USSD Fraud Is Still a Major Problem - and Authentication Isn't Enough
It is easy to assume USSD is a legacy technology on its way out. It is not. Across Africa, South Asia, and parts of Latin America, USSD - those *123# menu sessions on ordinary phones - remains the primary way hundreds of millions of people move money. For financial inclusion, it is indispensable. For fraud teams, it is a persistent headache.
The reason is simple: USSD combines high transaction value with very low visibility. And the industry’s default answer - stronger authentication - does not solve the problem, because authentication is rarely where USSD fraud breaks.
Why authentication falls short on USSD
USSD security has traditionally leaned on two things: a PIN and, sometimes, an OTP. Both are routinely defeated, and none of the common attack paths actually require breaking them:
- SIM swap. Take over the number and the OTP arrives in the fraudster’s hand. The PIN is often the only remaining barrier - and PINs are short, reused, and observable.
- Stolen or borrowed phones. A physical phone plus a shoulder-surfed or coerced PIN is enough. The session authenticates perfectly.
- Social engineering. Victims are talked through sessions step by step, or persuaded to share their PIN with a fake “agent” or “bank official.”
- Compromised PINs. PINs leak through phishing, observation, and reuse across services.
- Session abuse. Once a session is open on a controlled handset, the fraudster transacts as the legitimate user.
In each case, the credentials check out. Piling on more authentication - more PINs, more codes - mostly adds friction for legitimate users on constrained devices while barely inconveniencing the attacker.
The real problem: USSD is a low-telemetry channel
Modern app-based fraud prevention thrives on data. A banking app can observe the device, sensors, typing rhythm, touch dynamics, navigation flow, and a rich session context. USSD offers almost none of this. A USSD session is a short, menu-driven exchange over the mobile network: a handful of inputs, a service code, an amount, a destination.
That scarcity of signal is exactly why fraudsters prefer it. Controls that depend on device fingerprinting or behavioral biometrics from a smartphone simply have less to work with here. Treating USSD as “the app minus features” leaves a gap; it needs a defense designed for its constraints.
Compensating with context and behavior
If the channel gives you little device telemetry, you have to extract maximum value from the signals you do have - and from everything you know about the customer over time. That shifts the focus from authenticating the session to reasoning about its risk.
Even a thin USSD session carries meaningful context:
- Transaction behavior. Is this amount, time of day, frequency, and destination consistent with how this customer normally transacts? A sudden high-value transfer to a brand-new beneficiary at 3 a.m. is a story, even without device data.
- Velocity and sequence. Rapid repeated transfers, or a PIN change immediately followed by a large withdrawal, are classic takeover patterns.
- Beneficiary risk. Destinations linked to known mule activity are risky regardless of channel.
- Cross-channel signals. A SIM swap or a suspicious app-side event just before a USSD transfer connects the dots across channels.
- Account-lifecycle context. New account, dormant-then-active, or a recent contact-detail change all shift the risk.
Individually thin, these signals combine into a genuine risk assessment - one that can flag a fraudulent USSD transaction that authentication would happily wave through.
How Paygilant closes the USSD gap
Most fraud-prevention tools are built app-first and treat USSD as an afterthought. Paygilant is explicitly designed to deliver strong detection across both apps and USSD, precisely because so many of its customers’ users live on basic phones.
Instead of relying on device telemetry that USSD cannot provide, Paygilant leans on behavioral and contextual risk scoring: it evaluates each transaction against the customer’s established patterns, the beneficiary’s risk, velocity and sequence, and any cross-channel signals - continuously, and in real time. The result is a “safe or risky” judgment even when the only inputs are a short menu session and everything the system already knows about that user.
USSD is not going away, and neither is USSD fraud. But with contextual, behavior-aware risk scoring, banks no longer have to accept it as an unavoidable blind spot - or punish inclusive customers with friction that stops the honest and barely slows the fraudster.