
April 11, (THEWILL) – TUNDE OMOLEHIN writes on the perpetual electronic banking fraud (e-fraud) experienced by Nigerians as a result of the mandatory biometric data collection system started by the Federal Government since the introduction of its cashless banking system in 2015
Sometime in December 2021, an unidentified middle-aged man surfaced on social media threatening to kill himself at a branch of the United Bank for Africa (UBA) in Iju, Lagos State. The man alleged that the bank transferred his money to hackers who compromised his account.
It was gathered that the man had earlier reported an unfamiliar debit transaction of N450, 000 on his account to the bank, after which he asked to get a court order to prove that he had no business with the recipient who apparently happened to be a hacker.
“He came to the bank and complained at the Customers’ desk how his Bank Verification Number (BVN) was compromised by unknown person, but he was asked to get a court order only to be informed upon his return that the transaction had been facilitated in favour of the supposed hacker.
“Incidents like this are frequent in the banking hall, but most victims prefer to be silent about it and bear the loss. The fact is that the bank will never bear the responsibility of any account detail that was compromised by an outsider.
THEWILL further gathered that the bank neither refunded the stolen money to the man nor compensated him for losing it in such a way. But another victim of cyber fraud, Mrs Lillian Okon, was lucky to get a refund of N191, 000, after hackers succeeded in swapping it from her bank account.
“Honestly, I didn’t believe that the money would come back to me. I thank God for the EFCC, which is the hope of common people like me,” she said.
In January 2021, Okon had received a call from an unknown person who claimed to be a staff of the bank where her account was domiciled.
“It heard a man’s voice request my bank account detail. He said the Federal Government wanted to credit my account with a COVID-19 loan I once applied for.
“After I gave him my personal details, I started receiving some debit alerts that showed that I personally authorised some transactions from my account,” she recounted.
The suspects were later apprehended by the Police in Osogbo, Osun State, following a report by a Point of Sale Operator who grew suspicious of their activities. They were subsequently handed over to the Economic and Financial Crimes Commission (EFCC) for further investigation.
Until the incident, Okon said, she had no prior knowledge that a third-party could gain access to her account details without submitting her ATM code and Bank Identification (BVN). “I actually gave the caller my birth date, full name and few data about myself but not that of my bank or secret codes. This has been happening for some time now in the country. I don’t trust bank workers at all because they could also be involved in this fraudulent act. In most cases, bank officials are complicity in giving out their customers’ details to fraudsters,” she told THEWILL.
In the last few years, both data theft and cyber-crimes have become so widespread that the arrest and prosecution of the suspects have become a major preoccupation of the EFCC.
Such criminals are known locally as ‘Yahoo-boys.’ They operate in groups specialised in defrauding fellow Nigerians and foreigners through various online tricks.
In April 2021, the Central Bank of Nigeria issued a fraud alert about the activities of cyber-criminals who had taken advantage of the COVID-19 pandemic to defraud other citizens, steal sensitive information or gain unauthorised access to computers or mobile devices, using different techniques.
Fraud Index Rises
According to a report from Consumer Awareness and Financial Enlightenment Initiative, a non-profit organisation, Nigeria is ranked among the top countries that are prone to all forms of cybercrimes.
The report, which was released in 2019, projected that a total sum of $6 trillion will be lost by 2030 to cybercrime within and outside Nigeria.
The CAFEI also indicated that in 2018, commercial banks in Nigeria lost a cumulative N15 billion ($39 million) to electronic fraud and cybercrime. This was a 537 per cent increase on the N2.37 billion loss recorded in 2017. Over 17, 600 bank customers and depositors lost N1.9 billion to cyber fraud in 2018, with fraud rising by 55 per cent from the previous year.
Similar losses were also revealed by PwC’s Global Economic Crime and Fraud Survey 2020, which showed that the total cost of cybercrimes in Nigeria was worth about $42 billion. Aside from that, investigative data from the EFCC in Lagos State for the second quarter of 2021 indicated that Lekki District was the preferred location for all manner of cyber fraud syndicates.
According to the report, “between April and June 2021, the Advance Fee Fraud and Cyber Crime Sections of the command recorded a total of 402 internet-related fraud arrests.
Unsecured Data
A financial expert, Dare Omoluabi, told THEWILL that the mass e-registration of citizens, using biometric data collection systems via facial photographs, fingerprints and the issuance of a unique identification number, is believed to have encouraged fraud-related crimes and cybercriminals to prey on bank customers, using the latter’s bank details.
“If you have been following data on fraud-related cases you will agree with me that all can be traced to individual’s biometric data flipping into the hands of these cyber criminals and fraudsters.
“The moment they can lay hold on such data like your National Identification Number (NIN) or Bank Verification Number (BVN), then rest assured that everything about you can be manipulated,” Omoluabi said.
He expressed concern over the issue of requesting for the Bank Verification Number (BVN) of applicants as a prerequisite for NIN registration.
THEWILL recalls that since the introduction of the cashless policy via National Identification Numbers in 2015 and the subsequent mandatory use of Bank Verification Numbers for online transaction, there has been a rise in cases of fraud in the finance sector in Nigeria.
