
Mobile money is not informal money
How investigators trace wallets, agents, SIM swaps, mule accounts and cash-out patterns
A phone call at 9 a.m. from a managing director who had not called for the past two years is always interesting. “Mustapha, how are you? Indeed, you are legit, your phone number never changes. What is the earliest we can meet today?”
Before that call, at 8:17 a.m. on a wet Monday morning, the finance director of a large manufacturing and distribution company walked into the accounts office holding two reports that should have agreed. They did not.
The general ledger showed that the company’s regional collections had been received. The mobile-money settlement report showed that UGX 214,680,000 had left the collection environment through transactions that nobody in the room could immediately explain.
The company’s authorised approver, a tall, soft-spoken manager who normally carried two phones, insisted that he had approved nothing. The narrow-shouldered accounts assistant responsible for daily reconciliation said the platform had been unstable. A heavily built field supervisor blamed delayed reversals. Three agents operating around Kampala and Wakiso said they were merely serving customers. Everybody had an explanation, nobody had a complete one. That is when Summit Consulting Ltd was called in.
The case described here is a composite investigative scenario based on recognised mobile-money fraud patterns. It does not accuse any individual, agent, telecommunications company or financial institution. You need to know that an investigator is not hired to confirm management’s suspicions but to test competing explanations against evidence.
My opening statement to the investigation team was simple: “Stop calling this informal money. Cash may disappear into a pocket without leaving its name behind. Mobile money usually passes through systems, wallets, devices, agents, transaction identifiers, timestamps, approval records and settlement accounts. The challenge is not whether a trail exists, but whether you know where to look, how to preserve it and how to explain it without exaggerating what it proves.”
Uganda’s National Payment Systems Act treats electronic money as monetary value represented by a claim on the issuer, stored electronically, issued upon receipt of funds, accepted as a means of payment and redeemable in cash. Mobile money therefore operates within a regulated payment ecosystem. It is not merely cash travelling through a telephone.
The ledger was telling only half the story
The fraud allegation began with an accounting difference, not a telephone. That is the first point many investigators miss. A mobile-money investigation should not begin by grabbing phones from employees and searching for suspicious messages. It should begin by defining the financial event that must be explained.
The company’s ledger contained collection entries supported by manually uploaded schedules. The schedules carried transaction references, customer names and amounts. Yet several references had been used more than once, some customers denied making the stated payments, and certain collections were posted several hours before the corresponding mobile-money transaction allegedly occurred. The accounting records were not useless, but they could no longer be treated as independent proof.
The second insight came from timing. Most questionable transfers occurred between 6:40 p.m. and 8:15 p.m., shortly after the daily reconciliation team had signed off. The transactions were then divided among several wallets before the next morning. Timing does not prove dishonesty, but it can reveal a control window. Whoever designed the movement appeared to understand when the business stopped watching.
The third insight was behavioural. The questionable transfers did not resemble ordinary company payments, and legitimate payments went to known suppliers in predictable amounts. These transfers moved to recently active personal wallets, were divided into smaller amounts and were withdrawn or transferred onwards soon after receipt. FATF has identified rapid movement through accounts and the use of money mules as recurring features in cyber-enabled fraud, while GSMA recognises impersonation, identity fraud, social engineering and SIM-swap fraud among important mobile-money typologies.
The fourth insight was more confrontational. The records suggested internal knowledge, but they did not yet identify an internal offender. An outsider can learn approval routines through social engineering, a compromised account can imitate an employee and a genuine employee can also have credentials used without permission. The investigator must separate access, action, knowledge and benefit. They are related, but they are not the same fact.
A wallet name is not a conviction
The initial wallet statements showed that the money had passed through fourteen personal wallets. Management wanted the registered holders arrested immediately. That would have been reckless.
A wallet registration identifies the person in whose particulars the account was opened. It does not automatically establish who possessed the SIM, knew the PIN, operated the handset or benefited from the transaction at the relevant time. A wallet statement is like a name written on a gate. It tells you who is associated with the property, but it does not prove who entered the house at midnight.
The second issue was the role of mule accounts. Some account holders knowingly allow their wallets to receive and move money. Others may be deceived by a false job, a request from a relative, a supposed business opportunity or a person claiming that their own account is temporarily blocked. FATF notes that some money mules are unaware that they are facilitating criminal activity. Investigators should therefore distinguish deliberate participation, negligence, deception and innocent receipt.
The third issue was transaction velocity. One wallet received UGX 18,000,000, retained it for nine minutes, transferred portions to four other wallets and then returned to its previous low level of activity. Another wallet received money from two unrelated corporate transactions and cashed out through agents situated several kilometres apart within a short period. These patterns raised questions, but they still required corroboration from provider records, agent records, device evidence and witness accounts.
