POS agents face fake alerts, card substitution, stolen credentials, social engineering, cash-count disputes and unauthorised terminal access. This guide turns those risks into a practical opening, transaction and closing routine. It explains how to confirm approval on the terminal or provider record, shield customer PIN entry, keep cards in view, restrict staff access, reconcile settlement and preserve terminal IDs and
Pause the transaction, keep the card and customer data private, secure the terminal and check the provider’s own record before accepting a story or screenshot.
When fraud is suspected, stop the loss first
| Need | Code or route | What it does |
|---|---|---|
| Fake transfer alert | Receiving account history |
Confirm credit in your own bank or provider record |
| Suspicious card transaction | Terminal response + provider support |
Do not force approval or retain the card unlawfully |
| Terminal missing or swapped | Disable through provider |
Record serial, terminal ID, time and staff access |
| Staff or settlement mismatch | Daily reconciliation |
Compare terminal totals, cash, float and provider settlement |
| Threat or physical danger | Move to safety / contact authorities |
Money recovery is secondary to personal safety |
Do this in order
- Stop the current transaction and do not release cash or goods while status is unclear.
- Check the provider dashboard, receiving account or terminal record from a trusted device.
- Preserve receipt, reference, terminal ID, time, amount, CCTV or chat evidence without exposing PIN or full card data.
- Disable or isolate a missing, altered or unauthorised terminal through the provider.
- Report through the provider and request a complaint or incident reference.
- For theft, threats or suspected criminal activity, contact appropriate law enforcement and preserve the report details.
Expected result
A controlled response should prevent more transactions, preserve reliable evidence and place the incident with the provider or authority that can investigate. It should not depend on confronting a suspect or paying an unofficial recovery agent.
When that route fails
Close the service point temporarily, move staff to safety and use another verified terminal only after accounts and access are reviewed.
Quick answer
The strongest POS fraud controls are simple: confirm money in your own record, never expose a customer’s PIN, reconcile every shift, restrict staff access, record each terminal and report suspicious activity quickly through the provider. A screenshot or SMS is not final proof of payment.
Fake alerts work because they create pressure
A fraudster may show a successful screen, send a spoofed SMS or insist that network delay explains the missing credit. The agent should check the receiving account or provider history independently. Do not let the customer’s phone become the only evidence. Match amount, date, reference and status before releasing cash or goods.
Use a calm written policy: pending is not paid, and screenshots do not replace the receiving account. This protects honest customers too because staff follow one rule instead of accusing people based on appearance.
Card and PIN handling can create liability
Let the customer keep the card in view and enter the PIN privately. Do not photograph the card, write down the PAN, ask the customer to say a PIN aloud or keep a card because a terminal displays an error. Follow the provider’s official response for retained or suspicious cards.
Repeated PIN attempts can block a card or create customer distress. Read the response code and stop when the terminal says decline, invalid PIN or issuer unavailable. A decline is not permission to force the transaction through another path without customer consent.
Protect the terminal as an accountable device
Record terminal ID, serial number, provider, assigned location and authorised staff. Use device locks and provider access controls. Inspect the casing, SIM area, charging equipment and software prompts at the start of a shift. A swapped or altered device should be isolated and reported, not tested with a live customer’s card.
Do not install software, accept remote-control access or read an OTP to someone claiming to update the machine. Providers should use their documented maintenance route. Confirm a field officer’s identity through the provider before handing over a terminal.
Staff fraud is found through separation and reconciliation
Give each staff member an account or shift identifier where the system supports it. Separate the person who approves refunds from the person who handled the original transaction. Count cash and electronic float at shift changes, then match transaction totals and settlement.
Investigate differences with records, not public accusations. Save the relevant log, receipt, CCTV period and access history. Change credentials and disable staff access when there is a genuine risk, while following employment law and provider procedures.
False reversal stories and duplicate cash claims
A customer may return with a debit alert and say the first withdrawal failed. Check the terminal status and provider settlement for the exact reference. Do not pay cash merely because the alert looks real, and do not dismiss a genuine debit without giving the complaint route.
When the transaction is pending or reversed, explain the status shown, provide the available record and direct the customer to the issuing bank or appropriate provider. Avoid making a personal guarantee about the timing of a reversal.
Report with facts and protect personal data
An incident report should contain the date, time, amount, terminal ID, provider, transaction reference, response, staff present and a clear description. Redact card numbers, account numbers and identity documents before sharing beyond the authorised channel. Never include a PIN, OTP or CVV.
The CBN advises consumers to report suspected compromise promptly to their financial institution and relevant authorities. The Nigeria Electronic Fraud Forum provides industry context, while a bank or provider complaint remains the first operational route for a specific transaction.
Three terminal-risk scenarios
The following examples explain three terminal-risk scenarios and show how the guidance applies in different situations.
1. Customer shows a transfer screenshot
The agent checks the receiving account. No credit appears, so the agent politely waits and does not release cash. The customer’s screenshot is saved only if needed and sensitive details are redacted.
2. A caller offers a remote terminal upgrade
Staff refuse remote access, record the number and contact the provider through the official dashboard. The terminal remains offline until its status is confirmed.
3. Shift total is lower than settlement records
The owner freezes nonessential staff access, preserves logs and compares references one by one instead of changing figures to make the book balance.
Official sources for this guide
The response advice follows official consumer-protection, payment and fraud-awareness resources.
A safe POS point can explain every transaction
Confirm payment in your own system, control the terminal, protect PIN entry, reconcile staff shifts and report with complete references. These habits reduce fraud and also make genuine customer disputes easier to solve.
Pair this guide with payment confirmation before releasing goods and the POS error guide.
Regulated complaint evidence
For a bank or payment-service dispute, retain settlement reports, terminal identifiers and complaint references. The CBN complaints process explains why the regulated institution must receive the complaint first and what evidence supports a later escalation.
Verification record
- Last fact-check
- July 31, 2026
- Method
- Official provider or regulator sources reviewed where available; live menus control account-specific actions.
- Reviewed by
- Nigeria USSD Codes Editorial Team
Primary official sources:
Article note
Last reviewed: July 31, 2026. This independent guide is informational and does not replace instructions from your bank, telecom provider, regulator, or service provider. Verify sensitive actions through an official channel before sending money or sharing information.