Table of Contents
How dangerous are SIM Swap scams?
For years, millions of mobile money users across Uganda have lived with the constant threat of waking up to a dead SIM card, an empty wallet, and a maxed-out mobile loan facility. Whenever a subscriber fell victim to a smooth-talking scammer, the official corporate response from financial institutions and telecom companies almost always boiled down to a cold, frustrating refrain: “You shared your PIN, so it is your fault.”
That narrative took a major hit at the Uganda Communications Commission (UCC) Inaugural National Cybersecurity Conference in Kampala. Convened under the theme “Securing Uganda’s Digital Future: Collaboration, Resilience and Trust,” the high-level gathering brought together telecom operators, commercial bank executives, law enforcement officers, and ICT regulators to confront the country’s surging digital financial fraud crisis.
Speaking during a panel discussion on protecting digital financial services against social engineering, SIM swaps, and account takeovers, Airtel Money Commerce Uganda Limited (AMCUL) Managing Director Japhet Aritho issued a direct reality check to the industry. Aritho stated that telecom operators and banks must stop relying solely on consumer education campaigns and instead embrace “Security by Design”—building aggressive, automated fraud prevention mechanisms directly into the code of mobile money products.
Importantly, Aritho pushed back against the habit of blaming victims, noting that modern fraudsters are highly trained, articulate manipulators who build trust with ease.
“It’s very difficult to spot a scammer… they speak good English, they make you comfortable,” Aritho admitted to the panel. “The burden of protection should sit with service providers at the design stage, not solely with consumers.”
How does the attack chain connecting social engineering, SIM swaps, and account takeovers work?
To effectively stop mobile money fraud, financial operators must stop treating scams as isolated events. Aritho explained that social engineering, SIM swap fraud, and account takeovers are simply different stages of a single, continuous attack chain designed to strip a customer of their funds.
“For you to take over a mobile account, you have to do a SIM swap. For you to do a SIM swap, you have to start with social engineering, because there is some information that you have to pick,” Aritho explained.
The process almost always starts with psychological manipulation. Fraudsters call or text a target, pretending to be official customer service agents or network engineers resolving an account error. To build instant credibility, scammers deliberately repeat the exact security warnings issued by telecom companies.
“They will tell you exactly what we are telling them… and then they will trick you into sharing your PIN,” Aritho noted.
Once the scammer uses social engineering to trick a victim into disclosing personal identification details—such as their National Identification Number (NIN), date of birth, or registration details—they approach an unsuspecting or compromised mobile money agent to execute an unauthorized SIM swap. The moment the replacement SIM goes live, the victim’s physical phone loses network connection. The scammer then uses the new SIM to receive One-Time Passwords (OTPs), reset transaction PINs, drain mobile money balances, and clear out linked bank accounts.



What is device binding technology and how does it lock mobile money to your phone?
To break this attack chain, Airtel Money has begun implementing Device-Binding Technology as a core example of Security by Design.
Under traditional mobile money systems, if a fraudster successfully steals your PIN and executes a SIM swap, they can instantly log into your account using any smartphone handset. Device-binding technology completely changes this setup by mathematically locking your mobile money account and registered phone number to the specific hardware identifiers of your personal smartphone handset.
If a scammer performs a SIM swap and attempts to log into your mobile money account from a different physical phone, Airtel’s backend system instantly detects the hardware mismatch. Even if the scammer enters the correct PIN and receives the OTP, the app automatically freezes all financial transactions and blocks access.
Aritho acknowledged that device-binding creates minor friction for legitimate customers who switch phones, as they are forced to undergo re-verification before accessing their accounts on a new device. However, he argued that this inconvenience is far better than losing life savings.
“Being locked out of financial apps until re-verified with each provider, while inconvenient, is far preferable to fraud losses,” Aritho stressed, adding that automated systems must step in the moment a device or SIM card changes.
How does the IMSI check API stop scammers from draining bank accounts?
While device-binding protects mobile apps, telecom operators have also had to build backend tools to protect commercial bank accounts linked to mobile wallets.
