SIM Swap Fraud, Account Takeover and the AML Challenge for Mobile Money Providers

How criminals can turn control of a phone number into control of a financial account

A customer’s phone suddenly loses network connectivity.

They cannot make calls.

They cannot receive SMS messages.

They may assume it is a technical problem.

Meanwhile, somewhere else, another SIM card has been activated using their mobile number.

Within minutes, an attacker may be attempting to access the customer’s email, mobile banking, mobile money wallet or other accounts linked to the telephone number.

This is SIM swap fraud.

And for mobile money providers, the problem goes considerably beyond telecommunications security.

A successful SIM swap can become the first step in an account takeover, which can then become a financial crime event involving unauthorised transfers, cash-out activity, mule accounts, fraud proceeds and potentially money laundering.

The result is an important shift in perspective:

SIM swap fraud is not only a cybersecurity problem. It can become an AML problem.


What is SIM swap fraud?

A SIM swap occurs when a fraudster manages to have a victim’s mobile number reassigned to a SIM card controlled by the fraudster.

Once the attacker controls the number, they may be able to intercept SMS communications and authentication codes associated with the victim.

The GSMA describes fraudulent SIM swapping as an unauthorised reassignment of a victim’s SIM and notes that the threat became particularly relevant to mobile money users in sub-Saharan Africa.

The attack itself does not necessarily involve sophisticated hacking.

It can involve the exploitation of weaknesses in:

  • Customer verification;
  • SIM replacement processes;
  • Dealer or agent procedures;
  • Social engineering;
  • Compromised personal information;
  • Weak authentication mechanisms.

The attacker is effectively trying to convince the telecommunications provider:

“I am the legitimate customer.”

If successful, control of the telephone number may transfer to the criminal.


Why SIM swaps are particularly relevant to mobile money

Mobile money ecosystems are closely connected to mobile identities.

A customer’s phone number may be associated with:

  • A mobile money wallet;
  • Bank accounts;
  • Payment applications;
  • Email accounts;
  • Merchant accounts;
  • Digital services;
  • Authentication mechanisms.

This creates a potential chain:

SIM swap → Account takeover → Unauthorised transaction → Cash-out → Mule account → Criminal beneficiary

The SIM swap may therefore be only the beginning.

GSMA has specifically identified SIM swap, identity theft and SMS fraud among the fraud typologies affecting mobile money users.

This is why mobile money providers should not treat SIM-related events and financial transaction monitoring as completely separate issues.


From SIM swap to account takeover

Once a criminal obtains control of a customer’s mobile number, the next objective may be to gain access to the financial account.

The attacker may attempt to:

  • Reset credentials;
  • Intercept OTPs;
  • Change account details;
  • Register a new device;
  • Change authentication methods;
  • Initiate transfers;
  • Withdraw funds;
  • Send money to other accounts or wallets.

The important point is that the customer’s account may have been completely legitimate.

The criminal did not necessarily need to create a fraudulent account.

They may simply have taken control of an existing one.

This creates a significant challenge for AML teams.

Traditional KYC may tell the institution:

“This account belongs to John.”

But the more relevant question after a potential takeover becomes:

“Who is actually controlling the account right now?”


The identity paradox

This creates an interesting problem for financial crime professionals.

The account may pass KYC.

The customer’s identity may be genuine.

The documentation may be legitimate.

There may be no obvious onboarding problem.

Yet the person currently controlling the account may be someone completely different.

This is why KYC and authentication are related but not identical controls.

KYC establishes information about the customer.

Authentication attempts to establish that the person accessing the account is authorised to do so.

If criminals compromise the authentication layer, a perfectly legitimate KYC profile can become the gateway to financial crime.


What happens after the account is compromised?

The next stage can vary significantly.

In a simple case, the criminal may attempt to transfer money directly out of the victim’s account.

But organised criminals may use a more sophisticated structure.

For example:

Victim’s mobile wallet

↓

Mule account

↓

Second mobile wallet

↓

Cash-out agent

↓

Criminal controller

Alternatively:

Compromised account

↓

Multiple wallets

↓

Bank account

↓

Crypto platform

↓

Final beneficiary

Each additional movement can create distance between the original victim and the person ultimately controlling the funds.

This is where the fraud investigation begins to overlap with AML.


When does fraud become an AML problem?

Not every SIM swap is necessarily money laundering.

The initial event may simply be an account takeover and fraud.

The AML concern becomes particularly relevant when the proceeds are subsequently:

  • Transferred through multiple accounts;
  • Split between beneficiaries;
  • Converted between payment channels;
  • Sent across borders;
  • Combined with other illicit proceeds;
  • Routed through mule networks;
  • Withdrawn through cash-out points;
  • Converted into other assets.

