Mobile Money Fraud Begins at Onboarding: Two Billion Accounts, One Perimeter
Sigilith Research
Institutional AI governance & accountability
A note on scope. This brief is written from public records: GSMA industry reports, regulator and police statements, disclosures to parliaments, and published research, all cited at the end. It discusses countermeasures at the family level only, for the same reason our liveness explainer does, and it describes no production system's mechanics, no client, and no specific deployment.
More than $2 trillion moved through mobile money in 2025, across 2.3 billion registered accounts, 593 million of them active in a given month. It took the industry twenty years to pass $1 trillion in annual transaction value and four more to double it. A service that began as an SMS remittance channel is now the first and often only financial system available to hundreds of millions of people, and the GSMA credits it with adding roughly $190 billion to Sub-Saharan Africa's GDP in 2023 alone.
Every one of those accounts came into existence the same way: a person claimed an identity, at an agent's counter or into a phone camera; something or someone checked the claim; an account was issued. That moment is the subject of this brief, because the public record of the last four years is unambiguous about two things. First, this is where mobile money fraud actually begins: not in the transaction stream but at enrollment, where a false accept mints the mule accounts every later scam drains into. Second, the same threshold has a second error with no headline attached: the false reject, which turns away a genuine first-time applicant, and in these markets a first-time applicant is precisely the person the system exists to reach.
1. Why onboarding is the perimeter
The GSMA's most systematic public study of the problem, a 2024 typology built on consultations and a survey across 34 countries in Africa, Asia, and Latin America, asked mobile money professionals which fraud schemes they actually contend with. Identity fraud ranked first, cited by 90.38% of respondents, ahead of social engineering (88.46%), insider fraud (86.54%), and SIM swap fraud (78.85%). And the report is specific about where identity fraud happens: it is "mostly carried out at the point of subscription," through stolen genuine documents, forged or synthetic identities, or biometrics captured once and reused.
That location matters more than the ranking. A fraudulent transaction is an event inside an account; it can be scored, throttled, reversed. A fraudulent enrollment is different in kind: it is a legitimate credential correctly issued to a false claim. Nothing downstream misbehaves, because downstream controls audit behavior against identity, and the identity was fiction from minute zero. The account ages quietly, passes its early checks, and becomes valuable precisely by having a clean history. Transaction monitoring can tell you an account is acting wrong. Only the perimeter can tell you an account should never have existed.
So the onboarding decision carries two failure modes with very different signatures. Accept a false claim and you have created infrastructure for someone else's crime: a mule account, a farm unit, an exfiltration point. Reject a true claim and you have excluded a person, usually one holding a cheap phone and a thin or absent file, and the exclusion generates no alert, no case number, and no record that anyone was harmed. The rest of this brief is the public record of each error's cost.
Stolen and fictitious identityenters at 01 · 04
The claim itself is false: a genuine ID that belongs to someone else, a forged document, or a synthetic identity blended from several real people. The GSMA's 34-country typology ranks identity fraud first and places it at the point of subscription.
- Why the paperwork passes
- The document check answers the wrong question. A stolen genuine ID is authentic in every way a forgery inspection measures, and a well-made synthetic can validate against real registry numbers.
- The family-level counter
- One live, distinct human per enrollment is the unit this pattern cannot mass-produce. Paperwork replicates; a different living person per account does not.
Public record · Kenya: 287,214 SIMs deactivated in a quarter · India: 13.6M fake connections
Patterns and case figures are drawn from public reporting: the GSMA’s 2024 fraud typology and the regulator, police, and parliamentary records cited in this article. Countermeasures are named at family level only; no mechanism, threshold, or implementation, ours or anyone’s, is described. The reading that matters: every pattern enters at a different stage, and every one exits through the same door, a live account with clean paperwork.
2. SIM registration fraud: what the public record shows
In most mobile money markets the SIM is the root credential: the account is the number, and registering the SIM against a legal identity is the KYC event. Regulators across the world have spent the past decade mandating exactly that binding, and the results read as a controlled experiment in where fraud goes when you build a gate: it moves into the gate.
Kenya. In September 2022, ahead of an October deadline for subscribers to validate their registration details, the Communications Authority reported that operators had deactivated 287,214 SIM cards registered with incorrect identity particulars in a single quarter, and noted that subscribers checking their records were discovering numbers registered in their names without their knowledge. The pattern has not retired: in November 2025, police in Molo arrested six suspects holding 2,464 national identity cards and more than 3,000 SIM cards, suspected of feeding mobile money scams.