The fourth issue was beneficial use. The investigation became stronger when it moved beyond registration details and asked who ultimately controlled or enjoyed the money. Investigators compared wallet flows with asset purchases, debt repayments, field movements, staff attendance, communications, device possession and relationships among the account holders. Attribution becomes persuasive when separate evidence streams converge on the same explanation.
The SIM swap changed the direction of the case.
The company’s approval process depended partly on a telephone number registered to the authorised manager. Records later indicated that the line had undergone a SIM replacement shortly before the disputed transfers.
A SIM swap occurs when a mobile number is transferred to another SIM, but legitimate replacements happen when a SIM is lost, damaged or upgraded. Fraudulent SIM swaps arise when someone improperly obtains control of another person’s number, often through impersonation, compromised personal information or weaknesses in verification. Once control is obtained, calls and messages intended for the legitimate subscriber may reach the replacement SIM.
The second insight is critical: the SIM swap did not, by itself, move the company’s money. Control of a number may help an offender receive service notifications or authentication messages, but access to a financial platform may still require a PIN, password, device registration, approval credential or other control. A serious investigation reconstructs the whole authentication chain instead of presenting the SIM swap as a magical explanation.
The third insight concerned preservation. The team requested the relevant SIM-replacement records, transaction records, authentication logs, account-access logs and available device or network identifiers through the appropriate legal and institutional channels. We also preserved the manager’s original handset, documented its condition, isolated it from avoidable alteration and created a forensic working copy where technically and legally appropriate. NIST guidance describes mobile-device forensics as a process involving preservation, acquisition, examination, analysis and reporting.
The fourth insight concerned alternative explanations. Defence counsel could reasonably ask whether the manager requested the replacement, provider records were authentic, system clocks were accurate, whether credentials had been shared, another employee had delegated authority, or the replacement was unrelated to the transfers. We therefore compared the replacement time with the loss of network service on the original handset, support communications, approval events, staff locations and subsequent wallet movements.
In our practical training at the Institute of Forensics & ICT Security, I usually ask the students to draw an authentication chain. Begin with the registered subscriber, move to the SIM, handset, PIN, password, approval code, enterprise account and transaction. At every stage ask, ‘What evidence proves control at this exact moment?’ You will see why a SIM swap is a lead, not a verdict.
The agents were witnesses before they were suspects
Several cash-outs occurred through six mobile-money agents. Management interpreted the concentration as proof of agent collusion. Again, we slowed the room down.
An agent facilitates deposits and withdrawals within the provider’s network. A questionable transaction processed through an agent does not automatically make that agent part of the underlying offence. The agent may have served a customer appearing to be legitimate. The correct questions concern identification, transaction procedures, unusual behaviour, relationships, record integrity and whether the agent departed from required controls.
The second insight came from pattern comparison. Investigators reviewed the agents’ normal transaction volumes, cash and float positions, frequency of dealings with the relevant wallets and the timing of the questioned cash-outs. One agent had served the same wallet repeatedly despite the holder’s stated residence being far from that location. Another agent processed withdrawals soon after receiving large float transfers. These facts were relevant, but each still required a reasonable operational explanation.
Another eye-opener came from physical evidence. Available CCTV, transaction messages, agent registers, neighbouring business observations and handset records were compared with the system timestamps. A transaction record might establish that cash was withdrawn at a particular agent account, but it may not identify the person who physically collected the cash. The bridge between the digital record and the human being must be built carefully.
Then the cash-out does not always mean the trail ends. Cash may lose its electronic identity once handed over, but the events surrounding withdrawal remain capable of analysis. Investigators can examine repeated agent use, withdrawal clustering, travel feasibility, communication before and after cash-out, subsequent deposits, purchases and the relationships linking wallets to the recipient.
We built a case that could survive cross-examination
The most dangerous evidence in a digital investigation is often the screenshot. It looks convincing, travels easily and may contain the exact words management wants to see, yet a screenshot can be cropped, edited, detached from its source or stripped of context. We treated screenshots as leads and illustrations, not as substitutes for source records. The team sought original provider records, complete exports, system-generated logs, transaction identifiers and supporting certification or testimony where required. Uganda’s Electronic Transactions Act provides that electronic records should not be denied admissibility merely because they are electronic, while their evidential weight depends on matters such as reliability, integrity, origin and how the information was maintained.
Each device and dataset was recorded, labelled and controlled. We documented who collected it, when it was collected, how it was acquired, who handled it and where it was stored. Hash values were used where applicable to help demonstrate that forensic copies had not changed. UNODC describes chain of custody as the process for documenting the collection, possession and handling of evidence throughout the life of the case.
