There is a version of bank fraud that does not fit the movie. No hooded stranger, no cracked password, no breach of the perimeter. Just a member of staff with a real ID, real access, and a real reason to be exactly where they are in the process. It is the hardest fraud to catch, and in Nigeria it is now serious enough that people are calling it a crisis of insider complicity.
For a long time this was talked about in anecdotes. Now it has numbers.
In the first quarter of 2025 alone, FITC recorded 63 staff-related fraud cases, up from 47 in the same quarter a year earlier. Twenty-eight employees were under investigation. Twenty-three had their appointments terminated. In three months. And when NIBSS named the most prevalent fraud technique of 2025, it did not name a piece of malware. It named social engineering, particularly insider abuse.
Sit with what that means, because it breaks a comfortable assumption most institutions still run on.
The assumption is that authentication equals safety. If the credentials were valid, the session was real, and the maker-checker passed, then the transaction was legitimate. That logic feels airtight. It is also exactly the logic the insider exploits. The insider does not need to defeat your authentication. They are the authentication. Their login is genuine. Their access was granted on purpose. The maker-checker "passing" tells you the process ran, not that the instruction was honest.
This is why "but we authenticated it" has quietly stopped being a defence. Authentication answers one question: who is this? It has never answered the question that actually matters in a fraud: should this money move? A control that verifies identity and then trusts everything that identity does is, by design, blind to a trusted person doing an untrusted thing. And the insider lives precisely in that blind spot, at the right workstation, with the right credentials, at the right point in an otherwise legitimate flow.
The same blindness applies beyond staff. When a customer is socially engineered, they authenticate too. They pass every check because nothing was faked. They were tricked into authorising the transfer themselves. Device fingerprinting, one-time passwords, biometric prompts, none of them fire, because from the system's point of view the rightful owner simply made a payment. The fraud is in the intent, and intent is invisible to a control that only checks credentials.
So how do you catch a threat that carries a valid badge?
You stop watching the badge and start watching the behaviour. A trusted staff member processing a failed-reversal to an account that has no business receiving it is behaving abnormally, even though every credential is in order. An account that has quietly received for months and suddenly forwards to many others is behaving abnormally, even though the owner is real. A high-value transfer to a beneficiary added minutes ago, an approval from a session that does not match the usual device or location, a pattern of amounts and timing that this customer has never once shown: these are all detectable, and none of them depend on the identity being fake. They depend on the action not fitting the actor.
This is the core idea of positive security, and it is what we built into Omniguard. Instead of asking only "is this a valid user," it learns what normal looks like for that user and that account, then holds the action that does not fit. The valid session doing the invalid thing is exactly what it is designed to see, because it is watching behaviour, not just credentials.
The insider quarter is a warning, and I think it is a healthy one. It forces a discipline our industry has avoided: separating identity from legitimacy. Knowing who someone is has never been the same as knowing that what they are doing is right. For years we let the two blur together because it was convenient. The people moving money out of our banks with valid access have made it clear we cannot afford that blur anymore.
Verify identity, of course. But then watch behaviour, every time, on every transaction. Because the most expensive fraud in Nigeria today is not breaking in. It is logging in.
Sources
