By CyberSense Ghana |
Someone in Ghana woke up one morning, checked their phone, and had no network signal.
They assumed it was MTN acting up. By the time they figured out what had actually happened, their MoMo wallet was empty, their email had been accessed, and their bank account had been drained.
That's a SIM swap attack. And it's happening right here in West Africa — more than most people realise.
What Is a SIM Swap Attack?
A SIM swap (also called SIM hijacking or SIM porting) is when a scammer convinces your mobile network to transfer your phone number to a SIM card they control.
Once they have your number, every SMS-based OTP (One-Time Password) that your bank, MoMo wallet, email, or social media sends — goes to them, not you.
With that one move, they can:
- Reset your email password
- Log into your mobile money account
- Bypass two-factor authentication on your bank app
- Take over your WhatsApp and scam your contacts
It sounds like something from a hacking movie. It's actually shockingly simple to pull off.
How Does It Actually Happen?
Here's the typical attack chain in the West African context:
Step 1: They gather your personal info
Scammers collect your name, phone number, date of birth, and sometimes your Ghana Card or NIA details. This comes from:
- Data breaches (leaked databases sold online)
- Social engineering (calling you pretending to be your network provider)
- Your own social media posts (yes, that birthday post with your full name and photo helps them)
Step 2: They call your network provider
The attacker calls MTN, Telecel, or AirtelTigo customer care pretending to be you. They say something like:
"I lost my SIM card, I need a replacement on a new SIM."
They answer security questions using the info they already gathered. If the agent isn't careful, your number is ported to their SIM within minutes.
Step 3: Your phone loses signal
You notice your phone has no service. You assume it's a network issue. Meanwhile, the attacker is already receiving your OTPs.
Step 4: They clean you out
In the time it takes you to visit a service centre and figure out what happened, they've already:
- Withdrawn everything from your MoMo
- Transferred money from your linked bank accounts
- Locked you out of your email
Real Talk: Why Ghana and West Africa Are High-Risk Targets
- MoMo is everything. Mobile money is deeply embedded in daily transactions across Ghana, Nigeria, Senegal, and beyond. A compromised number = a compromised wallet.
- SMS OTP is still the dominant 2FA method. Most banks and fintech apps in the region rely heavily on SMS for verification — making SIM swap attacks particularly devastating.
- Customer service verification gaps. Not all telecom agents follow strict identity verification protocols consistently.
- Low public awareness. Most victims don't know what hit them until it's too late.
How to Protect Yourself: Practical Steps
✅ 1. Add a SIM Lock / Port Lock to Your Number
Call your network provider and ask them to add extra protection to your account — some providers allow you to set a PIN or password that must be provided before any SIM replacement is done.
- MTN Ghana: Visit a service centre and request a SIM swap lock
- Telecel / AirtelTigo: Ask customer care about account-level PIN protection
✅ 2. Move Away from SMS-Based 2FA
Wherever possible, switch from SMS OTP to an authenticator app:
These generate codes locally on your phone — even if someone steals your number, they can't get these codes.
❌ Less secure: SMS OTP → your phone number
✅ More secure: Authenticator app → your physical device
✅ 3. Use a Separate "Silent" Number for Financial Accounts
Consider having a dedicated SIM that you use only for banking and MoMo — one you never share publicly, never post online, and never use for regular calls or social media sign-ups.
✅ 4. Set Up Email Recovery That Doesn't Depend on SMS
If your email recovery method is your phone number, you've created a single point of failure. Add a recovery email address instead, and store your backup codes somewhere safe offline.
✅ 5. Be Stingy With Your Personal Information Online
- Don't post your full phone number on Facebook or TikTok
- Be careful with "fun" quizzes that ask for your name, date of birth, hometown — these are data collection tools
- Limit what's publicly visible on your social media profiles
✅ 6. Act Fast If You Lose Signal Unexpectedly
If your phone suddenly loses signal and you haven't changed anything:
- Immediately call your network provider from another phone
- Tell them you suspect a SIM swap
- Ask them to freeze your account
- Alert your bank and MoMo provider
- Change your email passwords from a trusted device
Speed is everything. The faster you act, the less damage is done.
For Developers: What You Should Know
If you're building apps that serve Ghanaian or West African users, SMS OTP should not be your only authentication option.
Consider implementing:
// Instead of relying solely on SMS OTP
// Offer TOTP (Time-based One-Time Password) support
const speakeasy = require('speakeasy');
// Generate a secret for the user
const secret = speakeasy.generateSecret({ length: 20 });
// Verify the token the user enters
const verified = speakeasy.totp.verify({
secret: secret.base32,
encoding: 'base32',
token: userInputToken,
window: 1
});
Libraries like speakeasy (Node.js) or pyotp (Python) make TOTP implementation straightforward. Pair it with a QR code so users can scan it into their authenticator app.
Your users deserve more than a one-point-of-failure SMS system.
The Bottom Line
SIM swap attacks aren't a distant, foreign threat. They're happening right now in Accra, Kumasi, Lagos, and Abidjan. And because mobile money is the financial backbone of millions of West Africans, the stakes are incredibly high.
The good news: awareness is your first line of defence. Share this with someone who uses MoMo. It might save them from a very bad morning.
This article is part of the CyberSense Ghana series — cybersecurity education built for Ghanaians and West Africans. Follow @cybersense101 on TikTok, Instagram, and Facebook for more.
Top comments (0)