Uncategorized

[New Podcast] Africa’s Scam Economy Has Industrialized: What Telecom Operators Must Do Next

Every successful scam steals twice.

First, it steals money, information or identity from the victim.

Then it steals something much harder for the telecommunications industry to recover: trust.

When a customer loses their savings following a SIM-swap-enabled account takeover, they rarely blame the fraudster alone.

They also blame the operator whose network they trusted, the agent who processed the request, the mobile-money service through which the funds disappeared and the institution whose brand the criminal impersonated.

To the customer, the entire ecosystem failed.

This is why I believe customer-facing fraud can no longer be treated as a specialist issue hidden somewhere inside a revenue-assurance, fraud-management or cybersecurity department.

It is now a customer-experience issue.

A brand issue.

A financial-inclusion issue.

An increasingly serious threat to the resilience of Africa’s digital economy.

This was the central theme of a discussion panel I had the privilege of moderating at the TARS 2026 Telecom Africa Revenue Assurance & Fraud Management Summit in Nairobi, Kenya, on the 13th May 2026. 

The panel was titled:

Protecting the Customer: Scam Typologies, Operator Responsibilities & Fraud Awareness in Africa

The Panel

I was joined by three highly experienced practitioners who brought different but complementary perspectives to the discussion:

  • Ann Khambo, Revenue Assurance and Fraud Management Manager, Airtel Money, Airtel Kenya — Ann brought a mobile-money and revenue-assurance perspective to the conversation. Her work involves designing and operating controls that protect mobile-money revenue and customer funds through system reconciliation, fraud-monitoring rules, near-real-time alerts, gap analysis and case resolution.
  • Ogochukwu (Ogo) Onwuzurike, Country Manager, Nigeria, Truecaller — Ogo brought Truecaller’s view of spam, caller identity, scam detection and customer trust. Truecaller sits at a particularly important point in the communications journey: between the caller and the person receiving the call. That provides the platform with a unique view of how unwanted and fraudulent communications are changing at scale.
  • Mieraf T. Birhane, Executive Head of Fraud Management, Safaricom Telecommunications Ethiopia — Mieraf brought extensive experience in fraud detection, investigations, analytics, internal controls and security awareness. mThe Ethiopian market provided an especially relevant case study because subscriber growth, digital adoption and mobile financial services are all expanding quickly.

Africa’s Scam Landscape Has Changed

I opened the discussion by observing that scam operations across Africa have become industrialised.

What used to be the occasional prize-scam SMS has evolved into a much broader spectrum of attacks:

  • Smishing through fraudulent text messages
  • Vishing through convincing phone calls
  • Business and institutional impersonation
  • Investment scams
  • Social-media-enabled fraud
  • SIM-swap account takeovers
  • Identity theft
  • AI-generated identity and KYC documents
  • Deepfake or cloned-voice calls

What makes the current environment particularly dangerous is not simply the number of scam typologies.

It is the scale at which criminals can now deploy them.

AI and automation allow scammers to generate messages, imitate credible institutions, operate across several communications channels and reach enormous numbers of potential victims.

As Ogo explained during the panel, a ringing telephone no longer necessarily means there is another human being on the line.

We have entered what she described as the machine era of spam and fraud.

The Telephone Call Is Losing Its Trust

Ogo shared that Truecaller intercepted approximately 68 billion spam and fraud calls in 2025, compared with approximately 37.8 billion in 2021.

That means the volume had almost doubled within four years.

Nigeria provides an especially revealing picture of the challenge.

According to the figures Ogo shared, Nigeria had a spam intensity of approximately 51%. Carrier-related communications accounted for around 35%, financial institutions represented approximately 10%, while outright fraud accounted for 6%.

Six percent may appear modest until it is applied to a market with well over 180 million mobile connections.

The wider problem is that customers often struggle to distinguish between:

  • A legitimate operator call
  • A financial-services promotion
  • A genuine customer-service notification
  • An aggressive sales campaign
  • A business being impersonated
  • A criminal attempting to steal personal information

The result is that people increasingly ignore unknown calls altogether.

This affects much more than fraud prevention.

Legitimate businesses struggle to reach customers. Customer-acquisition costs increase. Deliveries are missed. Service levels decline. Revenue opportunities are lost.

The scam economy is therefore damaging the credibility of the telephone call itself.

Fraudsters Are Engineering Credibility

One of Ogo’s most important observations was that scammers are becoming better at what she described as credibility engineering.

