Impersonation fraud continues to be a major risk in an increasingly connected digital environment.
Scammers often pretend to be trusted individuals, employees, websites or social media accounts in an attempt to obtain sensitive information from unsuspecting customers.
What makes these scams particularly dangerous is that fraudsters may already have some basic information about their targets, making their approaches appear legitimate.
Understanding how these schemes work and knowing what information should never be shared can help customers protect themselves.
Here are five common forms of impersonation fraud to watch out for.
SIM Swap Fraud
SIM swap fraud occurs when fraudsters take over a customer’s existing mobile number by registering it on a new SIM card.
Once they gain control of the number, they may be able to intercept notifications and one-time passwords, access online banking profiles and transactions, or make changes to account security settings.
This form of identity theft can have serious consequences because a mobile number is often connected to several digital services and accounts.
Customers can reduce their exposure by ensuring their SIM card has an active SIM lock, using strong passwords and avoiding the unnecessary sharing of personal information on social media.
The less personal information available to fraudsters, the harder it can be for them to impersonate a customer.
Read More:Â Five Common Tricks Fraudsters Use to Defraud Customers
Impersonating Safaricom Staff
Another common tactic is for a scammer to pose as a Safaricom employee or customer care agent.
Such callers may contact customers from personal lines while presenting themselves as legitimate representatives.
Fraudsters may also appear convincing because they already know the customer’s name or other personal identifiers.
This information may have been collected from different sources or unknowingly provided by the customer during a conversation.
The fraudster may then request sensitive information, including an M-PESA PIN, under the pretext of resolving an issue or assisting with an account.
In some cases, the interaction may also involve attempts to compromise the customer’s mobile device.
The most important safeguard is to remember that Safaricom staff will never ask customers to share their M-PESA PIN, SIM, passcodes or passwords.
A request for such information should therefore be treated as a major warning sign.

Fake Safaricom-Branded Links and Websites
Fraudsters can also create fake links and websites designed to look like legitimate Safaricom platforms.
Their objective is often to obtain customers’ personal information or expose devices to bugs and malware.
These fraudulent platforms may mimic genuine Safaricom products or services, but there can be clues that something is wrong.
For example, suspicious links may contain misspellings, missing words or other differences from the authentic branding.
Beyond putting customers at risk, fake websites and links can also cause inconvenience and undermine trust in the legitimate brand.
Customers should be cautious when interacting with unfamiliar links and websites and should notify Safaricom about suspected imposters and suspicious Safaricom-branded links, websites or social media handles.

Fake Safaricom-Branded Pages
Impersonation can also take place through fake social media pages that use Safaricom’s branding, including lifted logos, to appear genuine.
Fraudsters may create pseudo accounts that mimic Safaricom’s social media presence and approach customers through these pages.
They may ask customers to send them direct messages, where they can then attempt to obtain personal information that may be used to defraud them.
The professional appearance of such pages can make them difficult to distinguish from legitimate platforms at first glance.
Customers should therefore be particularly careful before responding to requests for personal or account information.
Do not share personal details with anyone through such platforms. If a page appears suspicious or is impersonating Safaricom, it should be reported rather than engaged with.
Fake Social Media Handles
Fake social media handles are accounts created to imitate genuine Safaricom accounts and trick users into engaging with fraudsters.
These accounts may be used to request personal information or promote non-existent offers and promotions.
Because social media is often used by customers to seek information and interact with brands, an account that appears legitimate can easily attract attention.
Fraudsters may use familiar names, logos and branding to make an account appear authentic.
Customers should therefore avoid communicating through an assumed or suspicious platform, particularly when the account requests sensitive information or presents an unexpected promotion.
Notify Safaricom about impersonating social media pages and avoid communicating with anyone through the suspected platform.
Staying One Step Ahead of Impersonation Fraud
The common thread across these five scams is deception. Fraudsters rely on trust whether that trust comes from a familiar brand, a convincing website, a social media account or someone claiming to be an employee.
Customers can protect themselves by being cautious about unexpected requests for personal information and by treating sensitive credentials as private.
In particular, M-PESA PINs, passwords, passcodes and SIM-related information should not be shared with people claiming to provide assistance.
When something appears suspicious, the safest approach is to stop the interaction, avoid sharing information and notify Safaricom through the appropriate channels.
Recognising the signs of impersonation is an important first step in protecting personal information and digital accounts.