The FATF’s 2026 paper on cyber-enabled fraud highlights the growing connection between fraud and money laundering and notes that 90% of FATF-assessed jurisdictions identify fraud as a major money laundering risk.

This is an important development.

Fraud teams may identify:

“The account was compromised.”

AML teams need to ask:

“Where did the money go?”

Both questions are necessary.


The importance of transaction sequencing

One of the strongest signals may not be the transaction itself.

It may be what happens immediately before and after it.

Consider a customer whose account normally shows:

  • Small person-to-person payments;
  • Regular airtime purchases;
  • Utility payments;
  • Low-value merchant transactions.

Suddenly:

10:02 — New SIM registered

10:08 — New device added

10:11 — Password reset

10:15 — Large incoming transfer

10:17 — Funds transferred to three new beneficiaries

10:25 — Cash withdrawal

Individually, some of these events might not generate a traditional AML alert.

Together, however, they tell a very different story.

This is why event sequencing can be more valuable than relying exclusively on static transaction thresholds.


SIM swap should become a risk signal

A recent SIM replacement should not automatically mean:

“This customer is suspicious.”

That would create unnecessary friction and potentially large numbers of false positives.

Instead, a SIM swap could become one signal within a broader risk model.

For example:

Low-risk scenario

SIM replacement occurs.

The customer continues normal activity.

No new device appears.

No password reset occurs.

No unusual payments follow.

The event may require little or no additional intervention.

Higher-risk scenario

SIM replacement occurs.

A new device is registered.

Credentials change.

New beneficiaries appear.

Large transactions begin.

Funds rapidly leave the account.

This combination should attract significantly more attention.

The difference is context.


What should mobile money providers monitor?

A strong fraud and AML framework can connect several types of information.

1. SIM events

Monitor:

  • Recent SIM swaps;
  • SIM replacements;
  • Number porting;
  • eSIM activation;
  • Changes in SIM-related customer information.

2. Device activity

Monitor:

  • New device registration;
  • Device changes;
  • Multiple accounts associated with one device;
  • Unusual device behaviour.

3. Authentication events

Look for:

  • Password resets;
  • PIN changes;
  • Failed authentication;
  • New authentication methods;
  • Unusual login patterns.

4. Transaction behaviour

Monitor:

  • Sudden increases in transaction volume;
  • New beneficiaries;
  • Rapid transfers;
  • Multiple recipients;
  • Large cash-outs;
  • Unusual geographic activity.

5. Network relationships

Examine connections between:

  • Accounts;
  • Wallets;
  • Devices;
  • Telephone numbers;
  • Agents;
  • Beneficiaries.

This becomes particularly important when criminals operate networks rather than individual accounts.


The African context creates additional complexity

Mobile money is not simply another digital banking channel in Africa.

It is often deeply integrated into everyday economic activity.

Customers use mobile money for:

  • Salaries;
  • Remittances;
  • Family support;
  • Merchant payments;
  • Small businesses;
  • Agricultural activity;
  • Informal trade;
  • Government payments.

This means transaction behaviour can vary significantly from customer to customer.

A customer receiving 20 incoming payments may be suspicious in one context.

In another, they could simply be operating a legitimate small business.

Similarly, frequent cash-outs may indicate:

  • Criminal proceeds;

or:

  • Normal business activity.

This makes contextual monitoring essential.

A simple rule such as:

“Multiple incoming payments = suspicious”

is unlikely to work effectively across diverse African markets.


The role of agents

Mobile money agents are another important part of the ecosystem.

They provide customers with access to cash and digital financial services, particularly in areas where traditional banking infrastructure is limited.

But agents can also become important points in the financial crime chain.

Potential indicators may include:

  • Unusual cash-out volumes;
  • Concentration of transactions involving suspicious accounts;
  • Multiple accounts cashing out at the same location;
  • Rapid cash-in/cash-out activity;
  • Unexpected changes in agent behaviour.

The objective should not be to treat agents as inherently risky.

Instead, providers should ask:

“Does this agent’s activity make sense within the expected economic context?”


Why traditional AML monitoring may miss the problem

Traditional transaction monitoring is often designed around customer and transaction attributes.

For example:

  • Amount;
  • Frequency;
  • Geography;
  • Counterparty;
  • Transaction type.

But account takeover can involve a different type of signal:

The customer’s behaviour changes immediately after an authentication or identity event.

This means AML systems need to increasingly incorporate non-transactional signals.

For example:

SIM swap + new device + credential reset + new beneficiary + rapid transfer

may be significantly more informative than any single transaction.

This is where fraud and AML data need to converge.


Fraud and AML cannot operate in silos

Historically, fraud teams and AML teams have often had different objectives.

