Main StoryNews

Lack of control safety measures by telcos abetting online fraud

Kenyans have berated telecommunications operators over the prevalence of SIM swap fraud in the country, arguing that such fraud could be possible with an insider in the network operator of the subscriber that is targeted.

Subscribers want the three major telcos — Safaricom, Airtel and Telkom — to improve the authentication and security mechanisms that govern mobile phone number registration and replacement.

Its Weru, a Twitter user, claimed that his father was a victim of a Sim swap scam.

“He woke up one morning and realised that his Sim card had been blocked; he couldn’t access M-Pesa. He went to the telco’s shop and they told him a swap had been done. In addition, the criminal had borrowed Sh30, 000 from M-Shwari. The telco [didn’t] do anything to help. Utaibiwa na bado ulipie sababu ya kuibiwa, (They steal from you then you have to pay loans you didn’t take),” he posted.

Jumah was baffled as to how a Sim card could be swapped without an ID number or M-Pesa pin.

Andrew Musyoki questioned how a Sim exchange would allow hackers access to bank accounts, pins, and passwords, as well as how they would get over security safeguards. Another Twitter user, Baroness Cherie, proposed a solution.

“Sim providers need to come up with an app-based 2FA [two-factor authentication] text message-based and number lock system. This Sim swap is an old fraud originally used to steal cryptocurrency. I am not surprised it has come to this,” he said.

The latest scenario Farah Bashir is still coming to terms with how thieves emptied out his bank accounts with Sh2.6 million from his four Absa Bank accounts in a series of operations that left him helpless.

See also  David Mwaure concede defeat in presidential race, endorses Ruto

He described how, in just two days after he arrived in Johannesburg for a two-week assignment in between February 7 and February 9.

On February 5, Bashir, a 58-year-old medical lab expert, arrived in Johannesburg, he later on received calls from his family and friends shortly after, informing him that some people were hunting for him.

Everything was OK until he received an alarming SMS from Safaricom at 5.43 p.m. on February 7, the text notified him that the company had received a Sim Card exchange request and that he should disregard the communication if he had not initiated it.

Bashir had received nearly ten such messages an hour later thus he contacted Safaricom Customer Care via Twitter, but was told to disregard the post because the requests were not initiated by him.

On Twitter, he contacted Safaricom Customer Care, who requested his personal information, including his ID and phone numbers.

A week ago, Anthony Mugo, 57, discovered that someone unknown to him had transacted more than Sh2.7 million using a Sim card associated with his identity card over the previous six months.

Mugo stepped into the Kilimani Branch of Equity Bank on April 25 looking for a loan, only to be told he couldn’t acquire one because he had been adversely categorized by a credit reference bureau (CRB) as a defaulter. He had not applied for a loan and was unaware of this.

Dismayed, he contacted a CRB agent over WhatsApp at 10:27 am the next day during a conversation that lasted until 11:10 am, only for Mugo to learn that he had defaulted on a Sh6,742 loan granted via Fuliza (a credit facility offered by M-pesa to clients with insufficient funds to complete a transaction).

See also  Agents crucial to digital insurance success - AAR Insurance

“You are listed because of a loan default with NCBA Bank… For you to be delisted, you have to make a complete payment plus a Sh2,200 clearance fee. That is 6743+2,200,” the response stated.

The CRB agent saw something was wrong and informed Mugo that the loan had been wiped off due to a mistake.

“All you have to do now is pay a Sh2,200 clearance fee,” the agent said. Mugo decided not to pay the fee. A few hours later, he was at the Junction Mall branch of NCBA Bank on Ngong Road. He, however, did not manage to have his name cleared. “I was told to contact Safaricom. In December, Safaricom cleared all the other numbers that had been linked to my ID and after checking using the USSD code *106#, it was clear that only my current line remained in the system,” Mugo said.

To combat this, Safaricom advises that users ensure their Sim card has an active Sim lock, use strong passwords, and avoid sharing personal information on social media.

Kenyans can also activate anti-swapping by dialling *100*100#. This implies that you cannot swap your SIM card with an M-Pesa agent; instead, you must go to a Safaricom shop and present yourself physically.

Sim swap has proven to be a source of frustration for millions of people all around the world. It was one of the main topics considered at the 16th Symposium on Usable Privacy and Security, which will be held in the United States in 2020.

The initiative brought together an interdisciplinary group of scholars and practitioners in the fields of human-computer interaction, security, and privacy, who collaborated to develop guidelines to address the issues.

See also  Love, class and coffee collide in new Kenyan feature film ‘Love and Coffee’

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button