Sponsored banner
BLOGS

FCMB Insider Threat: What Nigerian Banks Must Learn

  • September 3, 2026
  • 6 min read
FCMB Insider Threat: What Nigerian Banks Must Learn

The FCMB insider threat case has reopened a bigger conversation about banking security in Nigeria. It shows that cyber risk does not always start with an outsider breaking into a system. Sometimes, the biggest threat begins with a trusted credential.

The Economic and Financial Crimes Commission recently arraigned two men before the Federal High Court in Lagos over the alleged unlawful supply of access credentials linked to First City Monument Bank. According to reports, the case involves an FCMB service administrator, a former employee, and a third suspect said to be at large.

The allegations remain subject to court proceedings. Still, the case offers an important lesson for banks, fintechs and payment companies. Security is not only about stopping hackers outside the wall. It is also about limiting what trusted users can do inside the wall.

For more context on digital finance risk, read Blockwisely’s guide on crypto security and our explainer on phishing scams.

FCMB Insider Threat Case: What Happened?

The EFCC alleged that the defendants conspired to supply an access code connected to FCMB’s system. The credential was reportedly linked to a local administrative access point that could open the bank’s Virtual Centre Platform.

Reports also state that one count alleged the disclosure of server IP and domain credentials without authorisation. The alleged purpose was to facilitate access to the bank’s database.

One defendant reportedly pleaded not guilty, while the other pleaded guilty when the charges were read in court. The case now depends on the evidence presented before the court.

That distinction matters. At this stage, the public record points to allegations, not a final conviction against every named person.

Why This Is Not Just Another “Bank Hack” Story

Many headlines treat every cyber-related banking case as a hack. That can be misleading.

A hack usually suggests that an attacker broke through a system from the outside. An insider threat is different. It may involve someone with authorised access misusing that access, selling it, sharing it, or helping outsiders bypass normal security barriers.

That is why the FCMB insider threat story matters. It highlights the risk of valid credentials becoming dangerous when they fall into the wrong hands.

A password, admin code or internal system detail may look normal to security software at first. The system may see a recognised user. But the intention behind that access could be harmful.

This is the challenge banks face. They must trust employees enough to run daily operations. At the same time, they must design controls that assume any account can be abused.

The $25,000 Detail Matters

Some reports initially framed the case as a successful server hack involving stolen funds. Later clarification from TechEconomy said the $25,000 figure was allegedly a promised payment for disclosing credentials, not money confirmed to have been stolen from FCMB or its customers.

That is an important difference.

If the money was a promised payment for credentials, then the case is about attempted access and insider compromise. It is not the same as saying attackers successfully breached the bank’s database or drained customer accounts.

TechEconomy also reported that the attempt was detected and stopped before unauthorised access was completed. It said no customer funds or customer data compromise had been established.

This does not make the incident harmless. It means the risk appeared early enough for controls and law enforcement escalation to matter.

Why Nigerian Banks Should Pay Attention

Nigerian banks are becoming more digital. Customers now depend on mobile apps, instant transfers, USSD, agency banking, virtual accounts and automated settlement systems.

That growth creates convenience. It also creates more doors that need protection.

A single weak point can become expensive. A privileged account can expose internal tools. A former employee may understand old workflows. A current staff member may face pressure from fraud networks. A contractor may retain knowledge they should no longer have.

This is why banks need to treat insider risk as a core part of cybersecurity, not just a human resources problem.

The real question is not only “Who has access?” It is also “What can that access do, when is it being used, and does the activity match the user’s role?”

What Banks and Fintechs Should Fix

Banks and fintechs need stronger controls around privileged access.

First, they should apply least-privilege access. Staff should only access the systems they need for their roles. When a person changes role or leaves the company, access should change immediately.

Second, sensitive actions should require extra approval. No single user should be able to initiate and complete high-risk actions without review.

Third, companies should monitor unusual behaviour. An admin logging in at odd hours, checking systems outside their role, or attempting unusual actions should trigger alerts.

Fourth, institutions should strengthen offboarding. Former employees should not retain system knowledge, credentials or access paths that remain useful after exit.

Finally, banks should document and report suspected criminal activity quickly. Early reporting helps preserve evidence and improves the chance of enforcement action.

For more on financial fraud prevention, see Blockwisely’s coverage of digital payments and fintech fraud risks.

What Customers Should Know

Customers should not panic because of every banking cyber headline.

In this case, available reports have not established customer deposit losses or confirmed customer data exposure. The bigger issue is what the case reveals about how financial institutions must manage internal access.

Still, users should remain careful.

Never share banking passwords, OTPs, PINs or app login details with anyone. Do not trust calls or messages that claim your bank account will be blocked unless you act immediately. Always contact your bank through official channels.

Customers should also monitor account alerts. If a transaction looks strange, report it quickly.

Bottom Line

The FCMB insider threat case is a warning to Nigeria’s financial sector.

It shows that banking security cannot focus only on external hackers. Banks also need to watch trusted accounts, privileged credentials and internal access patterns.

The best defence is not fear. It is layered control.

Limit access. Verify sensitive actions. Monitor behaviour. Remove permissions quickly. Report suspicious activity early.

As Nigerian banking becomes more digital, insider threats will become harder to ignore. The institutions that handle this well will not be the ones that assume every credential is safe. They will be the ones that design systems for the possibility that even trusted access can become a risk.

Mastercat
About the author

Mastercat

Web3, Nfts, Crypto Investor. Builder 👷‍♂️ Business Development | Web3 Growth | Network Builder.

Share:
About Author

Mastercat

Web3, Nfts, Crypto Investor. Builder 👷‍♂️ Business Development | Web3 Growth | Network Builder.

Leave a Reply

Your email address will not be published. Required fields are marked *

ETHSafari