In late August 2025, several Standard Chartered customers in Bangladesh watched one-time passwords arrive on phones that had initiated nothing. Within seconds, Tk 50,000 had left each account, moved out through mobile financial service platforms including bKash and Nagad. Nobody broke a cipher. Nobody defeated a biometric sensor. The money simply walked out through a channel that was working exactly as designed.

That is the uncomfortable shape of mobile money fraud in Bangladesh. The Policy Research Institute has found that close to one in ten MFS users has already experienced fraud on their account. For most of them the losses are small and survivable. For a business owner running supplier payments through a personal wallet, for a politician whose number is public, or for a family office where three household staff know the handset PIN, the same techniques reach a very different number.

You are not being hacked — you are being called

The dominant fraud in this market is a phone call. A fraudster rings posing as a customer care representative from bKash, Nagad, Rocket or Upay. There is an account verification. There is a problem with a recent transaction. There is a promotion you have qualified for. The pretext varies and does not matter. The single objective is to get you to read out a PIN or an OTP.

The more sophisticated version does not guess who you are — it watches you. A scammer positions himself at an agent point, observes a cash-out, and notes the number and the amount. Minutes later the victim's phone rings. The caller knows the exact figure, knows the agent's location, and knows the transaction happened. He explains that the payment was accidentally processed twice and that a reversal code has just been sent. Please read it back.

Everything that makes that call convincing is information the fraudster obtained by standing near you for ninety seconds. The knowledge feels like proof of legitimacy, which is precisely why it works. Verified detail is not authority — it is just detail, and in a crowded agent point it is free.

Act on this: establish one rule in your household and your office, and make it absolute. Nobody calls you about your MFS account. If there is a genuine problem, you will call them — using the helpline number displayed inside the official app, never a number from your call log, an SMS, or a search result. Anyone who resists that, on any pretext, is a fraudster.

The four ways money actually leaves

It is worth being precise about the mechanisms, because the defences differ.

  • Credential disclosure. You are talked into reading out a PIN or OTP. The fraudster transacts as you. This is the overwhelming majority of cases.
  • Account takeover via PIN reset. The attacker does not need your PIN if he can reset it. Reset flows lean on your registered number, your NID details and your date of birth — all of which are more widely known than you think.
  • Agent-assisted fraud. A dishonest or careless agent processes a cash-out that was not authorised, or logs your NID against an account you never opened. The agent point is a human trust boundary, and it is the weakest one in the chain.
  • Standing access. A driver, a household employee, an office assistant or a relative knows the handset passcode and the wallet PIN because it was convenient. There is no attack here at all. There is only opportunity.

Notice that only one of these involves anything a security product would recognise as an intrusion. The rest are conversations, procedures and habits.

Act on this: write down, today, every person who currently knows your wallet PIN or could unlock your handset. If the list has more than one name on it, you do not have an account — you have a shared account, and you should treat every transaction on it accordingly.

Limits are a containment tool, not an inconvenience

Here is the single most useful thing in this article, and almost nobody uses it.

On 27 March 2025 the Payment Systems Department of Bangladesh Bank re-fixed MFS transaction limits upward. Daily cash-in from an agent point rose to Tk 50,000, up from Tk 30,000. Daily cash-out rose to Tk 30,000, up from Tk 25,000. Person-to-person send money doubled to Tk 50,000 a day. Monthly ceilings sit at Tk 3,00,000 for cash-in and Tk 2,00,000 for cash-out, and an MFS account may hold a maximum balance of Tk 5,00,000.

Read those numbers as an attacker would. They are not limits on you. They are the size of your worst possible day. Anyone who gets control of your wallet at 9am can move up to the daily ceiling before you have finished breakfast, and can keep doing it every day until you notice.

The defensive move is to stop treating the regulatory ceiling as your operating balance. A wallet is a transit account, not a store of value. Money that is sitting in a wallet because it is convenient is money exposed to a phone call. The discipline is boring and it works: sweep balances back to the bank, keep the wallet float at roughly what you actually spend in a week, and accept the ten seconds of friction when you need more.

