Most people assume insider fraud is a slow operation. Someone on the inside skimming a little, week after week, hoping auditors do not notice. A senior banker with direct knowledge of internal fraud investigations says that picture is almost entirely wrong.
“Taking the money small small will be detectable by audit,” the banker told Technext. “So they take it all at once and try to disappear.”
That single insight reframes Nigeria’s fraud problem in a way that data alone cannot.
The Nigeria Inter-Bank Settlement System (NIBSS) identifies insider abuse as the single greatest threat within the broader category of social engineering fraud, the dominant technique across the country’s banking and fintech sector.
Financial institutions recorded ₦25.85 billion in fraud losses in 2025, down from ₦52.26 billion in 2024. But the volume of incidents is falling while the damage each one causes is rising sharply, and the reason, according to both the data and people inside the system, is insider access.
The Financial Institutions Training Centre (FITC) confirms the scale.
In Q2 2024, staff involvement in fraud rose 23.4% quarter-on-quarter, with cases climbing from 47 to 58 and 49 employees terminated. By Q1 2025, staff-linked fraud produced losses of ₦3.3 billion, a 137% increase from the previous quarter, despite 33.8% fewer reported cases.
NIBSS Managing Director Premier Oiwoh, speaking at an industry event in Lagos in January 2026, was direct:
Investigations have consistently shown a high level of internal participation in fraud, and insider involvement, he said, poses the greatest threat to the banking sector.

Read also: The digital heist: Inside Africa’s $4B SIM swap and identity theft fraud crisis
3 cases that show how fraud works
The First Bank case is the most documented.
Tijani Muiz Adeyinka, a manager on the electronic products team at the bank’s Iganmu head office in Lagos, allegedly diverted ₦40 billion, approximately $29 million, before the scheme unravelled.
He processed customer reversal requests into merchant accounts he controlled. Because he was the final authorisation point on his team, no second approver was required. The fraud only surfaced when a customer complaint triggered an internal review.
First Bank reported the incident to the Nigerian Police Force on March 25, 2024, and obtained three court orders to freeze hundreds of linked accounts. Adeyinka remains at large and is wanted by INTERPOL.
This is exactly the access structure the banker described. The banker described a layered dynamic. Not every perpetrator has the system access required to move funds.

In some cases, the person who executes the fraud relies on a colleague with higher privileges, someone who either enables the transaction or simply does not ask questions. “If the person has high approval access,” the source said, “they can just leverage that.”
In January 2025, the EFCC arraigned three bank employees, Samuel Ihechukwu Asiegbu, Fabian Chizaram Onyeimachi, and Kingsley Kelechi Ejim, alongside four external accomplices, before Justice Daniel Osiagor at the Federal High Court in Ikoyi.
The group allegedly conspired to manipulate internal banking data at a regional lender, diverting ₦8.5 billion through altered transaction records. The charges included criminal conspiracy and obtaining by false pretences. This case fits the second model the banker described: a group scheme, where the person with access brings others in to move, receive, and obscure the funds.
A third pattern operates at the system level.
FITC’s Q2 2024 report documented a surge in branch-related fraud, a channel that requires physical insider access by definition.
Losses through bank branches spiked to nearly ₦8 billion in Q1 2025, and one fraud category recorded a 9,004% increase in Q2 2024, a figure that points to coordinated activity, not opportunism.
The banker pointed to another dimension here: IT staff who built the systems.
“Sometimes IT people may manipulate because they built it,” the source said. “They understand the gaps better than the people monitoring.”
Across all three patterns, what the banker identified as the first condition holds: negligence by ordinary users and staff who do not read instructions, do not follow protocols, and create the opening that others exploit. The fraud does not always begin with a criminal. Sometimes it begins with a shortcut.
Read also: The digital heist: Crypto scams, biometric fraud, and recovery solutions
What can account holders do?
Institutional controls are the primary line of defence, and they are failing often enough to matter. But there are steps account users can take to reduce their exposure, particularly to schemes that depend on customer negligence or accessible account information.
Ive Chike Meme, director at Environ, a financial technology intelligence firm, has warned that Nigerian banks remain dangerously under-protected and that insider collusion continues to drive fraud even as technology improves.
His practical guidance focuses on reducing the information available to bad actors. Users should never share account details, PINs, or OTP codes with anyone, including callers presenting themselves as bank staff. Legitimate employees do not need those details to assist you.

Oiwoh of NIBSS stressed in January 2026 that awareness remains critical and that many victims are still easily deceived. Monitoring account activity through transaction alerts and reporting unrecognised activity quickly gives institutions the best chance of acting before funds are moved beyond recovery.
Financial analyst Chukwudi Izuchukwu, quoted by ThisDay Live, put the institutional version plainly: if your system allows any single person to trigger a transaction without a second approval layer, that is your vulnerability.
Account holders can apply that same logic themselves. Setting daily transfer limits, enabling all available notifications, and keeping savings in a separate account from day-to-day spending limits the damage any single compromise can cause. The goal is not to stop fraud at the system level. It is to ensure that when something goes wrong, the blast radius stays small.
Read also: Sterling Bank, Remita and CAC data breaches: Why did the Nigerian institutions say nothing?