The Federal Government had mandated the National Identification Management Commission (NIMC), through the NIMC Act No. 23 of 2007, to establish, own, operate, maintain and manage the National Identity Database in Nigeria.
The commission is also charged with registering persons covered by the act, assigning a unique NIN and issuing General Multi-Purpose Cards (GMPC) to those who are citizens of Nigeria, as well as others legally residing in the country.
But Joshua Olufemi, Founder and Executive Director of Dataphyte, a leading data and research news outfit in Nigeria, believes there is evidence that large volumes of personal data, “including biometric information stored on multiple centralised databases, have been frequently compromised.”
He noted that such action is increasing citizens’ exposure to privacy intrusions, targeted advertisements, identity fraud and blackmail.
“Obtainng a NIN from the NIMC offices across the country is not something you would do without getting yourself prepared for it,” said Mr Segun, during an interview with some NIN applicants in Sokoto State.
The 35-year-old, who appears frustrated was among others on a long queue at NIMC official along Gusua Road, Sokoto, added: “You have to commit your time, money and energy. In the end, you may not get it at ease. This is about the fourth time I am doing SIM re-registration and verification within the same year. They keep calling me to say the registration wasn’t successful or something else.
“Yet, fraudsters are still committing different crimes, using SIM without hiding the lines. When you report such criminal acts, it is still difficult for the security agencies to fish-out the fraudsters.” He lamented.
Unease, Compromise
THEWILL investigation reveals that there are different prices for “capturing” alone, and “capturing with printout.” While getting a slip of Identify card is not without a fee illegally attached to it by NIMC officials in most biometric collection in some locations visited by THEWILL.
Most applicants seeking to obtain NIN alleged that the sale of registration forms at unofficial fees was a daily affair among officials, who use security guards as ‘middle men’ or ‘agents’ to avoid being caught in the act.
“To process the forms, they collect between N5, 500 and N6, 000 from us,” an applicant, who spoke on the condition of anonymity, said.
One of the ‘agents’, who approached this reporter to ask him if he was interested, explained that the fee charged for processing the form was meant to take care of the ‘extra-effort’ made by the NIMC officials to ‘fast-track’ it.
“The charges are for buying fuel for the power generator and to ensure that we subscribe to a faster Internet connection rather than waiting for the system provided by the government,” he said.
One of the applicants at the NIMC headquarters in Osogbo, Osun State, Adekemi Sule, described the process as cumbersome. To get the attention of the officials on time, some people had to queue up at the centre as early as 6.am.
The story is the same in other centres visited within the metropolis. It was also alleged that the NIMC officials collected between N2, 500 and N3, 000 from intending registrants to start the registration process.
But the spokesman of NIMC, Kayode Adegoke, said the commission would always ensure maximum security of its systems and database because of the critical nature of the identity data, which the Commission collects, manages and maintains as critical assets for the country.
“We assured members of the public that it will continue to uphold the highest ethical standards in data security on behalf of the Federal Government and ensure compliance with data protection and privacy regulations.”
Data Protection
Experts have said that Nigerians are unaware that data protection is the process of safeguarding important information from corruption, compromise or losses incurred.
“Lack of adequate knowledge about what data protection entails is no doubt making Nigerians’ data vulnerable to breach. Many Nigerians still don’t take the protection of their data privacy seriously. This explains why their data and personal information are breached by some dubious companies and individuals whose custodies the data is kept.
“And this is one of the reasons experts said every Nigerian should be fully aware of data protection and privacy in order to prevent these online criminals.
“The citizens have to be able to apply Section 6 (a,c) of the NITDA Act 2007 in pursuit of data rights infringement, which is the current national law on data protection in Nigeria as at today,” said Dr Nafiudeen Adetutu, a data scientist at the Ladoke Akintola University of Technology, Ogbomosho, Oyo State.
The regulation is aimed at protecting the right to privacy, creating the right environment for digital transactions, job creation, and improving information management practices in Nigeria.
Deji Idowu, a security expert, also advised that commercial banks should ensure that the right personnel are put in charge of their sensitive online departments to ensure that no foreign body has access to it.
“Security against fraud in banks is a holistic battle. Banks should not only ensure that competent people are employed to man their IT department but they should also continue to ensure that those employed are dutiful and sincere,” he added.
Adejoh Moses, a chartered accountant, said that customers were culturally not familiar with security issues around digital transactions, “Even well-educated people run the risk of falling victim to social engineering and identity theft traps in this country. Banking institutions must go beyond educating customers on the protection of crucial information to actual data protection and integrity amongst operators and stakeholders. Customer education is paramount in countering security threats in digital payments,” he said further.
“Currently, there are three main collectors of very private information on people in Nigeria. These are the various state institutions; private businesses, such as commercial banks, telecommunication service providers and foreign embassies. These stakeholders must ensure that the process of collecting or gathering citizen’s biometric data is secure and not compromised,” Moses advised.
Tunde Omolehin is an award-winning Journalist with prose in investigative and storytelling that is connecting the dots between the under-reported communities and policymakers to ensure good governance and accountability.


