Profiled Nigeria Corporate Logo - Nigeria’s trusted digital verification ecosystem for people, businesses, and products.
M
M
e
e
n
n
u
u
M
M
e
e
n
n
u
u

September 8, 2026

September 8, 2026

EFCCs 700 Million Case Exposes Nigerias 2FA Banking Risk

Two-factor authentication is supposed to stop criminals even when passwords are compromised. But a new 700 million EFCC case involving an alleged 2FA bypass shows why Nigerian bank customers cannot assume an OTP or banking app alone makes their money untouchable.

Two-factor authentication is supposed to stop criminals even when passwords are compromised. But a new ₦700 million EFCC case involving an alleged 2FA bypass shows why Nigerian bank customers cannot assume an OTP or banking app alone makes their money untouchable.

The EFCC has arraigned Osaretin Osagiede over an alleged ₦700 million fraud involving the bypass of two-factor authentication on Ravenpay user accounts.

The ₦700 Million 2FA Bypass Case

For millions of Nigerians, two-factor authentication feels like the final lock on a bank account.

You enter your password. The bank sends an OTP or requests another form of authentication. Without that second factor, nobody should be able to get in.

At least, that is how it is supposed to work.

A case brought before a Lagos court by the Economic and Financial Crimes Commission (EFCC) is now drawing attention to what can happen when that additional security layer is allegedly circumvented.

On Friday, September 4, 2026, the EFCC arraigned Osaretin Osagiede before Justice Olukayode Ogunjobi of the Lagos State High Court in Ikeja.

He faces a three-count charge relating to unauthorised access to computer material and receiving alleged stolen property valued at ₦700 million.

According to the EFCC, Osagiede and another suspect, Zacharia Lorshe, who remains at large, allegedly caused the two-factor authentication system protecting Ravenpay user accounts to be bypassed between March 2025 and January 2026.

The defendants allegedly sought unauthorised access to banking data.

The EFCC also alleges that the pair dishonestly received ₦700 million belonging to Best Start Micro Finance Bank, despite having reason to believe that the money was stolen.

Osagiede pleaded not guilty.

The court ordered that he be remanded in a correctional facility and adjourned proceedings to September 16, 2026, for consideration of his bail application.

The allegations have not yet been proven at trial.

What Exactly Is Two-Factor Authentication?

Two-factor authentication, usually shortened to 2FA, requires someone attempting to access an account to provide more than one form of authentication.

Instead of relying only on a password or PIN, a banking system may require another factor such as:

  • An OTP sent to a registered phone number

  • A banking hardware token

  • A software-generated security code

  • Biometric authentication

  • Confirmation from a registered device

The purpose is simple.

If a fraudster steals your password, they should still be unable to access your account because they do not possess the second authentication factor.

That makes the allegation in the Osagiede case particularly important.

According to the charge reported by the EFCC, the attackers allegedly did not merely steal someone's password. They are accused of causing the 2FA mechanism itself to be bypassed to obtain unauthorised access.

Does This Mean Nigerian Banking 2FA Has Been Broken?

No.

And this distinction is important.

The publicly available information about the case does not explain precisely how the alleged 2FA bypass occurred.

It does not establish that every Nigerian banking application's two-factor authentication can suddenly be defeated, nor does it prove that ordinary customers' OTPs are useless.

There are many ways criminals can defeat or work around authentication systems without mathematically “breaking” 2FA itself.

For example, financial fraud can involve compromised credentials, social engineering, SIM swaps, device compromise, insider abuse or weaknesses elsewhere in a payment system.

The specific mechanism alleged in the Ravenpay case will require more evidence to emerge during investigation and trial.

What the case does show is something more uncomfortable:

2FA is an important security layer, but it should never be treated as an invincible one.

Nigeria Has a Much Bigger Digital Banking Fraud Problem

The Osagiede case did not appear in a vacuum.

According to the Nigeria Inter-Bank Settlement System (NIBSS), Nigerian financial institutions recorded approximately 67,518 reported digital-payment fraud cases in 2025.

Actual losses were estimated at ₦25.85 billion.

That was a substantial improvement from the ₦52.26 billion recorded in 2024, representing a decline of about 51%. NIBSS report

A 2026 data brief from Nigeria's National Institute for Legislative and Democratic Studies (NILDS) warned that electronic-payment fraud is becoming increasingly sophisticated and technologically enabled.

The report identified threats including:

  • Social engineering

  • SIM swaps

  • Phishing

  • Account compromises

  • Insider collusion

  • Mobile banking fraud

  • Internet banking attacks

The report is available here: https://ir.nilds.gov.ng/handle/123456789/3473

So while the number of reported cases has declined, criminals have hardly packed their laptops and chosen respectable careers.

They are adapting.

Criminals Do Not Always Need Your OTP

Many Nigerians have been trained to follow one important banking rule:

Never give anybody your OTP.

That advice remains correct.

But modern account fraud requires a wider security mindset.

A criminal may attempt to compromise the systems surrounding your authentication instead.

For example, SIM-swap fraud can allow an attacker to gain control of a victim's mobile number. Because many services use phone numbers for OTPs and account recovery, control of the SIM can potentially expose other connected accounts.

Phishing can also lead victims to voluntarily enter banking credentials into fraudulent websites designed to resemble legitimate services.

Social engineering may involve someone pretending to be:

  • A bank employee

  • A fintech support agent

  • An EFCC official

  • A telecommunications representative

  • A loan company

  • A merchant

  • A family member

The objective is usually the same: obtain enough information or access to compromise the victim.

CBN Is Already Tightening Digital Banking Security

Nigeria's banking regulator has also been strengthening security requirements around digital payments.