For anyone with real exposure, split the function. Keep a low-value wallet on the number you hand out — the one printed on cards, used for merchant payments, known to staff. Keep any larger movement on a separate number that has never been published, is not linked to your public identity, and is not the number on your business cards.

The question is not whether your wallet can be compromised. It is how much can leave before you find out.

Act on this: decide your working float this week and sweep everything above it. Then check your actual balance against that float every Friday. Two minutes, once a week.

The settings worth changing this week

The app-level controls are genuinely useful, and most people have never opened them.

  • Enable biometric login. bKash supports Face ID and fingerprint login in place of repeated PIN entry. It requires a handset with Class 3 biometric security. The practical benefit is not convenience — it is that you stop typing your PIN in public, which removes the shoulder-surfing surface entirely.
  • Understand what revokes it. bKash automatically cancels biometric authentication when the app is installed and logged into on a new device, when the PIN is changed or reset, when the app is uninstalled, when the handset's own biometric records change, or after 365 days without use. That behaviour is a feature, not a bug. If your biometric login silently stops working and you did not change anything, treat it as a signal that someone logged in elsewhere.
  • Know the PIN reset path before you need it. bKash allows in-app reset via 'Forgot PIN?' on the login screen. Walk through where it lives now, calmly, so that on a bad day you are not searching for it while someone is emptying your account.
  • Cap what biometrics alone can authorise. Biometric authentication covers payments and mobile recharges up to Tk 1,000 without re-entering a PIN. That is a sensible small-value convenience. Know it exists, because it means an unlocked handset in someone else's hand is not harmless.
  • Lock the handset properly. A six-digit passcode, not four. Not a birth year, not a repeated digit. Auto-lock at thirty seconds. Every wallet control on this list is downstream of the phone lock screen.

Act on this: open the app now and turn on biometric login. It takes under a minute and eliminates the most common physical observation attack.

At the agent point

Cash-out is where the digital and physical worlds meet, and it is the least controlled moment in the whole system.

Shield the keypad — the same way you would at an ATM, and for the same reason. Do not let the agent type your PIN, ever, regardless of how busy the counter is or how helpful he is being. Check the confirmation SMS on your own handset before you leave the counter, not in the car afterwards. Vary the agent points you use if you withdraw significant sums regularly, and vary the timing, because a predictable routine is what makes surveillance worth the effort. And treat any call that arrives shortly after a cash-out as hostile by default.

For families and businesses, add one more control: no MFS transaction above an agreed threshold happens on the strength of a phone call or a WhatsApp message alone. Voice can be cloned and accounts can be compromised, so the confirmation must arrive through a different channel than the request. A short call back on a number you already have beats any amount of urgency in a message.

Act on this: set a taka threshold above which a second person must confirm out-of-band, tell everyone who transacts on your behalf what that number is, and make it a rule that no one can override with urgency.

The first ten minutes after something goes wrong

Speed is the only real advantage available to a victim, and confusion destroys it. Have the sequence ready.

  1. Lock the account immediately — change the PIN through the app if you still have access, or call the official helpline from inside the app if you do not.
  2. Move the remaining balance out to a bank account before doing anything else, including before you finish investigating.
  3. Record the transaction IDs, the exact times, the amounts and the receiving numbers. Screenshot the SMS confirmations. This is what any recovery attempt runs on.
  4. Report to the provider through official channels and file with the police. Report speed materially affects whether receiving accounts can be frozen before the money is cashed out.
  5. Check your other accounts — email, bank, any wallet on the same number. A compromised phone number is rarely used for one thing.

Recovery in these cases is genuinely difficult once funds have been cashed out through an agent, which is why the whole argument of this article sits upstream of the incident. The float you did not leave in the wallet is the loss you do not have to recover.

Act on this: put those five steps in a note on your phone tonight, alongside the official helpline number taken from inside the app. Ten minutes of preparation now is worth more than any amount of investigation later.