Several years ago, as mobile banking apps began allowing instant transfers between bank accounts and mobile money lines, scammers realized they could perform a SIM swap on a target and drain their commercial bank accounts via USSD codes. To block this backdoor, Airtel Money developed an internal security tool known as the IMSI Check API.
An International Mobile Subscriber Identity (IMSI) is a unique 15-digit code embedded inside every physical SIM card. When a user undergoes a legitimate SIM swap, their phone number stays the same, but the underlying IMSI code changes to match the new physical chip.
“We created APIs, very simple, done internally, not even by any sophisticated developer, which we exposed to all banks,” Aritho revealed.
Airtel Money subsequently engaged the Bank of Uganda to mandate that every commercial bank in the country integrate this API. Today, whenever a user attempts to transfer money from a bank account to a mobile line, the bank’s system automatically pings the telecom operator in real time. If the API reveals that the SIM card associated with that line underwent a SIM swap within the previous 24 to 48 hours, the bank automatically blocks the transfer, preventing devastating bank account drains.
How does Airtel use artificial intelligence to block scam text messages?
In addition to hardware locking and banking APIs, telecom companies are deploying machine learning to combat bulk SMS scams. Unsolicited text messages claiming a relative is hospitalized, announcing fake lottery wins, or sending fake deposit confirmations have targeted Ugandan phone users for over a decade.
To address this, Airtel deployed its native AI Spam Alert Service, which monitors network traffic in real time.
The system uses data analytics and artificial intelligence to analyze incoming SMS metadata across the network. It flags suspicious behavioral patterns, such as a single prepaid line broadcasting hundreds of identical messages per minute or texts containing recognized scam phrasing and unverified short-codes.
When the system detects a suspicious message, it automatically attaches a prominent warning header to the text before it lands in the subscriber’s inbox. If a sender exceeds aggressive spam limits, the network automatically suspends the line’s text-messaging capabilities and flags the user’s National ID for investigation, stripping scammers of the element of surprise.
What are your legal rights under Uganda Data Protection Act if your data is leaked?
A central theme raised by participants at the UCC National Cybersecurity Conference focused on personal data privacy, with audience members questioning whether insider leaks at telecom service centers contribute to targeted SIM swap attacks.
Addressing these concerns, Macgyver Mugamba, Manager for Data Protection and Legal Advisory at the UCC, reminded the public that personal data collection by private corporations is strictly regulated under Uganda’s Data Protection and Privacy Act of 2019.
Mugamba emphasized that every citizen has the legal right to ask private entities how their personal records are processed, stored, and protected. Service providers are legally barred from collecting or sharing customer information without explicit consent and transparent privacy policies.
Adding to the regulatory perspective, UCC officials noted that consumers facing unresolved data privacy complaints or suspected insider data leaks do not have to rely solely on corporate customer care desks. Citizens have the right to escalate unresolved privacy violations directly to the Personal Data Protection Office (PDPO) operating under the Ministry of ICT and National Guidance.
Regulators urged Ugandans to practice strict data hygiene by avoiding leaving physical copies of National IDs at unverified reception desks or sharing identity documents over unencrypted messaging apps.
Why building a secure digital economy requires collaboration across all sectors
The Inaugural National Cybersecurity Conference established that no single institution can defeat digital financial fraud in isolation. A telecom operator can build advanced AI spam filters and device-binding code, but if a commercial bank maintains weak application security or a local mobile money agent executes an unverified SIM swap for a minor bribe, the entire security chain breaks.
Aritho left stakeholders with a clear warning regarding the interconnected nature of Uganda’s financial network.
“We are as strong as an ecosystem as the weakest link within that ecosystem,” Aritho warned in his closing remarks.
Protecting Uganda’s cashless future requires continuous collaboration between telecom companies, commercial banks, law enforcement, and regulators. By combining hardware security, real-time banking APIs, AI-driven threat detection, strict data privacy enforcement, and proactive system design, service providers can finally shift the burden of protection off the shoulders of everyday consumers and build a safer digital economy.



