N1bn Fraud Slipped Past Security Systems in West Africa, Esentry Report Finds
By Aboki Forex —
More than N1 billion in fraudulent transactions bypassed conventional security tools across West Africa between January and June 2026, cybersecurity firm Esentry has said. The firm's new threat landscape report found that criminals exploited legitimate credentials and trusted digital environments rather than software flaws.
Three separate fraud incidents were only discovered after routine audits, customer complaints and settlement warnings. No security system flagged them. Esentry said attackers used legitimate login credentials, active user sessions and familiar digital environments, making their activity look normal to automated detection tools.
Nigeria records 4,700 weekly attacks
The report carries particular weight for Nigeria, where banks, fintech companies and payment providers have expanded digital services, including instant-payment channels, cloud infrastructure and application programming interfaces. During the six months, Nigerian organisations faced an average of more than 4,700 cyberattacks every week. About 281,500 Nigerian accounts were compromised in the first quarter of 2026 alone.
Esentry said its security teams processed over 3.5 million alerts across the period. Confirmed threats took a median of 11 minutes from detection to escalation. Its offensive security team carried out 175 security engagements in H1 2026, covering testing, social engineering exercises and cloud security assessments. All 175 engagements achieved unauthorised access without needing zero-day vulnerabilities, pointing to widespread weaknesses in access controls and authentication systems.
Trust, not bugs, is the new target
Esentry chief business officer Gbolabo Awelewa said cybercriminals were shifting away from exploiting software vulnerabilities and were instead manipulating trust within systems. He said attackers were deploying artificial intelligence-enabled workflows and operating through recognised platforms to avoid raising alarms.
The firm recommended that organisations move beyond relying on conventional alert systems and vulnerability scanning.
E-payment fraud losses ease but pressure remains
Despite some progress in reducing fraud losses, Nigeria's electronic payment sector remains under pressure. The Nigeria Inter-Bank Settlement System reported that fraud losses from electronic payments dropped 51% to N25.85 billion in 2025, down from N52.26 billion in 2024. However, the continued expansion of digital financial services means more entry points for potential exploitation.
Ghana also featured in the report. More than 3,500 confirmed cybersecurity incidents were recorded in Ghana in the first quarter of 2026. Online investment fraud in the country also rose during the same period.
Earlier, Ecobank Nigeria rolled out new mobile banking security rules that cap transactions at N20,000 for customers using the app on a new or first-time device. The bank cited alignment with Central Bank of Nigeria Instant Payments Guidelines. The policy applies to anyone registering the Ecobank Mobile App for the first time or logging in from a device that has not previously been linked to their account. During the first 24 hours following their initial transaction on such a device, those customers cannot transfer or pay more than N20,000 per transaction.
What it means for the naira and digital finance
For Nigerian banks, fintechs and merchants, the report points to a costly gap: fraudsters are getting past checks by looking like genuine customers. That raises the risk of chargebacks, customer losses and reputational damage as instant payments and digital lending grow. Stronger authentication, better monitoring of trusted sessions and faster escalation of confirmed threats will matter for protecting the naira flows moving through Nigeria's payment system.