#1 Middle East & Africa Trusted Cybersecurity News & Magazine |

40 C
Dubai
Saturday, August 2, 2025
HomeAfricaNew Mobile Money Scam in Burkina Faso: Central Cybercrime Unit Raises Alarm

New Mobile Money Scam in Burkina Faso: Central Cybercrime Unit Raises Alarm

Date:

Related stories

CVE‑2025‑7847: Arbitrary File Upload in AI Engine Puts 100K+ WordPress Sites at Risk of RCE

On 18 July 2025, researchers at Wordfence disclosed CVE‑2025‑7847, a high-severity...

Jordan’s Cyber Incidents Soar: NCC Reports 6,758 Attacks in 2024

On 31 July 2025, Jordan’s National Cybersecurity Center (NCC) revealed that...

Russian FSB‑Linked “Secret Blizzard” Launches ISP‑Level AiTM Campaign Against Moscow Embassies

Microsoft Threat Intelligence has uncovered an advanced cyberespionage campaign...
spot_imgspot_imgspot_imgspot_img

The Central Brigade for the Fight Against Cybercrime (BCLCC) in Burkina Faso has issued a high-alert fraud advisory after detecting a growing scam targeting Mobile Money users. This wave of attacks has already generated over 60 official complaints and caused estimated losses exceeding 10 million CFA francs. Cybersecurity professionals must pay attention now to advise on preventative measures.

In late July 2025, the BCLCC began tracking a novel scam where fraudsters impersonate mobile-operator agents to trick victims into updating their Mobile Money accounts. According to their technical unit, scammers first call the target, then send an SMS containing a malicious link under the guise of verifying an update. Victims are asked to input the SMS verification code, which scammers then use to reset passwords-granting full access to the electronic wallet.

Once access is achieved, attackers execute unauthorized withdrawals or even initiate transfers from linked bank accounts. As of 25 July 2025, the BCLCC has logged more than 60 complaints with estimated financial losses exceeding 10 million CFA francs.

Impact & Local Cybercrime Response

This scam is particularly alarming given the widespread use of Mobile Money across West Africa. In Burkina Faso, these services underpin much of informal commerce, making millions vulnerable to social-engineering attacks.

The BCLCC’s technical team urged users to remain vigilant:

  • Do not click links in SMS messages claiming to come from your operator.
  • Never share your verification code.
  • If in doubt, reset your PIN immediately or contact your operator.

BCLCC also promoted its Alerte‑BCLCC platform, launched on 11 February 2025, enabling citizens to report suspicious activity online or via mobile apps (Playstore, Huawei AppGallery, Apple Store).

Regional & Global Context

While this alert concerns Burkina Faso, the scheme reflects broader global trends in Mobile Money fraud and digital wallet scams that have surged across Africa. Countries with similar mobile-operator ecosystems-such as Côte d’Ivoire, Ghana, Nigeria, and Senegal-should take note. Recent patterns show fraudsters leveraging low digital literacy and trust in telecom brands to phish verification codes or reset credentials.

Expert Commentary

Dr. Mariam Ouédraogo, cyber‑security researcher in Ouagadougou, notes:

“This kind of social‑engineering attack on Mobile Money users is increasingly sophisticated and emotionally manipulative. It’s vital that telecoms and regulators step up public awareness campaigns now.”

Jonathan Mensah, digital‑finance consultant in Accra, adds:

“Scams exploiting SMS flows and verification codes are old tactics, but combining phone calls and spoofed links enhances trust and success rates. Service providers must strengthen security services and user training.”

Actionable Takeaways for Cybersecurity Teams & Executives

  1. Run User Awareness Campaigns – Educate Mobile Money users about phishing techniques and the risks of sharing verification codes.
  2. Train Customer‑Support Teams – Ensure operator staff know how to respond to reported scams.
  3. SMS Filtering & Link Warnings – Telecoms should flag suspicious messages or block known phishing URLs.
  4. Enable Two‑Factor Authentication (2FA) – Where possible, allow secondary verification methods in wallets or linked accounts.
  5. Monitor Transaction Patterns – Set alerts for abrupt activity following password resets.
  6. Promote Official Reporting Channels – Encourage clients to report fraud via platforms like Alerte‑BCLCC.
  7. Strengthen Telecom‑Law Enforcement Cooperation – Operators and BCLCC should collaborate on takedown and traceability.
  8. Run Red‑Team Exercises – Simulate social-engineering attacks to test resilience across the ecosystem.
  9. Update Consumer Protection Regulations – National regulators must require transparency and warnings around SMS-based updates.
  10. Support Digital Literacy Initiatives – NGOs, operators, and governments should co-develop educational content.

Conclusion

This Mobile Money fraud scheme highlights the evolving threat of social-engineering attacks targeting electronic-wallet users. While centered in Burkina Faso, the tactics bear relevance across West and Central Africa where Mobile Money adoption is growing rapidly. Vigilance, user education, and operator cooperation remain the best defenses. To keep communities safe, digital trust must be actively nurtured through proactive security awareness and coordinated fraud prevention efforts.

Sources

  • Sentinelle BF article on Mobile Money scam, 25 July 2025
  • 24Heures BF coverage of complaints and financial losses
  • NetAfrique.net report summarizing BCLCC alert, 27 July 2025
  • Actualité BF summary of the scam and recommendations
  • Sidwaya overview of Alerte‑BCLCC platform launch, February 2025
  • AITN coverage of broader cybercrime trends in Burkina Faso
  • CyberCory.com report on West African fraud trends
Ouaissou DEMBELE
Ouaissou DEMBELEhttp://cybercory.com
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here