Over N1 billion in fraudulent transactions bypassed security systems across West Africa in the first half of 2026, exposing growing weaknesses in the region’s digital financial infrastructure.
Cybersecurity firm, esentry disclosed this in its H1 2026 threat landscape report, stating that three major fraud incidents were detected only through routine audits, customer complaints and settlement warnings.
The report noted that the attacks did not trigger conventional security alerts because criminals exploited legitimate credentials, active sessions and trusted digital environments, rather than relying solely on software vulnerabilities.
According to Esentry’s chief business officer, Gbolabo Awelewa, attackers are increasingly exploiting “trust rather than vulnerabilities”, using legitimate credentials, familiar software platforms and AI-enabled workflows to evade detection.
The development is particularly significant for Nigeria, where banks, fintech companies and payment providers are rapidly expanding digital services, APIs, cloud infrastructure and instant-payment channels.
The firm said Nigerian organisations faced an average of more than 4,700 attacks weekly during the period, while about 281,500 Nigerian accounts were breached in the first quarter.
Esentry said its security teams processed more than 3.5 million alerts during the six months, with confirmed threats recording a median detection-to-escalation time of 11 minutes.
It added that its offensive-security team conducted 175 security engagements, including penetration testing, social-engineering exercises and cloud-security assessments. All the engagements reportedly achieved unauthorised access without requiring zero-day vulnerabilities.
The findings point to weaknesses in access controls and authentication systems, raising concerns over the ability of conventional cybersecurity tools to detect fraudulent activity carried out through authorised accounts.
Meanwhile, Nigeria’s electronic-payment ecosystem continues to face fraud risks despite improvements recorded in 2025. NIBSS reported that electronic-payment fraud losses fell by 51 per cent to ₦25.85 billion in 2025, from ₦52.26 billion in 2024.
Esentry said the threat extends beyond Nigeria, with Ghana recording more than 3,500 confirmed cybersecurity incidents in the first quarter of 2026, alongside growing online investment fraud.
The firm recommended stronger authentication controls, backend authorisation, continuous monitoring and improved logging of authentication sources and outbound data to help organisations detect abuse occurring within otherwise trusted systems.
We’ve got the edge. Get real-time reports, breaking scoops, and exclusive angles delivered straight to your phone. Don’t settle for stale news. Join LEADERSHIP NEWS on WhatsApp for 24/7 updates →
Join Our WhatsApp Channel




