GSMA fraud typologies consistently rank social engineering among the leading vectors.

How it plays out

The published typologies repeat a small number of moves:

Impersonation calls and messages. Fraudsters pose as the operator's "customer care" or "fraud department", warning of a suspicious transaction and walking the victim through "verification" — which is in fact the disclosure of a PIN or one-time code, or the approval of a transfer.

Reversal scams against agents. An agent receives what looks like a genuine deposit confirmation, pays out cash, and later discovers the confirmation was spoofed or the transaction reversed. Variants exploit fake overpayments and urgent "wrong number" refund requests.

Agent and employee manipulation. Agents handle both cash and customer trust, making them targets for SIM-swap setup (harvesting registration details), for laundering the proceeds of other frauds, and for direct manipulation into bypassing know-your-customer steps.

Corporate wallet abuse. As businesses adopt wallets for payroll, collections and supplier payments, attackers apply BEC logic to them: impersonating a manager to demand an urgent disbursement, or socially engineering the employee who holds the wallet credentials. The controls that banks spent decades building around corporate accounts often do not yet surround corporate wallets.

Who it targets

Customers at the base of the pyramid, agents working on thin margins with high transaction pressure, and — increasingly — the finance and operations staff of organisations that run significant balances through corporate wallets. For an employer, the last group is the critical one: a single manipulated employee can move an entire float.

Breaking the pattern

  • Teach the iron rule: no legitimate operator ever asks for a PIN or OTP. It must be reflexive for every employee who touches a wallet.
  • Separate duties on corporate wallets — initiation, approval and reconciliation should never sit with one person, mirroring bank-account controls.
  • Verify urgent disbursement requests out-of-band, exactly as for bank transfers; wallet speed is precisely why attackers prefer it.
  • Train agents and cash-handling staff on reversal and overpayment scams, with realistic scenarios rather than posters.
  • Reconcile wallets daily. Fast detection is the difference between an incident and a write-off.

Sources

  • GSMA, State of the Industry Report on Mobile Money (2024)
  • GSMA mobile money fraud typology publications
  • INTERPOL, African Cyberthreat Assessment Report (2024)

If your organisation runs money through wallets, your people are the control surface — benchmark them with our free Human Risk Maturity Assessment.