Overview

Spike in social‑engineering and SIM‑swap attempts forced a wallet provider to redesign flows. The goal: reduce successful fraud while preserving a fast checkout.

Controls Implemented

  • Risk scoring per transaction (amount, device, IP, velocity) with step‑up auth for risky events.
  • Device binding + push‑based approval replacing SMS OTP for high‑risk actions.
  • Transaction limits by tier (KYC level); cooling‑off periods after profile changes.
  • Customer education banners and in‑app tips; rapid takedown flow for reported scams.

Outcomes

  • Fraud loss rate down 60% in 3 months; checkout success preserved on low‑risk paths.
  • Fewer support tickets; clearer incident runbooks.

Lessons (Unit 4 lens)

  • Defense‑in‑depth beats single controls; tune thresholds to market behavior.
  • Education matters—social engineering bypasses pure tech controls.

Chapters covered

  • Threat landscape (4.2)
  • Technology solutions (4.3)
  • Policies and governance (4.4)