The Transfer Nobody Made: How Unauthorised Payments Are Testing Nigeria’s Banking Controls
For a bank customer, there is a particularly frightening moment when a familiar account balance suddenly stops making sense. Money is gone. The transaction appears on the statement. The bank says...
For a bank customer, there is a particularly frightening moment when a familiar account balance suddenly stops making sense.
Money is gone. The transaction appears on the statement. The bank says there is a security or fraud explanation. The customer says the transaction was never authorised.
A series of disputes involving Guaranty Trust Bank, GTBank, shows just how difficult that space has become for Nigerian banks and their customers.
In one case, the Federal Capital Territory High Court ordered GTBank to refund more than ₦4.6 million and $3,123.16 after finding that funds had been illegally deducted from the account of Universal Agricultural Empowerment and Development Initiative, UNAEDI. The judgment, delivered in September 2019, also awarded ₦100,000 in general damages.
The dispute began after GTBank placed a lien on the customer’s account in November 2015.
Months later, the customer began receiving alerts for transactions it said it had not authorised. According to the court report, ₦412,000 was deducted in a series of transactions on March 9, 2016. GTBank subsequently notified other banks that transactions involving the customer’s account were allegedly fraudulent.
The bank later deducted about $3,123 from the customer’s dollar account and more than ₦4.2 million from the naira account.
The customer challenged the bank’s actions, arguing that GTBank could not simply classify transactions as fraudulent, take the money and leave the account holder without a satisfactory explanation.
The court ultimately ordered the refunds.
The case is old. The compliance problem is not.
In February 2026, a separate GTBank customer, a university lecturer, alleged that two unauthorised transfers totalling ₦9.98 million were made from his account within less than three minutes. His solicitor said the transactions involved transfers of approximately ₦4.99 million each and that the customer had neither authorised them nor disclosed his PIN, token or other banking credentials. The petition demanded that GTBank refund the money within seven days.
The lecturer’s allegation has not been established by a final court judgment. That distinction matters.
But the case raises a question banks cannot avoid: when an electronic transfer is disputed, who should carry the burden of proving what happened?
That question is becoming more important as Nigerian banking becomes almost entirely digital.
The old image of bank fraud involved forged cheques, stolen cards or someone physically entering a branch. Today’s problem can be much quieter. An account can be accessed remotely. Credentials can be compromised. A customer’s phone can be taken over. A SIM can be swapped. Malware can capture information. A fraudster can manipulate a customer into approving a transaction without the customer realising what has happened.
There is also the insider risk.
GTBank itself has previously faced an alleged insider fraud case involving a staff member accused of stealing almost ₦10 million from customer accounts. The incident illustrates another uncomfortable reality for financial institutions: not every threat sits outside the firewall.
For compliance and risk teams, the important issue is therefore not simply whether a transaction was technically authenticated.
Authentication and authorisation are not always the same thing.
A transaction may carry the correct credentials and still be fraudulent if those credentials were obtained through social engineering, account takeover or other forms of compromise.
That is where transaction monitoring becomes important.
A transfer of ₦4.99 million is not automatically suspicious. Neither is a customer making two large payments within minutes. But if the transactions are radically inconsistent with the customer’s normal behaviour, move to a newly established beneficiary, occur at an unusual time, follow a change in device or SIM information, or are immediately followed by rapid movement of the funds, the combination should attract attention.
The bank’s controls should be able to see the pattern.
This is also where fraud prevention and AML compliance increasingly overlap.
Once stolen money enters another account, the receiving account can quickly become part of a money laundering chain. Funds may be moved through several banks, fintech platforms or mule accounts before anyone has time to recover them.
A recent Access Bank case demonstrates the scale of the problem.
In August 2026, Access Bank approached the Federal High Court in Lagos after discovering that ₦1.34 billion had allegedly been transferred without authorisation from four customer accounts through its Access SME App. The bank identified transfers from four accounts belonging to MIB TXN Bullion, AIICO General Insurance, Apogee Engineering and Sims Nigeria. The money was allegedly distributed across accounts held by dozens of banks and payment institutions.
Access Bank subsequently sought orders covering 71 financial institutions and payment providers, including GTBank, Zenith Bank, UBA, OPay, PalmPay and Moniepoint. It wanted the recipient accounts restricted, the funds preserved and information supplied to help trace the money.
That is the other side of an unauthorised transfer.
The first victim is the person or company whose account has been emptied. The second problem is the financial system’s race to stop the stolen money from disappearing.
For banks, this creates a difficult balance. Customer accounts must remain usable. Fraud controls cannot turn every unusual transaction into a blocked payment. Yet a system that allows large transfers to move instantly across dozens of institutions gives investigators very little time to intervene.
The regulatory expectation is therefore moving towards faster detection, stronger authentication and better cooperation between banks, fintechs and payment service providers.
For compliance officers, several questions should be uncomfortable ones. How quickly can the institution identify an account takeover? Can it distinguish a customer genuinely initiating a high value transaction from a fraudster using the customer’s credentials? What happens when a new beneficiary receives a large payment immediately after being added? How quickly does the bank contact the receiving institution? Can the institution freeze or recall funds before they are dispersed?
And when a customer disputes a transaction, can the bank produce reliable evidence showing how the transaction was initiated, authenticated and completed?
That last question is crucial.
In the 2019 GTBank case, the dispute was not simply about money. It was about the bank’s authority to place a lien, classify transactions as fraudulent and deduct funds without adequately explaining its actions to the customer.
The compliance lesson is straightforward.
A bank cannot treat a customer complaint as a customer service problem when the complaint concerns the integrity of the payment system.
It is a fraud risk issue, a conduct risk issue, a cybersecurity issue and potentially an AML issue at the same time.
The numbers involved make the stakes obvious.
The old GTBank case involved more than ₦4.6 million and $3,123. The 2026 lecturer’s allegation involved ₦9.98 million. The recent Access Bank incident involved ₦1.34 billion.
The amounts are different. The underlying question is remarkably similar.
When money leaves an account without the customer’s authority, how quickly can the financial system prove what happened, stop the trail and put the customer back where they were?
For Nigerian banks, that is becoming one of the most important tests of digital banking resilience.
Customers are being asked to trust the technology.
The technology now has to earn that trust.
Category: Banking Compliance, Cyber Fraud, Financial Crime, Consumer Protection, AML, Digital Banking, Operational Risk



No Comment! Be the first one.