Colombia’s mobile wallets changed who can move money digitally. Nequi and Daviplata let people open an account from a phone with an identity document in minutes, send money by phone number and pay merchants without a card. That speed is the point, and it is also what makes these products attractive to fraud that depends on having many accounts that look legitimate.
This post looks at the main abuse patterns around Colombian wallets, including account rental, mule networks and SIM-based takeover, and at the device signals that wallets and the merchants who accept them can use. It does not describe either wallet’s internal controls, which they do not publish in detail.
Why wallets attract this fraud
Simplified, low-amount deposit products are designed for financial inclusion: fewer documents, fast onboarding, instant transfers by phone number. For fraud, three properties matter:
- Accounts are tied to a real identity, so an account in someone’s name looks trustworthy to the receiving side.
- Transfers are instant, so stolen or scammed money moves through several accounts before anyone reacts.
- The phone is the identity, so whoever controls the SIM or the app session controls the money.
None of this is unique to Colombia. Brazil’s Pix, Mexico’s SPEI and peer-to-peer apps elsewhere face similar pressure. But the scale of wallet adoption in Colombia makes it a clear case.
Account rental
Account rental (often called alquiler de cuentas) is the pattern that defeats identity checks most cleanly. Recruiters, frequently on social media and messaging apps, offer a payment for “lending” a wallet account. The owner either hands over their credentials and one-time codes, or installs the operator’s access on a second device. From then on, the account receives and forwards money for the operator: proceeds of scams, fake online stores, unlicensed betting or extortion.
Identity verification passed when the account was opened, because the owner is a real person who opened it themselves. The fraud is in who is operating it now. That is why rental is a device problem more than an identity problem.
What changes when an account is rented:
- New device, same account. The operator logs in from their own phone or from an emulator.
- Many devices, one account, if access is shared within a group.
- One device, many accounts. An operator managing a dozen rented accounts often does it from one phone using a cloned-app tool, or from a bank of emulators on a computer.
- Behavior shifts. An account that used to pay for groceries suddenly receives many small transfers from strangers and forwards them within minutes.
Our post on money mule account detection covers the transaction side of this pattern; the rest of this post focuses on the device side.
SIM-based takeover
The second pattern is takeover through the phone number. If a criminal gets a duplicate SIM, they receive the one-time codes that recover or authorize the account. Social engineering does the rest: calls impersonating the wallet’s support line asking the victim to “confirm” a code, or messages with links to fake login pages.
The tell, again, is the device. A SIM swap moves the phone number but not the phone. When the account recovers on a device it has never been seen on, often minutes after a SIM change, that is a moment to slow down. Our guide to SIM swap account takeover goes through that flow in detail, and the account takeover page describes the signals.
Device signals that matter
A wallet app, or a merchant app that embeds a payment flow, can collect device evidence on every login, enrollment and high-value transfer. With Prynt’s mobile SDKs (iOS, Android, Flutter and React Native), the server-side event includes:
| Signal | Reason code | Why it matters here |
|---|---|---|
| Emulator | (mobile signal) | Operators run many accounts from emulators on a PC |
| Cloned app | CLONED_APP | App-cloning tools let one phone run several accounts |
| Rooted or jailbroken | ROOTED_OR_JAILBROKEN | Needed by many spoofing and automation tools |
| Instrumentation (Frida and similar) | INSTRUMENTATION | Used to bypass app checks and automate flows |
| Failed attestation | FAILED_ATTESTATION | The app or device is not what it claims |
| Account seen on many devices | DEVICE_SPREAD | Shared or rented access, or takeover |
| Many accounts on one device | MULTI_ACCOUNT, ACCOUNT_SHARING | An operator managing rented or mule accounts |
| VPN, proxy, datacenter IP | VPN, PROXY, DATACENTER | Hiding the operator’s location |
The account-level history is what ties it together. Link your customer id to each event with PUT /v1/events/{requestId} and { "linkedId": "<customer id>" }, and GET /v1/events/{requestId} returns accountsOnDevice: every account you have seen on that device. An operator’s phone holding nine customer accounts is not subtle.
For wallets
Practical places to put the check:
- Enrollment. Refuse or review a new account from a device that already holds several, or from an emulator or cloned app.
- New-device login. When a known account appears on a new device, require stronger verification before transfers, especially if a SIM change is recent.
- First outbound transfer after a device change. Hold or limit it for a short period. That is where rented and taken-over accounts pay out.
- Device spread. An account seen on many devices in a day is either shared or not under its owner’s control.
The fintech solutions page has more on where these checks fit in a regulated flow.
For merchants accepting wallet payments
Merchants see the other end: fake stores and scam storefronts receiving into rented accounts, and fraudulent buyers paying with taken-over wallets. A merchant cannot see wallet internals, but it can identify the device on its own checkout:
const ev = await prynt.getEvent(requestId); // @prynt/node, on your server
const risky = ev.decision === 'block'
|| (ev.accountsOnDevice?.count ?? 0) > 3
|| ev.smartSignals?.virtualMachine?.result;
if (risky) holdOrder(order, ev.risk?.reasons);
The same device behind many customer accounts on your store, or a checkout from a virtual machine, is a reason to hold the order before you ship.
Where to start
Start by measuring. Add identification to enrollment and login, link accounts, and look at how many accounts your busiest devices hold and how many accounts appear on many devices. That one report usually shows whether rental is a real problem for you, and it gives your risk team concrete devices to investigate rather than a score to argue about.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.