The verdict in three sentences
Mobile money fraud is less about card theft and more about social engineering: SIM-swap, forged payment receipts, stolen accounts. Your defense rests on three layers: verify (number, provider-side transaction status), limit (velocity, per-device and per-hour caps) and trace (fingerprint, history). In 2026, a good anti-fraud setup costs a few hours of configuration but prevents losses of 0.5% to 2% of revenue.
Typical fraud and how to detect it
| Fraud type | How it works | Detectable signal | Action |
|---|---|---|---|
| Fake receipt | Falsified payment screenshot | Reference not found via status API | Never fulfill without API verification |
| SIM-swap | Hijacked number validates a payment | Recent SIM change / unknown device | 2FA + security delay |
| Friendly fraud | Customer disputes a real purchase | Customer history, delivery proof | Timestamped proof, order log |
| Velocity abuse | Multiple rapid attempts | > 3-5 attempts / 10 min same device | Temporary block, CAPTCHA |
| Stolen account | Access to merchant or customer account | Login from unusual IP/country | Alert + reverification |
| Card testing | Micro-amounts to validate data | Burst of small failed amounts | Rate limit + IP block |
Key principle: the only valid proof of a mobile money payment is the provider-side status API check, never a screenshot sent by the customer.
Velocity rules and fingerprinting
A simple rules engine blocks most automated fraud. Goal: minimize false positives (real customers blocked) while catching suspicious patterns.
| Signal | Recommended threshold 2026 | Possible false positive | Graduated action |
|---|---|---|---|
| Attempts per device | > 5 / 10 min | Low | CAPTCHA then 30-min block |
| Amount vs average basket | > 5x average | Medium | Manual review |
| New device + large amount | 1st order > $300 (NGN/KES eq.) | Medium | Mandatory 2FA |
| Same number, multiple accounts | > 3 accounts / number | Low | Manual review |
| Risky delivery address | Flagged zone | High | Phone confirmation |
| Consecutive failures | > 4 failures / hour | Low | Temporary IP block |
Device fingerprint (browser/device signature) and rate limiting cover 80% of automated attempts. The remaining 20% — social engineering — is handled by team training and systematic reverification of large baskets.
The real cost of a fraud
A fraud doesn't cost only the product amount. Add up: lost product value, non-recoverable transaction fees, dispute handling time, and reputation impact. 2026 order of magnitude: an average fraud on a $40 basket actually costs $65 to $95 once everything is counted.
Mini case study
Ibrahim runs an electronics store in Nairobi, 1,200 orders/month, average basket about $70. With no controls, he suffered ~1.2% fraud, about 14 problematic orders/month, of which 6 were real losses at ~$85 = ~$510/month.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
After setup: systematic API verification (end of fake receipts), velocity limit at 5 attempts/10 min, and 2FA above roughly $300. Fraud dropped to ~0.3%, saving ~$390/month, for a config cost of one day of dev. False positives stayed under 1%, absorbed by phone confirmation.
FAQ
Is an M-Pesa/MoMo payment screenshot enough to validate an order?
No, never. Screenshots are trivially forged. The only reliable proof is verifying the transaction status via the provider's API, which returns success with the exact reference and amount.
How do I avoid blocking real customers?
Use graduated actions: CAPTCHA before blocking, 2FA only on large amounts, phone confirmation rather than a hard refusal. Target a false-positive rate under 1% and monitor it weekly.
What is SIM-swap and am I exposed?
It's hijacking a customer's number to validate a payment or reset an account. On mobile money, add a security delay or 2FA when the device changes to limit the risk.
Does friendly fraud exist in mobile money?
Yes: a customer disputes a genuine purchase. Your defense is timestamped proof — order log, delivery confirmation, transaction reference — documenting every step.
Do I need a paid tool or are homemade rules enough?
For most SMEs, a homemade rules engine (velocity, fingerprint, caps) covers the essentials. Radar-type tools become relevant beyond several thousand transactions/month.
Let's talk about your project. We configure custom anti-fraud that protects your margin without blocking your customers. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

