Skip to content

Author

Kwaku Boamah

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

BALANCING ACCESS AND PRIVACY: REGULATORY GAPS, AUTHENTICATION, AND DATA SECURITY IN DIGITAL PRESERVATION OF INSTITUTIONAL RECORDS

Digital preservation is often framed as a technical archival problem, yet the governance choices surrounding it carry direct consequences for information security and data privacy. This study draws on qualitative case-study data from a Ghanaian educational institution to examine how the absence of enforced legal and regulatory frameworks for digitized records shapes user authentication practices, data security, and privacy outcomes in a live school management information system. Twenty-five stakeholders, including parents, teachers, facilitators, and administrators, were interviewed about their experiences with user access, authentication, and data handling. Findings show that authentication mechanisms, including unique login credentials, QR-code verification, and digital signatures, were valued by users primarily as privacy safeguards, and that stakeholders explicitly requested encryption and non-disclosure of data to third parties, despite the absence of a specific institutional data-protection policy referencing Ghana’s regulatory framework. The findings are discussed in relation to Ghana’s Data Protection Act, 2012, and the Public Records and Archives Administration Act, 1997, alongside the growing role of artificial-intelligence-assisted compliance monitoring and cloud security posture management. The study concludes that in resource-constrained institutional settings, privacy protection is being improvised by end users and administrators in the absence of formal governance, a pattern with implications for institutions well beyond the case examined here.

A. Asante, Kwaku Boamah, Ranjith Kumar Patil · 0 citations
Review Open access Aug 2026

Anatomy of a vishing call: A theoretically grounded review of mobile money fraud and AI voice cloning in Ghana

Mobile money has become the financial backbone of Ghana, with transaction values reaching several trillion cedis annually and active accounts numbering in the tens of millions. This scale has attracted a parallel surge in fraud, much of it perpetrated through voice phishing (vishing): unsolicited telephone calls in which fraudsters impersonate telecommunications providers to manipulate subscribers into surrendering credentials or authorizing transfers. This paper reviews the state of vishing-enabled mobile money fraud in Ghana, synthesizing regulator data, industry reporting, documented case typologies, and the academic literature on social engineering and mobile money security. It organizes the dominant attack scripts - security-verification, loyalty-reward, misdirected-payment, and SIM-swap pretexts - into a common four-stage pattern of impersonation, pretext, manipulation, and extraction, and interprets this pattern through routine activity theory and persuasion theory. The paper then examines an escalating threat: the maturation of AI voice cloning, which can now replicate a target voice from seconds of audio, and which controlled studies show human listeners cannot reliably detect. Because Ghanaian vishing already succeeds using ordinary human voices, the paper argues that voice cloning constitutes a force multiplier that will erode voice familiarity, the last perceptual defense available to targets, and expand the pretext space from institutional to personal impersonation. The review contributes a consolidated threat taxonomy, a theoretically grounded attack model, and a research and policy agenda for providers, regulators, and awareness programs in Ghana and comparable mobile-money-dependent economies.

A. Asante, Kwaku Boamah, Ranjith Kumar Patil · 0 citations