The Cyber Security Authority (CSA) has advised the public to use its 292 hotline to verify suspicious online transactions before transferring funds, warning that money sent to fraudsters is often irretrievable once withdrawn. Mr. Alex Awere-Kyere, Senior Manager for Critical Information Infrastructure at the CSA, noted that although the Authority collaborates with the police and other security agencies to investigate fraud cases, recovery of funds cannot be guaranteed once they have been cashed out.
He made the appeal in Accra on Monday, August 10, 2026, during a media briefing on the protection of critical information infrastructure and the Cybersecurity Act, 2020 (Act 1038). The session formed part of the National Community Media Cyber Capacity Building Project (NCMCCBP), jointly implemented by the CSA, the Africa Centre for Digital Transformation (ACDT), and the Government of the Czech Republic. Launched in Accra on August 3, 2026, the initiative aims to strengthen the capacity of journalists and media practitioners in cybersecurity reporting.
Mr Awere-Kyere said the public should not wait until money had been lost before contacting the CSA, explaining that an early report could give the Authority and the police an opportunity to take action before a transaction was completed. He said once a victim transferred money to a fraudster and the money was withdrawn from a mobile money account, the prospects of recovering it became very slim.
“Once the money is withdrawn, it becomes very difficult to recover,” he said. Mr Awere-Kyere said the CSA could not guarantee that money lost through fraud would be recovered, even where a case had been investigated and prosecuted.
He explained that the Authority would make efforts to recover the money after a suspect had been convicted, but said preventing the loss in the first place was preferable to attempting to recover the funds afterwards.
He said reports made through the 292 hotline were assessed by CSA officials, who gathered information and evidence from callers before working with the Ghana Police Service and other security agencies to investigate the cases.
According to him, an early call could also allow the Authority to advise a potential victim and, where necessary, work with the police to intercept a suspected fraudster before money was transferred.
Mr Awere-Kyere also explained the provisions of sections 35 to 40 of Act 1038 relating to critical information infrastructure. He said the provisions empowered the Minister responsible for cybersecurity to designate systems as critical information infrastructure and to withdraw such designation where necessary.
The CSA, he said, was also required to register designated systems and conduct audits, while owners of such systems were required to report cybersecurity incidents within 24 hours of detecting them. Mr Awere-Kyere said unauthorised access to critical information infrastructure was an offence under Section 40 of the Act.
He said 13 sectors, including banking and finance, energy and health, had been designated as critical information infrastructure sectors because disruption to their operations could affect national security or the economy. Touching on emerging cyber threats, Mr Awere-Kyere mentioned advanced ransomware, attacks on operational technology and industrial control systems, large-scale data theft, distributed denial of service attacks involving infected personal devices and supply chain compromises.
He also identified artificial intelligence driven threats, including deepfakes, as emerging risks to the designated sectors. Mr Awere-Kyere cautioned journalists against publishing unverified claims made by cyber criminals or details of unresolved vulnerabilities in computer systems.
He said premature publication of such information could provide useful information to persons seeking to exploit the vulnerabilities. In response to questions from journalists, Mr Awere-Kyere said mobile money fraud involving stolen personal data was handled through the Joint Cybersecurity Committee established under Section 13 of Act 1038.
He stated that the Committee includes representatives from the Cyber Security Authority (CSA), the Bank of Ghana, the National Communications Authority, the Economic and Organized Crime Office (EOCO), the Ghana Army, and the Criminal Investigations Department (CID). Mr. Awere-Kyere emphasized that addressing the causes of mobile money fraud requires tackling how personal information is accessed by fraudsters.
He mentioned that the CSA should collaborate with institutions such as the Data Protection Commission and telecommunications operators, alongside the efforts of the Joint Cybersecurity Committee. This engagement is part of the National Cybersecurity Awareness and Media Capacity Building Programme (NCMCCBP), which is training over 100 journalists and media practitioners in Accra throughout August, before moving to Kumasi in September.
Source: Mohammed Ali

