08/06/2026
The Most Dangerous Security Vulnerability Isn’t Software. It’s You.
Have you ever stopped to think about what happens in your mind when someone holds a door open for you at a shopping mall or office building?
Probably not. And that’s precisely the point.
It feels polite. It feels normal. Your brain processes it as a social courtesy and moves on — no alarm, no hesitation, no second thought. That instinct is deeply human, and for the most part it serves you well. But it is also the exact mechanism that makes social engineering one of the most effective and consistently underestimated forms of attack in the world today.
Most attackers aren’t trying to break through your firewall. They’re not hunting for unpatched software or exploiting obscure system vulnerabilities. They’re targeting something far more accessible and far harder to patch — your natural tendency to be helpful, trusting, and kind. And that tendency, in the wrong moment, can be more dangerous than any virus or malware ever written. Because no antivirus in existence has found a way to protect against human politeness.
This is exactly how MoMo fraud works in practice. The attack doesn’t begin with a technical breach. It begins with a message — well-crafted, familiar-looking, and designed to feel completely legitimate. Same logo as your bank or telecoms provider. Same tone. Same formatting. It lands in your inbox and tells you your account has been compromised. It tells you the situation is urgent. It tells you to click a link immediately and reset your password before something worse happens.
So you click. You enter your details. And in that single moment — driven entirely by a reasonable, understandable human response to a perceived threat — you have handed your credentials directly to an attacker.
No hacking required. No sophisticated code. Just a message that knew exactly which buttons to press.
In cybersecurity, this specific technique is called smishing — a portmanteau of SMS and phishing. It is one strand of the broader discipline of social engineering: the art of manipulating people rather than systems. Where phishing arrives by email, smishing arrives by text — and it has proven particularly effective in environments where mobile money is deeply embedded in daily financial life, as it is across much of Ghana and West Africa. The familiarity of the MoMo interface, the trust people place in it, and the urgency that fraud messages are designed to manufacture combine into a near-perfect psychological trap.
The defence is not complicated, but it requires a habit of mind that runs slightly against the grain of how most people naturally operate. Legitimate banks and telecoms providers do not send unsolicited messages asking you to click links and enter credentials. They do not manufacture urgency. When in doubt — and especially when a message is generating a feeling of urgency — stop, breathe, and contact your provider directly through a number you already know and trust. Not the number in the message. Not the link in the message.
The door-holder at the mall is almost certainly just being polite. But the text message that looks exactly like your bank? That deserves a second thought.