The fraud may begin with an SMS.

The victim then receives a phone call.

The caller may claim to represent a bank, telecommunications company or government institution.

The victim may be sent an authentication code, moved onto WhatsApp or directed to a convincing website.

Each touchpoint makes the scam appear more legitimate.

Fraudsters are effectively creating omnichannel customer journeys.

Unfortunately, their objective is not to complete a sale.

It is to manufacture enough trust to make the victim disclose information, approve a request or transfer money.

The fastest-growing typologies Ogo identified included:

  • Business impersonation
  • Investment scams
  • Smishing
  • Multichannel social-engineering attacks

The lesson for operators and platforms is that calls, SMS messages, devices, identities and transactions can no longer be assessed in isolation.

Identity Theft and the Innocent Customer

When I asked Ann what kept her awake at night, she focused on the innocent person who may not even know their identity has been stolen.

A photograph may be combined with someone else’s biographical data.

A legitimate identity may be used to register several SIM cards.

An innocent customer may only discover the fraud when law-enforcement officers arrive at their door or when their details become connected to a criminal investigation.

Ann also raised an uncomfortable question for all of us:

How many places have our photographs and personal details been used without our knowledge?

A professional photograph taken from LinkedIn or another public platform could be used to create a false company profile, fraudulent identity or convincing impersonation.

The person whose identity has been copied may have no visibility into what is happening.

That is why Ann argued that operators must assume a meaningful degree of responsibility.

Customers cannot protect themselves from activity they cannot see.

Operators, however, have access to onboarding information, SIM-registration data, transaction behaviour, device information and other signals that can reveal suspicious patterns.

Operator Responsibility Starts at Onboarding

Ann’s argument was that customer protection must extend across the entire lifecycle.

It begins during onboarding and identity verification.

However, if suspicious activity is not detected at registration, the operator should still have opportunities to identify it through subsequent behaviour.

For example:

  • Is the same photograph being used across multiple identities?
  • Has a new SIM been followed by unusual transactions?
  • Has the device changed?
  • Is the customer transacting from an unexpected location?
  • Has a high-value transfer followed a SIM replacement?
  • Is the behaviour inconsistent with the customer’s historical profile?

Ann also proposed that stronger biometric approaches could eventually help operators move beyond relying on photographs from old national identification documents.

The larger point is that KYC should not be treated as a one-time exercise.

Knowing your customer should be an ongoing process of validating whether the person using the service continues to behave like the legitimate owner of the account.

Makeup-Assisted SIM-Swap Fraud

Mieraf shared one of the most extraordinary fraud examples I have encountered.

Fraudsters in Ethiopia had used makeup and physical impersonation to resemble legitimate customers closely enough to attempt fraudulent SIM swaps.

The example sounds almost cinematic.

However, it illustrates how carefully organised fraudsters study and attempt to defeat existing controls.

They understand what an agent expects to see.

They study identification documents and photographs.

They exploit the limitations of visual verification.

The encouraging part of the example was that the attempted fraud was detected by an agent.

The agent recognised the suspicious behaviour because they had received practical training based on real-world scenarios.

That example reinforced one of the strongest messages from the panel:

Technology is essential, but technology alone is not enough.

The Three Pillars of Fraud Prevention

Mieraf organised Safaricom Ethiopia’s approach around three interconnected areas:

  • People — Customers, agents and employees must understand the threats they are likely to encounter. Training has to be practical, consistent and based on real cases rather than generic compliance presentations.
  • Processes — Fraud risk must be considered before a product reaches the market. Mieraf described this as anti-fraud by design. Risk assessment should begin during product brainstorming and development — not after customers have already been exposed.
  • Technology — Operators need to use the data within their environments more effectively. That includes real-time detection, data analytics, machine learning, behavioural monitoring, stronger authentication, follow-up and investigation mechanisms

These three pillars must reinforce each other.

A strong technology platform cannot compensate for a poorly trained agent.

An effective awareness campaign cannot compensate for a weak onboarding process.

A well-designed process will still fail if insiders can override it without accountability.

GSM and Mobile-Money Fraud Are Connected

Another important insight from Ann was that telecommunications fraud and mobile-money fraud cannot be separated in practice.

Mobile money may be operated as a distinct business or regulated entity.

However, it still depends on the identity and KYC information created when the customer registers their mobile line.