The Philippines. The SIM Registration Act of 2022 required every SIM to be registered to a verified identity; when the deadline passed in July 2023, more than 54 million unregistered SIMs were deactivated. Two years later the national police were describing the adaptation: syndicates conducting, in their words, "mass registration using fake credentials" to activate thousands of SIMs, then selling the pre-registered cards openly, including on social media marketplaces. The gate exists; a market in gate-passage grew beside it.
India. The Department of Telecommunications turned the problem into a re-verification exercise. In July 2025 the communications minister told parliament that more than 1.36 crore (13.6 million) fake mobile connections had been disconnected under the Sanchar Saathi initiative's re-verification service. Separately, the department operates ASTR, an AI-based tool built to flag connections taken out on forged documents or in bulk against one face.
Three jurisdictions, one lesson. Registration mandates converted an anonymous channel into an identity-bound one, and the fraud converted with it: from unregistered SIMs to fraudulently registered ones. The enrollments that matter now are the ones that pass every documentary check, because the documents are genuine and stolen, or forged once and replayed at scale. A gate that inspects paperwork is a gate that farms can feed. It is the mobile money form of the lesson synthetic identity fraud teaches in credit markets: checks that examine records are passed by whoever manufactures the records.
3. How mobile money agent fraud works at enrollment
The distribution network that makes mobile money work is human. In 2024 there were 28 million registered mobile money agents, 10 million of them active monthly: 755 registered agents per 100,000 adults in mobile money markets, double the density of 2021. Agents digitized $356 billion of cash in 2024. For most customers, the agent's counter is the branch, the ATM, and, critically, the enrollment desk.
The GSMA's typology is direct about what that concentration means: where providers allow agents to carry out SIM registration, agents "can also carry out identity fraud and theft, such as registering fictitious mobile money accounts." The report documents the mechanics in family terms: an agent initiates a registration with a customer's biometrics, tells the customer it failed, and has them repeat the process against different numbers, leaving the agent holding registered accounts the customer does not know exist. Its survey found insider fraud, which in this ecosystem includes agents and third-party staff, ranked as a leading scheme by 86.54% of respondents, with 94% expressing concern about insiders and collusion with external fraudsters named the top insider scheme. One case study traces a scheme in which insiders created e-money on the platform and moved it out through fictitiously registered customer accounts and agent till lines.
The industry's own state-of-the-industry reporting frames the situation without varnish: fraud remained "a pervasive issue" in 2024, and "most mobile money fraud revolves around activities by agents or customers." Two adjacent findings explain why it persists. More than 70% of providers consider law enforcement ineffective against mobile money fraud, citing capacity, resourcing, and corruption. And most providers detect fraud through customer complaints, which is to say: after the harm, from the victim.
None of this makes agents villains; agents are also fraud's most frequent victims, and the same GSMA research catalogs the schemes run against them. The structural point is narrower and harder: the person operating the perimeter is paid by throughput. Commissions reward activations. The enrollment happens on the agent's own device, against documents the agent alone inspects, in a session no one else witnesses. Where that is true, the check and the checked share a channel, and the channel has a quota.
4. Mule accounts: what a false accept becomes
A mule account is where a false accept goes to work. The GSMA typology describes the role plainly: money stolen elsewhere, including from bank accounts, is withdrawn through the agent network via money mules, using mobile money as the exfiltration layer. The account itself did nothing anomalous until the day it did, and by then the funds are cash.
The public record now shows this at industrial scale. In September 2023, Philippine authorities raiding an offshore-gaming compound in Pasay City recovered roughly 28,000 pre-registered SIM cards with e-wallet accounts attached, together with lists of account numbers, balances, and passwords; the Department of Information and Communications Technology said the accounts had been used to siphon about PHP 1 billion from scam victims. In India, authorities reported in November 2024 that about 450,000 suspected mule bank accounts had been frozen in roughly a year, most of them opened with genuine KYC documents belonging to someone else. Legislators are responding in kind: the Philippines' Anti-Financial Account Scamming Act of 2024 made money muling itself an offense, including opening an account under a fictitious identity and selling or renting out an account.
