For years, the standard advice for protecting your bank account was simple:

Don't tell anybody your PIN. Don't share your OTP.

That advice is still important.

But in 2026, it is no longer enough.

The way Nigerians bank has changed dramatically. We send money from our phones, receive OTPs through the same devices, approve transactions with apps, use USSD, connect our cards to websites and move money between banks and fintech wallets within seconds.

That convenience has made life easier for us.

Unfortunately, it has also created more doors for criminals to try.

And some recent incidents in Nigeria should make every bank customer pay attention.

This is no longer just about someone calling you and asking for your OTP

In August 2026, Access Bank approached the Federal High Court in Lagos after discovering what it described as unauthorised transactions involving approximately ₦1.34 billion from some customer accounts through its Access SME internet banking application.

The money had reportedly moved across accounts in numerous financial institutions. A court subsequently ordered restrictions on accounts that allegedly received the funds while efforts were made to trace and recover the money.

In another recent case, a GTBank customer told The PUNCH that ₦4.6 million disappeared from his account in a single unauthorised transfer.

According to his account, his phone was still with him. He said he did not receive an OTP authorising the transaction and did not receive the usual SMS transaction alert. He only discovered something was wrong later when he tried to use his account and found that his balance had almost been wiped out. The matter was reported to the police and escalated to the bank.

Then, in September, the EFCC arraigned a man over allegations involving unauthorised access to financial accounts. Prosecutors alleged that two‑factor authentication on Ravenpay user accounts had been bypassed in a scheme connected to ₦700 million belonging to Best Start Microfinance Bank. The defendant pleaded not guilty, so those allegations remain before the court.

These are different cases, and they should not be treated as proof that every Nigerian bank is unsafe.

But together they illustrate something important:

The threat has evolved.

The numbers are already significant

According to figures contained in the Central Bank of Nigeria's Nigeria Payments System Vision 2028, banks and customers recorded approximately ₦134.48 billion in actual fraud losses between 2020 and 2025, from attempted fraud worth about ₦187.79 billion.

The attacks were spread across internet banking, mobile banking, e‑commerce, ATMs, POS terminals and other payment channels.

At the same time, banks are stopping a significant amount of attempted fraud.

Four major Nigerian banking groups reportedly blocked about ₦14.5 billion in potential fraud losses during 2025 through improved monitoring, detection and security systems.

So this isn't a story about banks doing nothing.

It is a story about an arms race.

Banks improve their security.

Fraudsters look for another weakness.

Banks close that weakness.

Fraudsters change tactics.

And increasingly, the easiest target may not be the bank's server.

It may be you.

Sometimes, the hacker doesn't need to hack the bank

Imagine receiving a call:

"Good afternoon sir, I'm calling from your bank. We noticed an unusual transaction on your account."

The caller knows your full name.

Maybe they even know your bank.

They sound professional.

They tell you they are trying to protect your money.

Five minutes later, you have unknowingly given them exactly what they need to steal it.

This is social engineering.

Instead of attacking sophisticated banking infrastructure directly, criminals manipulate the customer into opening the door for them.

And the methods are becoming more sophisticated.

NIBSS and CBN officials have specifically identified social engineering, internet banking, e‑commerce and insider‑assisted fraud among areas requiring continued attention. SIM‑swap‑related risks are another concern.

Nigeria's computer emergency response team, ngCERT, also warned in August about phishing, fake websites, impersonation, fraudulent calls and messages, credential theft and even AI‑assisted impersonation being used to deceive people and organisations.

So what can an ordinary person actually do?

Start treating your bank account like your house

Most people wouldn't have one key that opened their house, office, car and safe.

But digitally, many of us effectively do exactly that.

The same phone number receives our calls and banking OTPs.

The same email address connects to several financial accounts.

The same phone contains banking apps, email, WhatsApp and sometimes photographs of sensitive documents.

And some people reuse the same password everywhere.

That creates a dangerous chain.

If one important part of that chain is compromised, several other accounts may become vulnerable.

Your financial security therefore shouldn't begin when you open your banking app. It should begin with your phone, SIM, email and passwords.

Seven habits can make you a much harder target

1. Never approve a transaction you did not initiate.

An OTP is not something you give a bank employee over the phone. If somebody asks you to read out an OTP, PIN, password or card security code, end the conversation and contact your institution through its official channel.

2. Take an unexpected loss of mobile network seriously.

If your SIM suddenly stops working for no clear reason, don't simply assume the network is bad.

SIM‑related identity fraud remains a concern in Nigeria, and the NCC has introduced additional systems aimed at tackling fraudulent SIM activities, including risks involving swapped and recycled numbers.

If your number unexpectedly loses service, contact your mobile network and consider contacting your financial institutions promptly.

3. Reduce how much money can leave your account at once.

If your bank allows you to set transaction limits, use them.

There is little reason for an account you normally use for ₦20,000 or ₦50,000 transactions to have an unnecessarily high daily transfer limit.

Convenience is useful.

So is friction.

Sometimes one extra security step is exactly what prevents your entire balance from disappearing in one transaction.

4. Don't keep every naira in one everyday transaction account.

An account you use constantly for transfers, online purchases and everyday payments has more exposure than one you rarely touch.

Consider separating everyday spending money from larger savings.

That does not make the second account impossible to attack, but it reduces the amount exposed through your most frequently used account.

5. Turn on every useful transaction notification available to you.

Push notifications, SMS alerts and email alerts may feel repetitive until the day one of them tells you that ₦500,000 just left your account.

The faster you notice suspicious activity, the faster you can report it.

6. Stop clicking banking links simply because the message looks official.

A message can contain your bank's name and logo and still be fraudulent.

If a message says there is a problem with your account, don't panic and click the link.

Open your banking app yourself or contact the institution through an official number or website you independently verified.

7. If something happens, speed matters.

Don't wait until tomorrow.

Immediately contact your bank or fintech and request that the account or relevant channels be restricted. Report the transaction as unauthorised and preserve screenshots, messages, phone numbers, transaction references and other evidence.

Where appropriate, report the matter to law enforcement as well.

The first few hours can matter when money is rapidly moving through multiple accounts.

Banks have a responsibility too

Customers cannot carry the entire burden.

Banks, fintechs, telecommunications companies and payment providers have access to information and security infrastructure that ordinary customers do not.

The CBN recently warned that Nigeria's financial institutions are now so interconnected that a cybersecurity problem affecting one bank, fintech, payment provider or technology vendor can potentially have consequences beyond that institution.

The regulator is therefore calling for cybersecurity, third‑party technology risk and business continuity to be treated as financial‑system issues rather than simply IT problems.

That distinction matters.

When someone loses their life savings, telling them afterwards that they should have been more careful is not a security strategy.

Institutions must continue improving authentication, fraud monitoring, unusual‑transaction detection, customer notifications and rapid interbank response.

But customers also need to accept a new reality.

Your money is digital now. Your security habits must become digital too.

Twenty years ago, protecting your money might have meant keeping your ATM card somewhere safe and hiding your PIN.

Today, your phone may effectively be your bank branch.

Your SIM may be part of your identity.

Your email can be a route to resetting financial passwords.

A fake website can look almost identical to the real one.

And a criminal does not necessarily need to be standing anywhere near you to attempt to steal from you.

That shouldn't make us afraid of digital banking.

It should make us better digital bank customers.

Banks will continue investing billions in cybersecurity.

Regulators will continue strengthening the system.

Technology will continue improving.

But there is one security system that every Nigerian controls personally:

the decisions we make before we click, approve, disclose or transfer.

Sometimes, five seconds of suspicion can protect money that took five years to build.

Share Post Talk to AtomAfrica