Mobile money is critical financial infrastructure in Tanzania, but impersonation-based fraud can bypass technical safeguards by inducing users to authorise payments themselves. This study examined the techniques, patterns, and vulnerabilities facilitate impersonation-based fraud and the factors predicting user compliance with fraudulent instructions in Tanzania. A mixed-methods design combined a survey of 231 active mobile money users in Dar es Salaam and Kibaha, eight key informant interviews and a review of regulatory and industry documents. Impersonation attempts were pervasive, with 72.3% of users targeted and 86.2% of those targeted were repeatedly. Attackers requested PIN in only 0.6% of cases but inducing 98.8% to send money themselves. Among targeted users, 74.3% complied, and 97.6% of compliers lost money. Logistic regression identified trust in providers-appearing communications as the only significant unique predictor of compliance (OR = 2.50). Users strongly preferred transaction-context safeguards, with 93.1% wanting cancellation capability and 87.4% wanting more verification time. Impersonation-based mobile money fraud is primarily an authorised-payment problem rooted in trust exploitation. Mitigation should therefore strengthen safeguards at the point of payment authorisation