Defending against SIM swap fraud

February 2024 Access Control & Identity Management

Mobile networks must not be complacent about SIM swap fraud, and they need to prioritise the protection of customers, according to Gur Geva, Founder and CEO of iiDENTIFii.

“Although SABRIC has noted a slight decline in reported SIM swap fraud in its latest report, mobile service providers still need to tighten up their data security to protect against fraudsters using false identities and SIM swap scams,” says Geva.

This is particularly relevant as telecommunications and banking industries become increasingly intertwined. Banks now offer mobile services, while mobile network operators provide financial services, and so there is a convergence between the regulatory requirements of FICA and RICA. This shift has led to heightened identity theft risks, requiring mobile operators to adopt stringent identity verification practices inspired by the financial sector's standards.

Operators need to define practical, robust security solutions that adhere to and surpass current telco legislation. Geva says, “In order to combat SIM swap and identity fraud, networks should focus on the provision of simple, scalable and safe digital identity. This has a far-reaching impact, not only on safer mobile use and the protection of consumers from fraud, but also on the ability of consumers to access mobile, financial and governmental services through their phones.”

The current state of SIM swap fraud

SABRIC’s 2022 crime report notes that mobile banking fraud saw a 9% reduction in reported incidents in 2022, and that SIM swap incidents declined from 87% in 2021 to 76% (7 657) in 2022. While this reduction is positive, there are still thousands of SIM swap fraud incidents reported each year.

“Cybercrime will continue to evolve, and networks need to be prepared for increasingly sophisticated SIM swap attacks. Their strongest line of defence is in securing the identity of a person’s identity to each SIM,” says Geva.

The effectiveness of this approach has been demonstrated in nations such as Kenya, Namibia, Pakistan and Russia, which have all been enforcing varying levels of biometric SIM registration to deter fraudsters.

Increasing legislation to prevent attacks

The nature of these SIM-related crimes goes beyond financial crimes and SIM swap fraud. “For the cost of a few unregistered SIM cards at R5 each from a roadside vendor, planning a murder becomes untraceable by police through RICA, and thus virtually risk-free,” says Natasha Mazzone, the DA’s Shadow Minister of Communications and Digital Technologies in an article on RICA legislation.

In 2022, ICASA published draft regulations that would require mobile network operators to collect subscriber biometric data. ICASA said these regulations would reduce instances of mobile number hijacking via fraudulent SIM swaps and number porting. However, this was met with hesitance from consumers and organisations such as the Communications Risk Information Centre (COMRiC). Consumers feared that the collection of biometric data would compromise their privacy, while COMRiC felt that biometrics as a single solution was too limited in its scope and challenging to implement at scale.

What networks can do

Mobile networks (as owners of the SIM and the technology behind it) should consider implementing clear strategies and leading technologies to mitigate SIM swap fraud and protect their customers. And while SIM swaps constitute one problem, identity fraud is far more problematic.

“When it comes to securing a person’s identity, we believe that face biometrics offer the most secure solution,” adds Geva.

In South Africa, face biometrics would be able to verify whether the person registering a SIM is live and doing it in the present moment, as well as binding the SIM card to that applicant’s identity and facial image. It can validate barcoded identification documents presented, RICA or FICA details and a facial image back to the Department of Home Affairs. This prevents identity fraud and proves that the individual applying for services online is a ‘live’ person and not a deepfake. SIM swaps become a moot point, as all SIM cards are then data bound to a legitimate individual with accurate RICA requirements.

The question of surveillance

Biometrics are deeply personal, but opt-in biometrics do not open consumers up to surveillance. “Because biometric technology only started making its way into the mainstream relatively recently, consumers are still unsure of what the technology entails and how it may be used. This, naturally, leads to some misconceptions and fears. The reality is that opt-in biometrics are the most secure way to identify someone – and keep their information and identity safe from misuse – and these differ a great deal from biometrics used for surveillance,” says Geva.

Remote biometric onboarding links a person’s biometric data, whether their face or fingerprint, to their account so that they, and only they, can access the account safely and securely. This protects them from fraud.

The question of implementation

In terms of successfully rolling out biometric identity for mobile phones in Africa to protect consumers and companies from SIM-related crime, two key criteria need to be met: scalability and accessibility.

“I urge network providers in Africa to invest in enterprise-grade identity platforms that are robust, scalable and built to handle growing subscribers and fraud-prevention demands,” says Geva. “For example, most of South Africa’s leading banks have relied on our own enterprise-grade platform at iiDENTIFii to roll out fast and effective mobile banking verification initiatives at scale. This has proven that, with a simple, fast and friction-free tool, consumers are willing to pass through an extra layer of digital protection.”

“SIM swaps are still a major problem, and networks still have a way to go in protecting consumers. By securing identity for all SIMs at the moment of registration, it is possible to make great leaps in providing protection against SIM-related crimes.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Keenfinity creates two security businesses
News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
The Keenfinity Group, today announced the creation of two dedicated businesses from its former Intrusion & Access portfolio. Radionix will focus exclusively on intrusion alarm systems, while MiCOS will become a dedicated access control company.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Connecting access control, logistics and asset tracking
Access Control & Identity Management Asset Management Logistics (Industry)
Physical barriers matter, but a site is not secure just because the gate is strong or the container is locked. True security requires verifying every movement, tracing handovers, making exceptions visible, and allowing intervention before minor issues become major losses.

Read more...
Gallagher Security assists St Vincent School for the Deaf
Gallagher News & Events Access Control & Identity Management
At a time when vehicle purchase and running costs are higher than ever, St. Vincent School for the Deaf will have a more reliable vehicle thanks to a recent donation from Gallagher Security.

Read more...
Solo replaces legacy access control
Paxton Access Control & Identity Management
Paxton’s new Solo system is giving student accommodation providers a simpler way to manage access at scale. This case study examines how a phone-based, cloud-hosted security system modernised access for 500 students without requiring network infrastructure.

Read more...
Readers support employee badge in Apple Wallet
Gallagher Access Control & Identity Management Products & Solutions
rf IDEAS, a global manufacturer of RFID credential readers, today announced that its WAVE ID readers support Gallagher Employee Badge in Apple Wallet, expanding the range of credential technologies supported across its reader platform.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.