Scammers are copying banks' own security warnings to steal your PIN, Airtel Money boss warns

Japhet Aritho (extreme right) joins other panellists to pose for a photo during Day 1 of the inaugural National Cybersecurity Conference in Kampala. Thank you for all your support.
Scammers targeting mobile money users have learned to weaponize the very security warnings meant to protect the public, opening fraudulent calls with official-sounding language before manipulating victims into giving up their PINs, a top Airtel Money executive told regulators, bankers, and telecom operators gathered at Uganda's first National Cybersecurity Conference.
The conference, organized by the Uganda Communications Commission (UCC) under the theme "Securing Uganda's Digital Future: Collaboration, Resilience and Trust," brought the country's digital finance industry together to grapple with a fraud problem that has grown alongside Uganda's mobile money boom.
During a panel on social engineering, SIM swap fraud, and account takeover, Japhet Aritho, Managing Director of Airtel Money Commerce Uganda Limited (AMCUL), argued that the industry has spent too long treating these threats as separate problems when they are really links in a single chain.

"For you to take over a mobile account, you have to do a SIM swap. For you to do a SIM swap, you have to start with social engineering, because there is some information that you have to pick," Aritho told the audience, describing how one form of deception typically enables the next.
He said telecom companies had been fighting this battle long before it became front page news, pointing to a homegrown fix that has since become industry standard. Airtel Money built a simple internal API and shared it with every commercial bank in the country, allowing lenders to check in real time whether a SIM card tied to an account had recently been swapped. Airtel later pushed the Bank of Uganda to make the check, now known as the IMSI check API, mandatory across the sector.
Aritho also pointed to Airtel's newer AI Spam Alert Service, which scans for patterns in fraudulent text messages and flags them to subscribers before a scam can take hold. But he warned that even well-informed customers remain vulnerable, because fraudsters have adapted by mimicking the exact warnings telecom firms send out. "They will tell you exactly what we are telling them... and then they will trick you into sharing your PIN," he said.
His proposed fix leans less on customer vigilance and more on technology doing the work quietly in the background. He described device-binding systems that automatically freeze transactions the moment a phone or SIM tied to an account changes, locking the account until the holder re-verifies their identity, a safeguard that kicks in even if a scammer already has someone's login details. Aritho spoke from personal experience, noting that being locked out of his own financial apps after switching phones was frustrating in the moment but a small price next to the cost of fraud.
He also pushed back firmly against the instinct to blame victims for falling for scams, arguing that today's fraudsters are often polished and convincing. "It's very difficult to spot a scammer... they speak good English, they make you comfortable," he said, insisting that responsibility for protection belongs with service providers at the design stage, not with consumers alone.
The conversation also turned to data privacy more broadly. Fielding a question on how safe personal information is once it's handed over to service providers, Macgyver Mugamba, UCC's Manager for Data Protection and Legal Advisory, reminded attendees that Uganda's Data Protection Act gives individuals the right to ask companies how their data is stored and used, and whether proper policies are in place. Complaints that go unresolved, he noted, can be escalated to the Personal Data Protection Office under the Ministry of ICT.
Closing the panel, Aritho called on telecom operators, banks, and regulators to treat cybersecurity as something built into products from day one rather than bolted on afterward, warning that the whole digital ecosystem is only as secure as its most vulnerable participant. "We are as strong as an ecosystem as the weakest link within that ecosystem," he said.
