
Nando's · 2022
Fraud-proofing UX: the 2FA solution
I led the design of two-factor authentication for Nando's to tackle account takeover fraud. The challenge became encouraging customers to enrol a second factor. Shipped to 300k+ customers across all platforms.
- Role
- Lead product designer
- Duration
- 6 months
- Client
- Nando's
Case study still in construction.

Context
Nando's is a South African multinational chain of fast casual dining restaurants, famous for its Portuguese-African style peri-peri flavoured chicken. Nando's now offers a platform for customers to order and earn rewards.
Problem
As of March 2022, Nando's had seen a sharp increase in online ordering refunds compared with previous months, attributed mainly to fraudulent behaviour around delivery refunds. Two refund types both triggered full refunds: orders marked delivered but not received, and orders claimed to be spilt or damaged in transit.
Scale of fraud: in January 2022, Nando's was refunding around 100 orders per day at a cost of roughly £3,000. At its peak towards the end of March, before action was taken, that had grown to around 365 orders per day costing £16k per day. Measures at the end of March stabilised this at around 300 orders and £10.5k per day. Account takeover fraud could also carry a fine of up to £17m or 4% of global turnover.
The growth of digital channels expanded the domain for online fraud. Malicious actors had more opportunities to commit fraud or take over accounts, while customers expected an easier digital experience with fast authentication and seamless web and mobile interactivity. Maintaining brand love and trust meant striking a balance between seamless multichannel experiences and strong security standards.

Hypothesis
Customers prefer to log in with an authentication method that is familiar, and do not believe high levels of security to be necessary.
Success metrics
- Reducing ATO fraud
- Reduce the amount of account takeover fraud and protect customer security and data.
- Increase 2FA enrolment
- Encourage customers to enrol a second factor, for both SMS and email customers.
Solution
Introducing 2FA tackled the fraud issue and enabled CRM to collect cleaner customer data — reducing account takeover and improving security. Alongside it we introduced ways to encourage second-factor enrolment, from email campaigns to small nudges in the app.

Challenges and considerations
- New customers
- All new accounts created after launch would be asked to enrol in SMS 2FA (mandatory).
- Existing accounts
- All accounts registered before the SMS release would have a verified email.
- Auth API
- We would be able to identify the authentication status of customers at an individual level.
- CRM data
- Verified contact details meant cleaner CRM data and reliable order confirmations and updates.
- Customer expectations
- "It's not a bank, why do I need 2FA?" Customers did not want to verify more than one MFA method in one hit.
- Online ordering
- All customers need to enter a phone number before placing an online order, used for delivery purposes.


Ideation
I ideated with the team on how we might encourage customers to verify a second 2FA method, mapping out all the possible outcomes.

Significance
Verifying customer data matters, both so we hold quality CRM data and so customers reliably receive order confirmations and updates.