NEWS
Security Systems Missed Over ₦1bn In Fraud Across Three Cases, esentry Says
Security Systems Missed Over ₦1bn In Fraud Across Three Cases, esentry Says
-
esentry says three investigated fraud incidents escaped automated detection.
-
Audits, support tickets or settlement warnings exposed the incidents afterwards.
-
Trusted access and missing logs featured in the company’s findings.
-
The reported amount covers investigated cases, not national fraud losses.
September 16, () – Three fraud incidents involving more than ₦1 billion passed through financial systems without triggering automated security alerts while the attacks unfolded, according to cybersecurity company esentry.
Investigators examined incidents across Nigeria’s fintech, payment infrastructure and core banking sectors during the first half of 2026. The company says they surfaced through routine audits, customer support tickets or settlement warnings after the attacks had run their course.
In a summary publicised on September 15, esentry attributed the failures to abuse of trusted access and missing activity logs. Its account concerns selected investigations and does not establish the scale of fraud across Nigeria or West Africa.
Access Looked Legitimate as Money Moved

According to esentry, attackers operated through credentials, sessions or access that the affected systems already trusted.
“Attackers are increasingly exploiting trust rather than vulnerabilities,” the company’s chief business officer, Gbolabo Awelewa, said in the announcement.
A valid login can establish that someone possesses an accepted credential without proving that the person using it is the rightful owner. Similarly, permission to enter a system does not make every subsequent transaction legitimate.
Missing logs compound the problem by leaving investigators and monitoring tools without records needed to connect suspicious actions. esentry recommends retaining authentication source addresses, recording outbound activity and checking permissions at the application’s backend.
Fast Responses Cannot Cover Unseen Activity

Across its wider operations, esentry says it processed more than 3.5 million security alerts during H1 and recorded a median detection-to-escalation time of 11 minutes for confirmed threats. Its report overview also describes investigations into credential abuse and breaches involving trusted workflows.
Those operational figures cannot establish how effectively the affected institutions detected fraud. An escalation clock begins after detection, leaving incidents that generate no alert outside that measure.
The public summary does not provide enough detail to establish individual losses, recoveries or responsibility for each failure. Nor does it identify the affected institutions.
For financial firms, the cases raise a practical testing requirement. Monitoring needs to recognise suspicious behaviour after a successful login, including activity performed through accounts the system already accepts.