Most mobile-money fraud does not begin with the final transaction.

It may begin with:

  • A phone call
  • An SMS
  • A compromised identity
  • A fraudulent SIM swap
  • An insider sharing customer information
  • A social-engineering conversation

This means operators must connect telecommunications data with financial activity.

A mobile-money system should be able to ask:

  • Why is the customer apparently in Nairobi while the transaction is occurring in Mombasa?
  • Has the customer’s device changed?
  • Did a SIM swap take place shortly before the transaction?
  • Was an unusual call or SMS pattern observed?
  • Is this a shared wallet or genuinely abnormal behaviour?
  • Has the transaction pattern changed suddenly?

The ability to integrate voice, SMS, SIM, device, location and transaction data creates a much stronger fraud-detection environment.

Internal Integrity Matters

Ann also raised the role of insiders.

An employee with access to customer information may monitor a high-value account, provide details to an external accomplice or help facilitate a fraudulent SIM swap.

The fraud may appear to have been committed entirely by an outsider.

In reality, an insider may have provided the intelligence required to make it possible.

This is why fraud awareness must extend beyond customers.

It must include:

  • Employees
  • Agents
  • Customer-service personnel
  • Sales teams
  • Technology teams
  • Third-party partners
  • Senior leadership

Integrity cannot be treated as a slogan displayed on an office wall.

It must be supported by access controls, monitoring, accountability and a culture in which suspicious conduct is investigated regardless of who is involved.

Operators Can No Longer Be Neutral Pipes

The central tension running through the discussion concerned the limits of operator responsibility.

Customers have responsibilities too.

They should protect their PINs, question suspicious requests, avoid sharing authentication codes and report suspected fraud.

However, an operator cannot simply argue that it provided a technically secure communications channel.

Customers place their trust in operator brands.

They trust registered agents.

They trust branded SMS messages.

They trust that SIM-replacement procedures will verify the right person.

They trust that highly unusual activity will be identified.

When those systems are exploited, the resulting damage is attached to the operator’s reputation.

Operators may not be able to prevent every scam.

They can, however, make fraud harder, more expensive and less scalable.

Key Takeaways

  • Africa’s scam economy has entered an industrial phase — AI and automation are allowing criminals to operate at unprecedented scale.
  • Social engineering remains the primary attack vector — Most fraud still requires a customer, agent or employee to perform what appears to be a legitimate action.
  • Spam is also an economic problem — When customers stop trusting unknown calls, legitimate organisations struggle to reach them.
  • Identity theft may remain invisible to the victim — Operators must use the information available to them to identify patterns customers cannot see.
  • GSM and mobile-money fraud must be analyzed together — Voice, SMS, identity, SIM, device, location and transaction data are all part of the same risk journey.
  • Fraud prevention must begin during product design — Anti-fraud controls should be embedded before launch rather than added after losses occur.
  • Human awareness remains essential — The makeup-assisted SIM-swap attempt was detected because a trained agent recognised the warning signs.
  • Internal fraud cannot be ignored — Sophisticated external controls can be undermined by compromised employees or agents.
  • Operators are no longer neutral pipes — Their infrastructure, processes and brands form part of the customer-protection environment.
  • Collaboration is essential — Fraud does not respect operator boundaries, company structures or national borders.

Protecting the Trust Layer

My biggest takeaway from the discussion is that customer-facing fraud is no longer merely a fraud-management problem.

It is a threat to the trust layer on which Africa’s digital economy has been built.

Mobile money works because people trust that their funds will remain secure.

Digital banking works because people trust that their identities will be protected.

Telecommunications networks work because people trust the calls, messages and services travelling through them.

Once that trust begins to disappear, adoption slows, complaints increase, regulators intervene and customers return to less efficient but seemingly safer methods.

The telecommunications industry helped build Africa’s digital economy.

It must now take equal responsibility for defending the customers whose trust made that economy possible.

My sincere thanks to Ann Khambo, Ogochukwu Onwuzurike and Mieraf T. Birhane for sharing their experience and insights during this important conversation

Listen To The Podcast

Previous post

[New Podcast] From Data-Rich to Insight-Driven: How AI Is Reshaping Retail in Kenya & Africa

Next post

[New Podcast] WhatsApp Usernames, Privacy, Fraud & Digital Identity: An Interview with the BBC's Nkechi Onyinyechi Ogbonna on the Focus on Africa Podcast

No Comment

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.