22.6k unique visitors in the last 3 days

Regulating Telcos Like Banks, Ghost Accounts, SIM Swaps and Bananas: Episode 5 of The Commsrisk Show

The theme of our April 12 broadcast was the risk and regulatory implications of telcos providing financial services.

Joseph Nderitu returned as our guest for this week’s episode of The Communications Risk Show, sharing insights derived from his time as one of the first RA professionals to assure M-PESA at mobile money pioneer Safaricom, and from the work he has done with mitigating the risks surrounding mobile money at many other leading African telcos. Safaricom has been hit with two lawsuits about M-PESA. One says the telco is lending money like a bank and should be regulated accordingly, whilst the other claims Safaricom is to blame for a wave of account takeover frauds as criminals seek to hijack accounts, including the ‘ghost accounts’ of deceased users, in order to drain the wallets and borrow money in somebody else’s name.

The regular crew also debated whether telcos are failing to appreciate the change in their risk profile as they transition towards an increasingly common model that involves the same software running on commodity hardware. Each vulnerability becomes more serious as bad actors will know many more telcos will share the same vulnerability. This then encourages a rise in ransomware attacks, data privacy hacks that target leaky APIs, and the insertion of malware through supply chain attacks. A lack of diversity in farming methods is putting banana crops at danger because diseases spread more easily and could affect harvests globally; should engineers and security professionals start treating diversity of electronic systems as a way to reduce the number of occasions when bad actors target their businesses?

Another example of reduced diversity is the extent to which different organizations and different societies are placing much more reliance on the connection between a SIM and a phone user when identifying who is accessing their services online. This has motivated an international criminal industry focused on SIM swap frauds and other methods to hijack a user’s phone account. Making phones the gateway to valuable assets like bank accounts, mobile money wallets and cryptocurrency exchanges means that criminals can easily afford to bribe telco staff to execute SIM swaps. The team debated whether this risk could realistically be mitigated and whether it is appropriate to implement more invasive monitoring of staff.

Episode 5 of The Communications Risk Show can be watched again by using the player below. Live shows are streamed every Wednesday at tv.commsrisk.com. There you will also find recordings of all past episodes, which are updated soon after each live show finishes, and links to the audio-only podcast version, which can be streamed or downloaded from Spotify and Apple.

Eric Priezkalns
Eric Priezkalnshttp://revenueprotect.com

During his career, Eric has been a Director of Risk Management for a national telco, the Chief Executive of the Risk & Assurance Group, a Chief Marketing Officer for a software business, a consultant, a public speaker and the publisher of Commsrisk since its launch in 2006. Look here for more about the history of Commsrisk and the role played by Eric.

The comms providers that Eric has worked for include Qatar Telecom, Cable & Wireless, T‑Mobile, Sky and Worldcom. In addition to his proficiency at speaking about the current scamdemic, Eric is also a qualified chartered accountant and a subject matter expert in consumer protection, enterprise risk management, fraud prevention, data integrity and billing accuracy. Eric was the lead author of Revenue Assurance: Expert Opinions for Communications Providers, published by CRC Press. He can be reached through the contact form on this website.

Related Articles

The Commsrisk Global Fraud Dashboard


Our Global Fraud Dashboard uses AI-powered search to collate, update and visualize data about scams and other network abuses from around the world. New charts are added each month. See it here.

Get Our Weekly Newsletter by Email