Home News NCBA Bank faces tough questions over delayed fraud detection systems after eight-day multimillion shilling heist

NCBA Bank faces tough questions over delayed fraud detection systems after eight-day multimillion shilling heist

by Bonny
0 comment

NCBA Bank is facing fresh questions over the security of its banking systems after a contractor with access to a live platform allegedly altered the system and enabled fraudulent withdrawals at the bank’s Rwandan subsidiary.

The contractor had been hired as a software developer to maintain and upgrade NCBA’s mobile and retail banking platform connected to the MTN network.

However, according to court papers and reports, the consultant allegedly went beyond the assigned duties and made changes that allowed cash withdrawals to be processed even when the affected accounts either did not exist or had insufficient funds.

The alleged fraud took place between June 6 and June 14, 2025. During the period, 70 customers reportedly made 260 fraudulent transactions, resulting in losses of about Sh57.5 million.

The case raises serious questions about how much control external contractors are allowed to have over banking systems and how closely their activities are monitored once they receive access.

Technical contractors are often given wide privileges because their work may require them to make changes directly to live systems. But such access also creates a major security risk if controls are not strong enough. In this case, the alleged changes appear to have allowed normal checks to be bypassed, raising concerns about whether the contractor’s activities were properly restricted and monitored.

Another concern is the length of time the suspicious transactions continued. An eight-day period gave room for hundreds of transactions to be completed before the problem was detected and action was taken. For a bank handling customer money, such a delay can raise questions about the effectiveness of its monitoring and alert systems.

The Rwanda incident also comes against the background of other fraud cases linked to insiders and contractors that have affected NCBA in recent years. These have included cases involving Fuliza-related fraud and misuse of customer accounts at branches.

Also Read  Agnes Kagure Foundation Rolls Out Projects to Empower Youth, Women, and Special Needs Communities

The repeated nature of such incidents puts greater pressure on the bank to demonstrate that lessons are being applied and that access to sensitive systems is being controlled more tightly.

Banks cannot completely avoid using outside technology specialists. Modern banking systems are complex and often require specialised developers and engineers. The responsibility, however, remains with the bank to ensure that contractors only have access to what they need, that every system change is recorded and that unusual transactions are detected quickly.

The NCBA case therefore goes beyond the actions of one contractor. It raises broader questions about internal controls, access management and the speed at which suspicious activity is identified.

For customers, the expectation is simple. Money placed in a bank should be protected by strong systems and constant oversight. NCBA will now face pressure to demonstrate that its controls are strong enough to prevent a repeat, particularly where external contractors are given access to live banking platforms.

You may also like

You cannot copy content of this page