A few years back, account takeover fraud in Nigeria was straightforward. A bad actor compromised a victim’s details, moved the money once, and cashed out. Simple. Linear.
What we’re seeing across digital banking today is structurally different. Fraud has gone fully networked.
If you work in fraud risk in Nigerian fintech, you already know the playbook: It starts with a compromised account, usually via a SIM-swap, phishing attempt, or social engineering trick that pries loose a BVN, OTP, or PIN. But that’s just the entry point. The real engine behind the operation is a network of "mule" accounts. These are often opened by ordinary people recruited through social media ads promising quick cash for "renting out" their bank details.
Once inside, stolen money doesn't sit still. It hops through three, four, sometimes six of these mule accounts in rapid succession across multiple banks and fintechs in minutes before hitting a POS terminal or a P2P crypto exchange to cash out. Every hop is intentionally designed to outrun manual reviews and make tracing the paper trail as expensive as possible.
For a fully digital bank - no physical branches, no in-person verification to fall back on- this specific setup is a critical battleground.
Everything in digital banking runs on rails: API transfers, instant BVN/NIN validation, automated velocity checks, and digital liveness detection. That speed is our absolute strength for financial inclusion, but it’s also the exact terrain fraud rings seek to exploit. A mule network doesn't need to break a bank's security head-on; it just needs to move faster than the slowest link in the interbank chain can respond.
Regulation Sets the Floor, Not the Ceiling
This is where regulatory compliance becomes central to strategy, not just a checkbox exercise.
The CBN’s AML/CFT/CPF Regulations (2022) and the broader KYC framework place the responsibility of ongoing due diligence, not just onboarding checks, squarely on financial institutions. Tiered KYC backed by BVN/NIN linkage was specifically designed to make mule accounts harder to open and easier to track down. Industry obligations around Fraud and Forgery returns, alongside NIBSS Fraud Desk tools like BVN watchlists, "Post No Debit" (PND) restrictions, and instant interbank escalation, exist to make those rapid fund hops expensive and risky rather than effortless.
But regulation only sets the floor. What separates institutions that catch these networks early from those that miss them isn't whether they have controls, but how well those controls are tuned:
- Transaction Monitoring Calibrated for Velocity: Detecting pattern anomalies across an entire chain of transfers, rather than just isolated account red flags.
- Rapid Escalation Paths: Fast-track communication channels with other Financial Institutions, NIBSS, law enforcement, and the Judiciary that don't stall on internal sign-offs.
- An Informed Customer Base: Ensuring users understand that "renting" an account isn't a harmless side hustle. It is a direct step into a money laundering chain with serious legal consequences.
The Unwitting Mule: A Customer Education Problem
Neither banks nor regulators can close this fraud gap without the public. A few non-negotiable habits go a long way toward keeping people out of a fraud chain:
- Protect your credentials: Never share your OTP, PIN, or full BVN with anyone, including someone claiming to be calling from your bank. No legitimate institution will ever ask for them.
- Beware of "easy" money: Be extremely sceptical of any job or offer that only asks you to open an account and hand over the card or login details. The moment that account is used to move stolen funds, it will be frozen, and the owner will face legal questioning.
- Act fast: If you see an unauthorised transaction, report it to your bank immediately. Don't wait to see if it "sorts itself out." The first hour after a compromise is the most critical window for recovery.
Many people entangled in these networks never set out to commit a crime. They were offered what looked like a gig, completely unaware of how the account would be used or how severely the law treats money laundering.
Public awareness campaigns often focus exclusively on helping people avoid becoming victims of fraud. Far fewer address the fact that many mule account holders view themselves as gig workers rather than fraud accomplices. Closing that awareness gap is just as much a product and communication problem as it is a compliance issue, and digital banks are uniquely positioned to solve it directly through the app experience.
Moving Faster Than the Threat
The directional push from regulators, stricter BVN/NIN enforcement, structured reporting, and deeper interbank data-sharing is closing the loop. It is actively making the interbank system harder for fraud rings to navigate.
However, fraud networks adapt constantly to how digital banking functions. It is on financial institutions to ensure our defences evolve just as fast, together as an industry, rather than institution by institution in isolation. Fraud typologies move faster than regulatory cycles. The institutions that stay ahead treat compliance as a baseline to build from, not just a checklist to clear.
For digital-only banks, that means investing heavily in the unglamorous, technical work behind the scenes: fine-tuning transaction monitoring models and accelerating escalation response times.
That is the standard we hold ourselves to at Carbon. Being a digital bank cuts both ways: it is the precise terrain these networks attempt to target, but it also means we possess the infrastructure to move as fast as they do.
We constantly recalibrate our monitoring rules as fraud tactics shift. Escalations to NIBSS and other Financial Institutions happen on the same real-time digital rails that process customer transactions. Crucially, our Internal Audit and Fraud team works directly alongside Compliance and Engineering, not downstream.
We would rather be the institution that flags an anomalous chain of transfers within minutes and asks questions, than the one that discovers the fraud hours later after the funds have cleared six accounts. A proactive stance isn't just risk management; it's what a Bank owes its customers in exchange for their trust.



