SIM swap and account takeover: why your MFA choice matters more in Africa
This is an analysis of a documented fraud pattern, drawing on GSMA industry publications on mobile money and fraud, INTERPOL's African Cyberthreat Assessment (2024), and regulator and operator advisories issued across African markets. It describes patterns, not any single incident.
The pattern
Across much of Africa, the phone number is the master key to financial life: it anchors mobile money wallets, receives banking one-time passwords, and serves as the recovery channel for email and business applications. SIM-swap fraud attacks that anchor directly. If a criminal can persuade — or pay — a telco channel to move a victim's number onto a SIM they control, every SMS code and callback verification built on that number now belongs to the attacker. Regulators and operators in markets including South Africa, Kenya and Nigeria have repeatedly warned about the pattern, and GSMA fraud typologies list SIM-swap and social engineering among the leading mobile-financial-services threats.
How it plays out
The published pattern has three stages:
Reconnaissance. The attacker gathers the victim's personal details — from phishing, data leaks, social media, or by social-engineering the victim directly with a fake "customer care" call. The goal is to be able to answer the identity questions a SIM-replacement process will ask.
The swap. Armed with those details, the attacker requests a SIM replacement, impersonating the victim at an agent outlet or call centre. In some documented cases the path is insider-assisted rather than fully social-engineered. The victim's first symptom is usually a phone that suddenly loses signal.
The harvest. In the window before the victim reacts, the attacker triggers password resets and drains what the number protects: mobile money balances, bank accounts via SMS OTP, and increasingly corporate assets — email accounts, admin consoles and payment platforms whose "second factor" was a text message to a personal phone.
For organisations, that last step is the one that matters. A SIM swap against one finance officer's personal number can defeat the MFA on a corporate payment system.
Who it targets
High-balance mobile money users, bank customers in SMS-OTP markets, and — for the corporate variant — executives, finance staff and IT administrators whose phone numbers are discoverable and whose accounts guard money or access. Attackers select targets whose number is worth the effort of a swap.
Breaking the pattern
- Stop treating SMS as strong MFA for anything critical. Prefer authenticator apps, and phishing-resistant methods such as security keys or passkeys for payment systems and admin access.
- Remove personal phone numbers from account-recovery paths on corporate email and finance platforms wherever possible.
- Teach the tell-tale sign: sudden loss of mobile signal plus a flood of password-reset emails is an emergency, not an annoyance — staff should know to report it within minutes.
- Guard the data that enables swaps. ID numbers, dates of birth and answers to security questions leak through phishing; awareness training reduces the raw material.
- Coordinate with your operators on port-out and SIM-replacement notifications for key corporate lines.
Sources
- GSMA, mobile money and fraud typology publications (including the State of the Industry Report on Mobile Money, 2024)
- INTERPOL, African Cyberthreat Assessment Report (2024)
- Public advisories from African telecom and financial regulators on SIM-swap fraud
Your MFA is only as strong as the humans and processes around it — see how prepared your organisation really is with our free Human Risk Maturity Assessment.