Telecom systems, enterprise platforms, handsets, CCTV systems and accounting software may not display time in the same format or may contain inaccurate clocks. We recorded the source time zone, server time, device time and any observed variance before constructing the master timeline. A five-minute clock difference can create a false sequence and give defence counsel a genuine opening.
The report did not say the registered wallet holder stole the money, it said the evidence is consistent with the wallet receiving UGX 18,000,000 from the company environment at the stated time. Attribution was expressed separately and supported through device possession, communications, access logs, location evidence and demonstrated benefit. Good forensic writing separates fact, inference and opinion.
The defence questions improved the investigation.
We asked our team to think like defence counsel before interviewing the persons of interest. Could the account have been operated by another person? Were the passwords shared because management tolerated weak practices? Did the provider produce a complete record or merely a spreadsheet? Was the employee present at the location alleged? Could a reversal, integration error or duplicate posting explain the loss? Were investigators selecting only incriminating messages while ignoring conversations supporting innocence? These were not obstacles, they were quality-control questions.
Great investigators know that access logs do not always equal authorship. A username may show which account acted, while an IP address may show the connection used, but neither automatically identifies the person sitting behind the device. In a 2025 Ugandan Supreme Court decision involving misuse of a mobile-money system, electronic records, usernames, IP information and login trails were considered in addressing attribution. The lesson is not that one log proves identity, but that attribution becomes stronger through corroborated system evidence.
We did not begin with accusations. Each person was asked to explain ordinary duties, approval routines, device possession, credential handling and movements during the relevant period before being shown contradictions. An innocent person may clarify an anomaly, a mistaken witness may correct a timeline and a dishonest explanation may create new evidence, but the investigator should never manufacture inconsistency through misleading questions.
Take keen interest in privacy and proportionality. Wallet records, call records, device contents and identity information contain personal data. Investigators should define a lawful and specific purpose, limit collection to relevant material, protect the data and use appropriate authority when requesting information from providers. Uganda’s Data Protection and Privacy Act regulates the collection and processing of personal data while recognising circumstances connected to lawful investigation, prosecution and enforcement.
At the Institute of Forensics, we train students to be careful. Write the strongest innocent explanation for every red flag in your case, then identify the independent evidence that would confirm or disprove it, and if your conclusion survives that test, it has earned the right to appear in the report.
How the case closed
The case was not cracked by one dramatic confession, it closed because small records began agreeing with each other.
The duplicated accounting references linked the financial loss to the manual reconciliation process. The approval records aligned with the period during which the authorised line had been replaced. Several recipient wallets shared transaction relationships and device or contact links. The cash-out times corresponded with communications and movements involving particular persons of interest. Some wallet holders gave explanations supported by evidence and were removed from suspicion. Others could not explain repeated receipt, onward transfer and benefit.
The investigation found no basis to accuse every agent who processed the withdrawals. Two agents had followed ordinary procedures and cooperated fully, one agent’s relationship required further regulatory and law-enforcement review because the transaction history, customer familiarity and supporting records were inconsistent with the explanation provided. That conclusion was deliberately limited. An investigator should say no more than the evidence allows.
The confirmed gross diversion was UGX 214,680,000. UGX 36,900,000 was frozen or recovered during the response process, leaving a net financial exposure of UGX 177,780,000, excluding investigative costs, business disruption and reputational damage.
The deeper failure was not the telephone, the company had allowed reconciliation, exception handling and supporting-record preparation to sit too close together, shared credentials had become culturally acceptable, SIM-replacement alerts were not connected to payment-risk controls, evening transactions were reviewed the following morning, customer confirmations were manual, Agent and wallet concentration was not monitored and Management had built controls around individual transactions while ignoring the behaviour of the network.
The future-ready response is not to distrust mobile money, but to treat it with the seriousness already applied to bank accounts. Organisations should monitor transaction velocity, recently changed SIMs, unusual device changes, new beneficiaries, repeated agent concentration, rapid cash-outs, dormant-wallet activation and transactions occurring outside normal business patterns. GSMA has highlighted tools such as number-verification and SIM-swap interfaces as part of the emerging fraud-prevention ecosystem, but technology must still operate within lawful, privacy-conscious and properly governed processes.
Here is the lesson I leave with investigators, auditors, directors and executives:
Mobile money is not informal money.
It is structured money moving through a digital village. Every wallet is a house, every transaction is a footpath, every agent is a possible observation point, every SIM change is a change of keys and every cash-out is a gate through which value leaves the electronic environment.
But seeing footprints is not the same as identifying the traveller.
The top investigator does not rush to name the person, he preserves the path, tests who could have walked it, eliminates innocent explanations and then shows the court, step by careful step, why the remaining explanation is the most defensible one.
Copyright Institute of Forensics & ICT Security, 2026. All rights reserved.


