You are here:

USSD Security: How to Protect Mobile Money Sessions From SIM-Swap Fraud

Table of Contents

hSenid USSD Gateway

hSenid USSD Gateway enables Telcos to rapidly create and deliver new value-added, dialog-based services, by providing a platform that links content providers to end users, opening up new means of generating revenue. 

USSD Datasheet Download

hSenid USSD Gateway Resource
Floating Share Bar

Table of Contents

USSD is often used for high-value journeys: checking balances, transferring money, paying bills and accessing mobile wallets.

That makes security part of the transaction design, not something that can be added later.

One threat operators and financial institutions have to consider is SIM-swap fraud. A criminal takes control of a subscriber’s mobile number by moving it to another SIM, then attempts to use that control to access accounts or intercept authentication.

The danger is simple: possession of a phone number does not always prove that the person using it is the legitimate customer.

 

What happens during a SIM-swap attack?

In a typical SIM-swap attack, a fraudster manages to have the victim’s number associated with another SIM.

Once the swap succeeds, authentication methods that rely heavily on control of the mobile number can become vulnerable.

GSMA describes SIM-swap fraud as a method criminals use to intercept messages, reset passwords and obtain verification codes for account takeover. Its SIM Swap API was created specifically to let applications check when a SIM was last changed or whether a change occurred within a specified period.

For a mobile-money provider, a recent SIM change combined with an unusual transaction should therefore be treated differently from an ordinary transaction.

The goal is not to block every subscriber who replaces a SIM.

The goal is to recognise when several risk signals appear together.

 

1. Check for a recent SIM swap before sensitive transactions

One of the strongest signals available to operators is something the network already knows: whether the SIM associated with a number recently changed.

GSMA Open Gateway’s SIM Swap API can return the latest SIM-swap date or answer whether a swap occurred during a defined previous period.

That makes a risk-based flow possible.

For example:

A customer opens a USSD mobile-money service.

They attempt to transfer a large amount.

The fraud engine checks the mobile number.

A SIM replacement occurred two hours earlier.

Instead of automatically approving the transaction, the service could trigger stronger verification, delay the transaction or send it for additional review according to the institution’s fraud policy.

The SIM-swap signal does not prove fraud. It gives the system a reason to look more carefully.

 

2. Do not rely on the mobile number alone

USSD already identifies the subscriber through the mobile network, but sensitive financial actions should still require appropriate authentication.

For many services, that means a PIN or another verification control before money moves.

The important distinction is between identifying the mobile connection and authenticating the person attempting the transaction.

Network-based signals can strengthen that decision further.

GSMA’s Number Verification API, for example, allows an application to verify that the phone number being presented is actually associated with the SIM currently accessing the service. It uses network- or SIM-based authentication rather than requiring an SMS OTP.

For higher-risk transactions, several controls working together are stronger than trusting one signal.

 

3. Combine SIM-swap data with real-time behaviour

A recent SIM swap becomes more meaningful when it appears with other unusual behaviour.

A fraud system could consider signals such as:

  • recent SIM replacement
  • recent device change
  • unusual transaction amount
  • unusual transaction frequency
  • repeated authentication failures
  • sudden changes in normal account activity

This is increasingly practical because telecom network signals can be exposed securely to banks and fintech applications.

Airtel, for example, has implemented GSMA Open Gateway/CAMARA-aligned fraud-prevention APIs that give banks and fintechs access to real-time signals such as recent SIM or device changes. GSMA describes the use case as a response to account takeover attempts involving unauthorised SIM replacements and intercepted authentication codes.

The lesson for USSD security is straightforward: evaluate the transaction context, not just the session.

 

4. Protect the USSD session itself

Fraud detection is only one layer.

The USSD gateway also needs reliable control over the session lifecycle.

hSenid’s USSD Gateway manages the initiation, management and termination of sessions for each USSD application. It also supports session resumption after unexpected timeouts within a configured period.

For financial services, session recovery must be designed carefully.

Resuming navigation does not mean automatically restoring every sensitive transaction state. Authentication, transaction confirmation and backend validation still need to follow the security rules of the service.

The objective is to preserve convenience without weakening transaction controls.

 

5. Monitor abnormal behaviour across the application

Fraud does not always arrive as one obvious event.

Patterns matter.

The hSenid product roadmap includes AIOps capabilities for abnormal-behaviour detection, application-level analysis and automated root-cause identification.

These capabilities are part of the product direction described in the material provided; they should not be presented as proven SIM-swap detection functionality today.

That distinction is important.

A USSD platform can provide secure session infrastructure, while SIM-swap detection may require integration with operator network signals or dedicated fraud systems.

 

Why this matters in a real banking deployment

For one hSenid deployment in the Democratic Republic of Congo, a leading bank used a USSD application to extend digital banking across mobile operators.

Subscribers could check balances, transfer value, pay utility bills and access wallet or agent services. The application processed nearly 20,000 transactions per day.

At that scale, security decisions are repeated thousands of times every day.

A single control is not enough.

Mobile-money security works better when the USSD session, subscriber authentication, transaction rules and telecom fraud signals work together.

 

What operators should build toward

When evaluating a USSD gateway for mobile money or looking for the best USSD provider for fintech, do not ask only whether the platform can deliver menus.

Ask how the complete transaction can be protected.

Can sensitive journeys require authentication?

Can the platform integrate with existing financial and fraud systems?

Can a recent SIM swap or device change influence the transaction decision?

Can suspicious behaviour be detected before money moves?

USSD may be simple for the subscriber.

The security behind it should not be.

Explore how hSenid’s USSD Platform supports operators in building and managing high-volume USSD services.

Now You Can Download

USSD Datasheet

You can get an idea about hSenid Smart Chatbot and investigations by referring this document.

Now You Can Download

USSD Datasheet

You can get an idea about hSenid Smart Chatbot and investigations by referring this document.