Anatomy of a vishing call: A theoretically grounded review of mobile money fraud and AI voice cloning in Ghana
Abstract
Mobile money has become the financial backbone of Ghana, with transaction values reaching several trillion cedis annually and active accounts numbering in the tens of millions. This scale has attracted a parallel surge in fraud, much of it perpetrated through voice phishing (vishing): unsolicited telephone calls in which fraudsters impersonate telecommunications providers to manipulate subscribers into surrendering credentials or authorizing transfers. This paper reviews the state of vishing-enabled mobile money fraud in Ghana, synthesizing regulator data, industry reporting, documented case typologies, and the academic literature on social engineering and mobile money security. It organizes the dominant attack scripts - security-verification, loyalty-reward, misdirected-payment, and SIM-swap pretexts - into a common four-stage pattern of impersonation, pretext, manipulation, and extraction, and interprets this pattern through routine activity theory and persuasion theory. The paper then examines an escalating threat: the maturation of AI voice cloning, which can now replicate a target voice from seconds of audio, and which controlled studies show human listeners cannot reliably detect. Because Ghanaian vishing already succeeds using ordinary human voices, the paper argues that voice cloning constitutes a force multiplier that will erode voice familiarity, the last perceptual defense available to targets, and expand the pretext space from institutional to personal impersonation. The review contributes a consolidated threat taxonomy, a theoretically grounded attack model, and a research and policy agenda for providers, regulators, and awareness programs in Ghana and comparable mobile-money-dependent economies.