KODA
KODA Blog

How KODA Catches Fake Payment SMS

Fraudsters can forge a payment SMS or edit a screenshot — but they can't forge the operator's own record. See how KODA catches fake mobile money confirmations automatically.

reads

The most common way merchants get cheated on mobile money is a forged confirmation. If a seller trusts a message that says "you have received 5,000," then a fraudster's whole goal becomes producing something that looks like that — a copied SMS, an edited screenshot, or on some phones a planted app that injects a fake notification. It is convincing, it is fast, and it is exactly the attack KODA is built to stop.

The reason it works comes down to where KODA looks for the truth. It does not trust the message the customer shows you. It verifies against the operator's own confirmation on the merchant's side — the record the network itself produced, which the customer never sees and cannot control. A forged or edited message simply does not match that record, so it is held back instead of trusted.

That distinction is everything. A human glancing at a message cannot tell a perfect forgery from a genuine one — but KODA is not reading the message the fraudster crafted; it is checking against what the operator actually reported. A confirmation that was never really issued has nothing to match, so it is quarantined automatically and you are alerted, rather than releasing goods on a lie. The checks run quietly in the background: the merchant just sees clean payments verified and forged ones held back, with no extra effort at the till.

This forgery defence is one layer among several, and layers are the point. On top of it, KODA runs fraud scoring and velocity rules that catch suspicious patterns — the same code appearing across channels, a burst of attempts in seconds, amounts that do not match the claimed order — and screenshot forensics for customers who insist on sending images. Combine that with permanent replay locking, where every verified reference code is spent forever and can never be reused, and the total fraud surface collapses. How to Stop Mobile Money Screenshot Fraud in 2026 covers replay protection in detail.

A fair question is what KODA does with the rest of your messages. The answer is nothing: only payment confirmation SMS from known operators are parsed, and the platform is a verification layer that never moves, holds, or touches your money. It is not a bank or a wallet — it reads the operator's confirmation, checks it against the network's own record, and returns a verdict. Developers who want to see why a given message was accepted or quarantined can inspect the decision trace through the KODA API for developers platform, and operator parse health is visible on the KODA platform status & operator parse health page.

For a merchant, the practical result is peace of mind that does not depend on vigilance. You do not have to become a forensics expert or memorise what a real M-Pesa, Orange Money or Airtel Money message looks like. KODA enforces the check on every confirmation, day and night. If you want to see it protecting your own line, start free at Get started with KODA free — a forged SMS should break on your defences, not on your bottom line.

Frequently asked questions

Can someone send a fake payment SMS to trick verification?

They can try, but KODA verifies against the operator's own confirmation on the merchant's side — a record the fraudster can't see or control. A forged message doesn't match it and is quarantined automatically.

Does KODA store my other SMS?

No. Only payment confirmation SMS from known operators are read — see How KODA verifies mobile money payments.

Related reading

Verify your first payment free → · ← all articles