Overview
Spike in social‑engineering and SIM‑swap attempts forced a wallet provider to redesign flows. The goal: reduce successful fraud while preserving a fast checkout.
Controls Implemented
- Risk scoring per transaction (amount, device, IP, velocity) with step‑up auth for risky events.
- Device binding + push‑based approval replacing SMS OTP for high‑risk actions.
- Transaction limits by tier (KYC level); cooling‑off periods after profile changes.
- Customer education banners and in‑app tips; rapid takedown flow for reported scams.
Outcomes
- Fraud loss rate down 60% in 3 months; checkout success preserved on low‑risk paths.
- Fewer support tickets; clearer incident runbooks.
Lessons (Unit 4 lens)
- Defense‑in‑depth beats single controls; tune thresholds to market behavior.
- Education matters—social engineering bypasses pure tech controls.
Chapters covered
- Threat landscape (4.2)
- Technology solutions (4.3)
- Policies and governance (4.4)