The economics deserve one plain sentence: an account farm is a bet that onboarding is repeatable. Its unit cost is the cost of one more successful enrollment; its unit revenue is what a clean account is worth to a scam operation. Every mule account in every seizure list was a false accept once, and the cost of that acceptance landed months later, on a victim in a different city, through a cash-out point in a different network, in someone else's ledger.
Which raises the question every one of these cases eventually forces. When the trace-back arrives at the enrollment, what exists? Who opened this account, against which documents, checked how, approved by whom? Most operators can produce a registration form. Far fewer can produce evidence in the sense an investigator or regulator means the word: a contemporaneous, tamper-evident record of what was captured and what was decided. The onboarding decision is the one that made everything after it possible; it is usually the least documented decision in the chain.
5. What a false reject costs: the financial inclusion trade-off
The other error never makes a seizure list. The World Bank's Global Findex 2025 measured account ownership at 79% of adults worldwide, which leaves 1.3 billion adults with no account at all. About 900 million of them own a mobile phone, 530 million of those a smartphone: the rails reach them, and the perimeter is what stands between them and a first account. The barriers Findex finds are mundane and stubborn: money, distance, and, consistently, documentation. The World Bank's identification program estimated in 2021 that some 850 million people lacked official ID entirely.
Now put hardware under that. The GSMA's connectivity research prices an entry-level internet-enabled handset at 18% of average monthly income in low- and middle-income countries, rising to 51% for the poorest 20%, and to 99% of a month's income for the poorest fifth in Sub-Saharan Africa. The marginal mobile money applicant is therefore, almost by definition, on the cheapest camera in production, often a shared or second-hand device, frequently in bad light. A verification stack tuned on flagship phones will read those conditions as risk, and as we wrote in the liveness explainer, the bona fide error rate lands hardest on exactly this population: a false rejection is a person denied an account, often the first account they have ever tried to open.
The asymmetry between the two errors is what makes tuning by instinct dangerous. A fraud ring treats rejection as a unit cost: next SIM, next document, next attempt; rejection is amortized across the farm. A first-time applicant rejected at the counter may simply never come back, and the system records nothing, because a person who was never onboarded generates no data. One error produces raids, freezes, and headlines. The other produces silence. Institutions overcorrect toward whichever error they can see.
And both errors spend the same currency: trust. CGAP and IPA's national surveys find that in Uganda the median fraud loss equals 23% of a household's monthly income, and that users in Kenya, Rwanda, and Uganda who lost money to fraud show significantly lower trust in digital finance providers; in Peru, 11% of users who experienced fraud stopped using digital financial services and a further 25% reduced their usage. Fraud that gets in drives the included back to cash; a harsh filter keeps the excluded out. The trade-off is not fraud prevention versus financial inclusion. Managed badly, each error erodes inclusion by itself.
A false acceptLoud
Who pays
A scam victim somewhere else first, then the operator once the trace-back arrives at the enrollment that made it possible.
When the cost lands
Months later, at cash-out, after the account has aged into exactly the clean history that makes it valuable.
What it compounds into
Criminal infrastructure at farm economics: each accepted enrollment is one more mule account, priced at the cost of one more sign-up.
What the public record shows
Raids, freezes, and seizure lists: 28,000 pre-registered wallet-linked SIMs recovered from one Pasay compound; about 450,000 suspected mule accounts frozen in India in roughly a year.
Both errors spend the same currency, trust: CGAP and IPA surveys find fraud losses in Uganda run to a median 23% of a household’s monthly income, while in Peru 11% of users who experienced fraud stopped using digital finance entirely. The asymmetry is the argument: one error is loud and the other silent, so a perimeter tuned by instinct drifts toward the error it cannot see. Governing the pair together is a policy and records problem, not only a model problem.
6. Presence, escalation, and the record: the field-level answer
What actually narrows both errors at once? The public literature keeps returning to three elements, all of them field-level, none of them secret as categories.
Presence. The enrollment-fraud patterns above share one economic dependency: they scale by not producing a distinct, live human being for every account. Stolen documents, synthetic identities, replayed biometrics, and pre-registered farms all reproduce paperwork; none of them cheaply reproduces a different living person in front of a camera, once per account, at enrollment time. Verifying presence (the countermeasure families: challenge-response at capture, material and texture analysis, display and recapture forensics, device and session intelligence) attacks the farm's arithmetic rather than the applicant's paperwork. It is also, notably, a check the document-poor applicant can pass: presence does not require a file, a credit history, or a document the applicant may never have been issued. Presence is not identity, and it does not claim to be; it establishes that the enrollment event contains a human, which is the premise every later check silently assumes.
