“Bankak” and the Password… Who Is Responsible?
Azmi Abdel Razek
Over the past few days, I have come across various accounts of financial fraud and hacking incidents targeting the phones of some individuals in connection with electronic financial transactions. Fortunately, some of these attempts were thwarted at the last moment. I do not know anyone in my country who does not have a financial application on their phone—particularly “Bankak.” It has become almost as though the entire Sudanese family—from Khartoum to Texas, and from Cairo to Tokyo—is part of this cross-border financial network.
It is perfectly natural for people to be alarmed by stories of fraud—call it hacking if you wish. But before we panic or worry, we should understand the root of the problem, its causes, and where the danger actually comes from.
One lesson from this ordeal is the importance of taking great care to protect our money and of voluntarily embracing the digital world. People before us also lived through their own eras of change. Necessarily, there has always been a “thief,” ever since humans first knew money and barter. As the poet Al-Mutanabbi put it: “Whenever time grows a spear, man mounts a blade upon it.”
Today, the world goes to sleep and wakes up inside this small glass box. Through it, we pay, buy, sell, transfer money, and conduct our transactions within minutes—after these same transactions once required long queues, stamps, and running between offices.
But every great revolution has another side. The thief in the digital age has not disappeared or repented; he has simply changed his tools. He discarded his old robe and donned the “cloak of technology.” He mounted a blade upon the spear. Once, he watched your pocket so he could steal your wallet; now he watches your phone. He once searched for the key to your door; now he hunts for your password.
This is where we need to understand the root of the story. Most digital systems today rely on the phone number as a key element in establishing identity and sending one-time passwords (OTPs). What often happens is not actually a “hack” of Bank of Khartoum or the “Bankak” application itself as a security system. The truth we need to understand is that it is often a malicious practice known globally as SIM swapping, or the fraudulent takeover of a mobile phone SIM card.
How Does the Scheme Work?
The fraudster—through forged documents, a suspicious power of attorney, or by exploiting a vulnerability at a telecommunications service outlet—manages to obtain a replacement SIM card for your phone number.
At that moment, your phone loses service, while the thief’s SIM card begins receiving all verification messages for your bank accounts, emails, and other services.
So the door was not broken down from the bank’s side. Focus carefully: the key was stolen from the telecommunications company’s gate.
When someone steals your house key and uses it to enter, we do not blame the building engineer or the lock. We simply ask: How did the key end up in the stranger’s hands?
In many cases, financial transactions leave traces. They have trails and timestamps that security authorities can follow to identify and apprehend the perpetrator. But prevention is always better than waiting for the damage to occur.
The real battle to protect people’s money begins with strengthening our weakest links:
SIM cards and replacement SIMs: They must be subject to extremely strict security controls and should only be issued to the actual owner of the number in person, using live biometric verification, while tightening controls on forged powers of attorney.
Banks and financial institutions: They must expand the use of multi-factor authentication (MFA) rather than relying solely on phone numbers. Biometric authentication and systems capable of detecting unusual financial behavior should also be adopted.
Instead of sensational headlines such as “Bankak Hacked,” each incident should first be properly investigated: Were the customer’s credentials stolen through a fraudulent link? Was their SIM card taken over? Or did they fall victim to social engineering and hand over their verification codes themselves?
Our responsibility today is not to fear technology or demonize it, but to protect it. The way forward is an integrated approach: awareness among citizens, advanced security measures at banks, strict controls at telecommunications companies, and constant vigilance by the relevant authorities.
Only then will technology cease to be a door through which the thief enters and instead become—this is the whole point—the trap that leads the thief into the hands of the law.
Many digital systems around the world rely, to varying degrees, on mobile phones as part of the process of identifying users, sending verification codes and alerts, or restoring access. This is common in banking services, e-commerce, government platforms, and other digital services, while the more advanced systems are increasingly moving toward additional layers of verification.
Banks must continuously keep pace with developments in security systems. Telecommunications companies must make taking over another person’s phone number extremely difficult. Authorities must tighten regulations governing the issuance of replacement SIM cards. The media must promote information-security awareness. And citizens must never hand over their personal information or verification codes to anyone.
Digitalization is here to stay.
In Sudan specifically, when institutions were disrupted and families became scattered across different states and countries of the diaspora, Bankak became a lifeline. It stood by people in times of hardship before prosperity. Through it, fathers sent money to support their families; patients relied on it to purchase medicine; and merchants continued buying and selling. Financial activity continued at a time when its complete shutdown would have multiplied people’s suffering.
It is only fair to say that those responsible for this system carried a major national responsibility at a time when the country and its people were in desperate need of uninterrupted financial services—a role comparable in importance to the experience of Nafath in Saudi Arabia.
And if thieves have entered the world of technology—which is only to be expected—then we must stay one step ahead of them: awareness among citizens, protection at the banks, strict controls at telecommunications companies, and vigilance by the relevant authorities.
Shortlink: https://sudanhorizon.com/?p=16825