article · East African Journal of Information Technology
Mobile money systems in Tanzania face widespread impersonation fraud that bypasses technical safeguards by manipulating users into sending funds directly. An examination of 231 active users alongside key informant interviews and regulatory reviews revealed that 72.3 percent of users experienced impersonation attempts, with 86.2 percent targeted repeatedly. Rather than seeking account credentials such as personal identification numbers, perpetrators induced 98.8 percent of victims to transfer money themselves. Compliance was high, as 74.3 percent of targeted individuals complied with fraudulent instructions, leading to financial losses for 97.6 percent of them. The primary predictor of user compliance was trust in communications that appeared to originate from service providers. Consequently, users expressed a strong demand for enhanced controls during transactions, particularly cancellation mechanisms and extended verification windows to prevent fraud at the point of authorisation.
Mobile money serves as essential financial infrastructure, yet fraud that tricks users into authorising transfers undermines security. Because technical firewalls cannot stop voluntary payments made under deception, understanding why users comply is critical. Identifying that misplaced trust in official-looking messages drives high financial loss rates highlights the urgency of designing protective safeguards directly into the payment authorisation stage.
Mobile network operators, fintech firms, and financial regulators could use these findings to design user-facing security features for mobile money platforms. Desired applications include transaction cancellation mechanisms and extended payment verification windows. This represents early-stage research pointing towards platform feature development, demonstrating clear user demand for safeguards built directly into the point of transaction authorisation.
AI-generated from the published abstract. Always read the original work before citing.
Mobile money is critical financial infrastructure in Tanzania, but impersonation-based fraud can bypass technical safeguards by inducing users to authorise payments themselves. This study examined the techniques, patterns, and vulnerabilities facilitate impersonation-based fraud and the factors predicting user compliance with fraudulent instructions in Tanzania. A mixed-methods design combined a survey of 231 active mobile money users in Dar es Salaam and Kibaha, eight key informant interviews and a review of regulatory and industry documents. Impersonation attempts were pervasive, with 72.3% of users targeted and 86.2% of those targeted were repeatedly. Attackers requested PIN in only 0.6% of cases but inducing 98.8% to send money themselves. Among targeted users, 74.3% complied, and 97.6% of compliers lost money. Logistic regression identified trust in providers-appearing communications as the only significant unique predictor of compliance (OR = 2.50). Users strongly preferred transaction-context safeguards, with 93.1% wanting cancellation capability and 87.4% wanting more verification time. Impersonation-based mobile money fraud is primarily an authorised-payment problem rooted in trust exploitation. Mitigation should therefore strengthen safeguards at the point of payment authorisation
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.37284/eajit.9.2.5694
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.