Escalation. Every verification system has an ambiguous band, and in this market the ambiguous band is not exotic: it is an old camera, a dim room, a first-time user moving slowly. Auto-rejecting that band exports caution as exclusion; auto-accepting it invites the farm. The defensible pattern is the one we have described before: ambiguity routes to a person with authority to decide, the evidence is assembled in front of them, and the resolution is attributed. In regulated onboarding a rejection is an adverse action against an identifiable person; "the model was unsure" is not an account of it.
The record. Both errors are eventually adjudicated somewhere: the false accept in a trace-back, a freeze order, an investigator's request; the false reject in a complaint, an audit of exclusion, a regulator's question about who is being turned away and why. The onboarding decision must therefore be able to outlive the session that produced it: what was captured, which checks fired against which policy, who decided, sealed at the time and producible later. What that record must contain is its own discipline, and it applies to accepts and rejects equally, because in this domain both are consequential decisions about a person.
Our own entry in this field, Sigilith Sentry, is built on exactly that pattern, and claims here only what we claim publicly: a single capture with an active light challenge, adjudication on the server rather than the device, escalation of ambiguous sessions to a named officer, and a sealed, tamper-evident record of every verdict. Presence, not identity. How any of it works internally is not in this article, deliberately.
The diagnostic we would leave with any operator is the one that costs nothing to run. Pick one accepted enrollment and one rejected applicant from eighteen months ago, and try to reconstruct both decisions: what was seen, what was checked, who decided. The first tells you what you could say to an investigator. The second tells you what you could say to the person you turned away. An onboarding perimeter that can answer both questions is rare, and it is what the next decade of mobile money growth will be judged on.
Sources
Industry and research reports
- GSMA, State of the Industry Report on Mobile Money 2026, and press release, 24 March 2026: $2 trillion in 2025 transaction value, 2.3 billion registered accounts, 593 million monthly active accounts
- GSMA, State of the Industry Report on Mobile Money 2025 (April 2025): 2024 agent figures, cash-in value, and the fraud and regulatory findings quoted above
- GSMA, Mobile Money Fraud Typologies and Mitigation Strategies (March 2024): the 34-country survey, identity-fraud and insider-fraud rankings, agent registration schemes, and mule exfiltration description
- GSMA, The State of Mobile Internet Connectivity 2024, press release: entry-level handset cost as a share of monthly income
- World Bank, Global Findex Database 2025, press release, 16 July 2025: account ownership, the 1.3 billion unbanked, and phone ownership among them; Findex 2021 on barriers to account ownership
- World Bank, Identification for Development (ID4D) and "850 million people globally don't have ID" (2023)
- M. Chalwe-Mulenga, E. Duflos, G. Coetzee, The Evolution of the Nature and Scale of DFS Consumer Risks: A Review of Evidence, CGAP, February 2022
- E. Duflos, Fraud in Digital Finance: A Crisis Calling for Ecosystem Solutions, CGAP, July 2026: the Uganda, East Africa trust, and Peru usage findings
- ENISA, Remote Identity Proofing: Attacks & Countermeasures (January 2022)
Regulator, police, and government records
- Communications Authority of Kenya, Operators Deactivate 287,214 SIM Cards Registered with Wrong IDs as 15th October Deadline Looms, 26 September 2022
- Citizen Digital, Six suspected SIM card fraudsters arrested in Molo, 6 November 2025
- Gulf News, Philippines: 54 million unregistered SIM cards deactivated, August 2023, on enforcement of the SIM Registration Act (Republic Act No. 11934)
- SunStar, PNP cracks down on syndicates selling pre-registered SIM cards, 12 October 2025
- GMA News, 28K SIM cards with e-wallets seized in Pasay scam hub, September 2023, and Philstar, SIM cards from POGOs contain P1 billion in e-wallets, 15 September 2023
- Republic of the Philippines, Republic Act No. 12010, Anti-Financial Account Scamming Act, approved 20 July 2024
- News On Air (Prasar Bharati), Over 1.36 crore fake mobile connections disconnected under Sanchar Saathi, says Communications Minister, 30 July 2025
- Business Standard, Centre freezes 450,000 'mule' bank accounts used in cyber fraud schemes, 12 November 2024
Related Sigilith analysis
Also Applicable To