Most mobile money losses are process failures, not technical ones. Here are the four patterns behind the bulk of them.

Mobile money moved from convenience to core infrastructure faster than most institutions updated their controls. Salaries, per diems, supplier payments, field allowances and beneficiary disbursements now run through the same channels that fraudsters target every day.
The uncomfortable part is that most losses are not technical. Nobody breaks the encryption. Somebody calls a finance officer, sounds official, creates urgency and obtains an approval that should never have happened.
Agent impersonation, where a caller claims to be from the provider and asks for a PIN reset or a reversal. SIM swap, where an attacker takes control of the number that receives one time codes. Fake reversal requests, where a finance officer is told a payment was sent in error and pressured to send it back. And internal collusion, where a staff member with approval rights splits payments to stay below the review threshold. Each of these exploits process, not code.
The controls that work are specific and unglamorous. Call back verification using a number your institution already holds, never the number that called you. Dual approval above a stated threshold. A standing rule that no reversal is ever processed on a verbal request. Separation between the person who initiates a payment and the person who releases it.
The other half is training. Finance and field staff need to have heard the exact script a fraudster uses before they hear it live. Institutions that run simulated fraud calls alongside phishing simulations find their weak points before an attacker does.
Call back verification on held numbers
Dual approval above a set threshold
No reversals on a verbal request
Separate payment initiation and release
Run simulated fraud call exercises
Review transactions every month
Nakawa, Kampala, Uganda
Uganda and East Africa
Onsite and remote
John Doe joined UHA
12 people registered today
ECG Interpretation Workshop