How a failed FCMB access attempt highlights insider threats in banks

Avatar
How a failed FCMB access attempt spotlights insider threats in banks

An alleged insider attempt to sell bank-access credentials has drawn attention to one of the financial industry’s hardest cybersecurity risks: stopping people with knowledge of internal systems before they can cause harm. The case involving First City Monument Bank (FCMB) has been described in some reports as a successful “$25,000 server hack.” Available information suggests a different sequence of events.

The allegation concerns an attempted unauthorised entry using legitimate credentials. The activity was detected and stopped before the attacker accessed the bank’s server or database. No customer funds were lost, and there is no evidence that customer data was accessed or compromised.

The $25,000 cited in reports was an alleged payment offered in exchange for access credentials. It was not money taken from FCMB or its customers. A server administrator and a former employee have been charged before the Federal High Court in Lagos in connection with the matter. The allegations have not been proven, and the defendants are entitled to the presumption of innocence.

Beyond the criminal proceedings, the case illustrates how insider threats differ from conventional cyberattacks. Banks must defend their systems not only against external hackers but also against employees, contractors and former workers who may understand internal processes or possess legitimate credentials. That makes early detection critical.

FCMB CEO and MD, Yemisi Edun
FCMB CEO and MD, Yemisi Edun

Read also: What are banks for? FCMB made ₦76B in Q1 2026 and gave less loans than ever

An attacker trying to break through an external security barrier may be easier to identify than someone attempting to enter with valid or recently compromised credentials. Security systems must therefore assess both the user’s identity and whether the person’s activity matches their assigned role.

This approach relies on layers of protection. Limit access to the information and systems each job requires. Sensitive activities may require additional approval or authentication. Duties should be divided so that no single person can complete a high-risk process without oversight. Continuous monitoring is also needed to identify unusual behaviour, including attempts to enter restricted systems, access outside normal responsibilities or activity at unexpected times.

The FCMB incident did not progress to a completed breach. The bank detected the alleged compromise, contained the attempt and referred the suspects to the Economic and Financial Crimes Commission for investigation and prosecution. That sequence matters because an attempted attack does not necessarily mean a security system failed.

Financial institutions are continually targeted. Cyber resilience is measured partly by how quickly an institution detects suspicious activity and whether it can stop the threat before money or information is lost.

The case also raises a wider question about how cybercrime is reported. Terms such as “hack,” “breach” and “fraud” are sometimes used interchangeably, even though they describe different events. An attempted intrusion means someone tried to gain access. A breach means the person succeeded in entering a protected system or obtaining information. Financial loss requires evidence that money was taken. These distinctions affect how customers, regulators and investors assess the severity of an incident.

In this case, the available facts indicate an alleged attempt to trade credentials and obtain unauthorised access. They do not indicate that FCMB’s server was successfully hacked, that $25,000 was stolen or that customer funds and data were compromised. Individual misconduct must also be distinguished from institutional conduct. An employee’s alleged attempt to misuse access may expose an organisation to risk, but it does not by itself show that the organisation authorised the act or lacked effective safeguards.

The institutional test is what happens next: whether monitoring systems identify the activity, whether access is blocked, whether the threat is contained and whether the matter is escalated for investigation.

FCMB

FCMB’s decision to report the suspects to the EFCC shows another part of cyber-risk management: the need for cooperation between financial institutions and law enforcement. Internal controls may prevent immediate harm, but prosecution can establish accountability and help deter similar conduct.

Banks also need to preserve evidence and share relevant intelligence about methods used to obtain credentials or bypass controls. Such cooperation can strengthen defences across the financial system, particularly as criminal networks increasingly combine social engineering, insider knowledge and digital tools.

The FCMB case is therefore more accurately understood as an alleged insider-access attempt that was detected before it became a breach. No successful server intrusion or financial loss has been established, and no customer impact has been identified. Its broader lesson is that insider threats cannot always be prevented at the point of intent. Employees can be approached, credentials can be compromised, and trusted access can be misused. The stronger defence is a system that limits access, monitors behaviour and intervenes before an attempt becomes a loss.


Technext Newsletter

Get the best of Africa’s daily tech to your inbox – first thing every morning.
Join the community now!

Register for Technext Coinference 2023, the Largest blockchain and DeFi Gathering in Africa.

Technext Newsletter

Get the best of Africa’s daily tech to your inbox – first thing every morning.
Join the community now!