Fraud asks:

“Was the customer defrauded?”

AML asks:

“Where are the proceeds moving?”

In a SIM-swap scenario, both questions are connected.

Consider:

Stage 1: Customer’s SIM is compromised.

Stage 2: Account is taken over.

Stage 3: Funds are stolen.

Stage 4: Funds are transferred to several accounts.

Stage 5: Money moves through wallets or payment providers.

Stage 6: Funds are withdrawn or converted.

If the fraud team stops at Stage 3, part of the financial crime picture is lost.

AML teams can potentially identify the subsequent movement of funds.

The FATF has repeatedly emphasised the importance of breaking down silos and improving cooperation between public and private sector stakeholders when tackling cyber-enabled fraud and related laundering.


What controls can providers implement?

There is no single solution.

A layered approach is more effective.

Stronger customer verification

SIM replacement and account recovery processes should receive an appropriate level of customer validation.

GSMA guidance has highlighted the importance of consistent customer validation for new and existing customers, staff training, multi-factor authentication and other controls for reducing SIM-swap risks.

Temporary transaction restrictions

A recent high-risk account-change event could trigger proportionate restrictions on certain transactions.

For example, particularly sensitive transactions may require additional authentication.

Real-time risk scoring

Providers can combine:

  • SIM information;
  • Device information;
  • Customer behaviour;
  • Transaction data.

This can provide a more complete risk picture.

Behavioural analytics

Understand what normal behaviour looks like for the individual customer.

Then identify meaningful deviations.

Network analytics

Identify whether multiple apparently unrelated accounts are connected through:

  • Devices;
  • Phone numbers;
  • Beneficiaries;
  • Agents;
  • Transaction patterns.

Customer communication

Customers should be informed about:

  • SIM-swap risks;
  • Social engineering;
  • Account recovery fraud;
  • OTP protection;
  • The risks of sharing credentials.

A particularly important red flag: the timing

One of the most useful analytical questions may be:

“What happened immediately after the SIM swap?”

Consider two accounts.

Account A

SIM swap → normal activity → normal spending.

Account B

SIM swap → new device → PIN reset → new beneficiary → large transfer → cash-out.

The second scenario clearly deserves more attention.

The SIM swap itself is not necessarily suspicious.

The combination of events is.

This is a fundamental principle of effective financial crime monitoring:

Signals become more powerful when they are connected.


The challenge of false positives

There is also a danger in overreacting.

Customers legitimately:

  • Replace lost phones;
  • Change SIM cards;
  • Travel;
  • Change devices;
  • Reset passwords;
  • Send money to new recipients.

If every SIM replacement automatically results in account restrictions, the customer experience can deteriorate rapidly.

For mobile money providers serving millions of customers, excessive controls can also undermine financial inclusion.

The objective should therefore be:

Risk-based friction.

Low-risk customers should experience minimal disruption.

Higher-risk combinations of signals should trigger stronger intervention.


The future: identity, behaviour and money movement

SIM-swap fraud illustrates a broader transformation in financial crime.

KYC tells us:

Who the customer is.

Authentication tells us:

Who is accessing the account.

Behavioural analytics tells us:

How the account normally behaves.

Transaction monitoring tells us:

How money moves.

Network analytics tells us:

Who the account is connected to.

The strongest financial crime systems increasingly need all five perspectives.


Final Thoughts

SIM swap fraud is often described as a telecommunications or cybersecurity problem.

For mobile money providers, that description is incomplete.

A SIM swap can become the gateway to account takeover.

Account takeover can facilitate fraud.

Fraud generates proceeds.

Those proceeds may then move through mule accounts, mobile wallets, banks, agents and other payment channels.

At that point, the problem is no longer simply:

“Someone stole access to a phone number.”

It becomes:

“How did the stolen funds move through the financial ecosystem?”

This is where fraud prevention and AML need to converge.

The future of mobile money financial crime prevention will therefore require providers to connect identity events, authentication signals, device intelligence, transaction behaviour and network relationships.

Because the most important signal may not be the suspicious transaction itself.

It may be what happened five minutes before it.

And in an increasingly digital African financial ecosystem, understanding that sequence could make the difference between detecting an account takeover early and discovering the crime only after the money has disappeared.

The future of AML for mobile money will not only be about monitoring transactions.

It will be about understanding who controls the account, how that control changed, and where the money moved afterwards.

#AML #FinancialCrime #SIMSwap #AccountTakeover #FraudPrevention #MobileMoney #FintechAfrica #DigitalPayments #TransactionMonitoring #CyberFraud #Africa

Leave a Reply

Discover more from FinCrime Africa

Subscribe now to keep reading and get access to the full archive.

Continue reading