When Fraud Moves Faster Than Rules

fraud-vs-rules-wp-header

Nigerian banks lost N52 billion to fraud in 2024 and a Nigerian infrastructure company thinks it has found a structural fix to fraud and the evidence is starting to back it up.

Somewhere in Lagos Nigeria, a fraud analyst is staring at a transaction pattern that does not quite make sense.

The amounts are small; the timing is regular, and nothing in the system has flagged it. But something is off; a low-value account funding sequence, a withdrawal rhythm that does not match the customer’s profile, a device identifier that has appeared before, in a different institution, on a different day.

Individually, these signals mean nothing. Across a network of 500 financial institutions, they are the early signature of a coordinated cash-out scheme. The kind that, left unchecked, will drain multiple institutions before a single alert is raised.

This is the fraud problem that Africa’s financial sector has not yet fully reckoned with. Not spectacular breach. Not the rogue insider caught on CCTV. The quiet, systematic, cross-institutional attack that exploits the one structural weakness every bank shares: it can only see itself.

The Numbers Behind the Problem

Nigeria’s financial institutions lost N52.26 billion to fraud in 2024 and this figure represents a 196% increase over five years, according to the Nigeria Inter-Bank Settlement System. In more recent times, the number of individual fraud cases is falling, and what is rising sharply is the value lost per incident.

More than 92% of those cases are linked to digital channels. Social engineering; phishing, impersonation, account takeovers, accounts for nearly half of all fraud. Instant payment transactions through NIBSS exceeded N1 quadrillion in 2024 across billions of individual transfers. The infrastructure that makes African finance faster is, by definition, also the infrastructure that makes fraud faster.

The institutions most at risk are not those with the weakest individual controls. They are those operating in isolation, unable to see threats that are already visible elsewhere in the ecosystem.

What once appeared as a patchwork of isolated cyber incidents has evolved into a sophisticated, industrialized ecosystem of cross-border financial crime.

What AI Changed – For the Attackers

For years, the fraud prevention conversation has focused on what AI can do for banks. Anomaly detection, behavioral biometrics, real-time decisioning, etc. but worthy of note is that AI has also changed the calculus on the other side of the table.

Synthetic identity generation; the creation of convincing false personas using combinations of real and fabricated data, used to require significant resources and skill. Generative AI has made it cheap and fast. Social engineering scripts that once took days to craft can now be personalized at scale in minutes. And crucially, attackers can now test fraud typologies against institutional defenses, observe the response, and iterate. Faster than any institution’s rule-writing team can keep up.

The CBN’s 2024 Risk-Based Cybersecurity Framework acknowledges this directly: regulated institutions are now expected to operate formal Cyber-Threat Intelligence programmes proactively identifying and mitigating threats, not simply responding to incidents after they occur.

The Structural Fix

This is where Qore, a banking-as-a-platform company providing infrastructure for hundreds of financial institutions across Africa, has staked a claim worth examining.

Qore sits at the intersection of more than 500 financial institutions across Africa. That position, the company argues, is not just a commercial advantage; it is a detection advantage. Fraud patterns that are invisible within any one institution become statistically visible across the network. This can be a cash-out scheme being tested across three institutions simultaneously, or an unusual transaction sequence that looks like noise in isolation but looks like a typology at scale.

Qore has implemented an anonymized fraud typology response, which means that the intelligence shared across its network of 500+ institutions is never traceable back to any individual client. Security teams receive actionable threat briefings, validated patterns, proposed controls; deployment guidance built entirely from anonymised, aggregated signals. No institution has to choose between protecting its customers and benefiting from shared intelligence. The anonymization model ensures they can do both.

What Qore has built and what it is now making a case for is a governance model designed to translate that network visibility into institution-level protection, with the documentation trail that regulators and boards require.

The model operates in three layers. Every fraud signal identified at the network level is validated before any control is recommended, assessed for accuracy, cross-institution consistency, and potential customer impact. Controls are then tested in parallel environments against historical data before live deployment, generating the audit evidence that regulatory review demands and every deployment decision is documented: what was deployed, when, against which typology, and with what evidence base.

To Qore, this is zero trust governance, a principle borrowed from cybersecurity architecture but applied to operational accountability. No signal is acted on without validation, no control is deployed without testing, and no deployment is completed without documentation.

Why This Matters Beyond Nigeria

At the 2026 Spring Meetings, the fund characterized data sharing between financial institutions not as a policy option but as infrastructure, as foundational to resilience as capital buffers. The World Bank’s work on fast payment fraud has reached similar conclusions: the institutions most exposed are those that cannot see beyond their own transaction data.

For Africa’s financial sector, where digital payment infrastructure is expanding faster than fraud governance frameworks can track, the stakes are not abstract. The same connectivity that has brought millions of people into the formal financial system has also created the attack surface that organised fraud networks are actively mapping.

African financial institutions are already being targeted and the infrastructure they rely on should be built to respond before the attack fully materializes, with governance that holds up under scrutiny.

For the fraud analyst in Lagos still staring at that transaction pattern, the difference between an infrastructure that sees what they see and one that sees the whole network is not a feature comparison. It is the difference between catching a scheme early and writing the incident report after the fact.

REFERENCES

Nigeria Inter-Bank Settlement System (NIBSS), Fraud Report 2024, released February 2025. Reported losses of N52.26 billion across 70,111 confirmed fraud incidents. Nigeria’s financial sector suffers N52.26 billion loss to fraud in 2024 – NIBSS report  – Nairametrics

Technext24, “Nigeria fintech fraud data sharing gap costs industry billions,” April 2026. “Fewer incidents, but far more money is lost per incident. Fraud is becoming more organised.” Nigeria fintech fraud data sharing gap costs industry billions, experts warn

Daily Trust, “Nigeria Losing Billions to Digital Fraud,” October 2025. Consolidated estimates from CBN, NIBSS and industry reports. dailytrust.com/nigeria-losing-billions-to-digital-fraud/

NIBSS CEO Premier Oiwoh, 2026 Nigeria Electronic Fraud Forum Technical Kickoff Session, Lagos, January 2026. legit.ng; itedgenews.africa

Foundation for Investigative Journalism (FIJ), April 2026, citing CBN and NIBSS data on NIBSS Instant Payment platform volumes. E-payment transactions in Nigeria hit all-time high of N1.07 quadrillion in 2024  – Nairametrics Instant payment transactions rise by 120% in 2yrs — CBN – NIBSS

 

 

Build Tomorrow, Today

Let’s discuss how our products can give your business the boost it needs.

Qore icon
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.