The Central Bank of Nigeria (CBN) introduced measures taking effect from July 1, 2026, including requirements around stronger authentication, fraud monitoring and device controls.

Among other provisions, the CBN says financial institutions should deploy real-time enterprise fraud-monitoring systems and strengthen identity verification.

Mobile banking applications are also expected to be linked to one device at a time, while activation on a new device attracts temporary transaction restrictions. CBN information.

These controls matter because banking security increasingly has to detect suspicious behaviour, not simply wait for a customer to enter the right PIN and OTP.

How Nigerian Bank Customers Can Protect Their Accounts

There is no security practice that can guarantee that an account will never be compromised.

But Nigerians can significantly reduce their exposure.

1. Never Share an OTP

No legitimate bank employee needs you to read an OTP to them over the telephone, WhatsApp or social media.

Treat OTPs like cash.

2. Protect Your SIM

Your phone number is connected to far more than telephone calls.

It may be connected to:

  • Your bank

  • Email account

  • WhatsApp

  • Social media

  • Password recovery services

If your phone suddenly loses network service unexpectedly while people around you still have service, contact your network operator.

3. Never Install Apps Sent by Supposed Bank Agents

Fraudsters may convince victims to install applications under the pretence of:

  • Fixing banking problems

  • Reversing transactions

  • Updating KYC information

  • Receiving loans

  • Verifying accounts

Use applications downloaded through official channels.

4. Keep Your Email Secure

Your email can become the back door into multiple financial accounts.

Use a strong, unique password and enable multi-factor authentication.

Do not reuse your banking password on other websites.

5. Take Unexpected Banking Notifications Seriously

If you receive an OTP, login alert, device-registration notification or password-reset message that you did not initiate, do not ignore it.

Someone may already be attempting to access your account.

6. Reduce Transaction Limits

You do not necessarily need a ₦5 million daily transfer limit because your bank is willing to give you one.

Set limits based on what you genuinely need.

A lower transaction limit can reduce potential losses if an account is compromised.

7. Keep Your Banking Device Updated

Install operating-system and banking-app updates from legitimate sources.

Avoid using modified or untrusted banking applications.

8. Monitor Your Accounts

Review transactions regularly instead of waiting for the end of the month.

Early detection can make an enormous difference in how quickly your bank can respond.

If Money Suddenly Leaves Your Account

Speed matters.

If you notice an unauthorised transfer:

Contact your bank immediately.

Ask the bank to:

  • Restrict or freeze the affected account where appropriate

  • Disable compromised digital banking access

  • Trace the transaction

  • Escalate the recipient account

  • Open a formal fraud complaint

  • Give you a complaint or reference number

Preserve:

  • SMS alerts

  • Emails

  • Screenshots

  • Transaction references

  • Account statements

  • Phone numbers

  • WhatsApp conversations

  • URLs or phishing messages

The CBN's consumer fraud guidance specifically advises victims to contact their financial institution immediately and secure compromised accounts.

CBN fraud and scam awareness:

https://www.cbn.gov.ng/supervision/cpdfraudandscam.html

Suspected financial crime can also be reported to the EFCC:

https://www.efcc.gov.ng/

The Person Behind the Transaction Matters Too

Technology is only one part of digital fraud.

Many successful financial attacks begin with human trust.

A person contacts you pretending to represent your bank. A supposed investment adviser convinces you to transfer money. Someone claims to be customer support. A fake business asks for sensitive information.

That is why verifying who you are communicating with can be just as important as securing your banking application.

Profiled Nigeria's tools are designed to help Nigerians conduct additional verification before trusting unfamiliar people or organisations online.

Conclusion

The Osaretin Osagiede ₦700 million case should not be interpreted as evidence that every Nigerian banking application's two-factor authentication has been compromised.

The case remains before the court, Osagiede has pleaded not guilty, and important technical details about the alleged breach have not yet been made public.

But the allegation matters.

It demonstrates the direction financial crime is taking in Nigeria.

As banks strengthen their security, criminals increasingly look for ways around passwords, authentication systems, identities, devices and the people using them.

NIBSS data shows that Nigeria made progress in reducing digital-payment fraud losses in 2025. Yet ₦25.85 billion in reported losses and more than 67,000 reported cases show that digital banking fraud remains a serious problem.

For Nigerians, the lesson is bigger than protecting an OTP.

Protect your phone. Secure your email. Monitor your bank account. Question unexpected requests. Verify the people you transact with. And act immediately when something looks wrong.

In the age of increasingly sophisticated financial fraud, 2FA is a security layer. Verification must become a habit.

The EFCC has arraigned Osaretin Osagiede over an alleged ₦700 million fraud involving the bypass of two-factor authentication on Ravenpay user accounts.

The ₦700 Million 2FA Bypass Case

For millions of Nigerians, two-factor authentication feels like the final lock on a bank account.

You enter your password. The bank sends an OTP or requests another form of authentication. Without that second factor, nobody should be able to get in.

At least, that is how it is supposed to work.

A case brought before a Lagos court by the Economic and Financial Crimes Commission (EFCC) is now drawing attention to what can happen when that additional security layer is allegedly circumvented.

On Friday, September 4, 2026, the EFCC arraigned Osaretin Osagiede before Justice Olukayode Ogunjobi of the Lagos State High Court in Ikeja.

He faces a three-count charge relating to unauthorised access to computer material and receiving alleged stolen property valued at ₦700 million.

According to the EFCC, Osagiede and another suspect, Zacharia Lorshe, who remains at large, allegedly caused the two-factor authentication system protecting Ravenpay user accounts to be bypassed between March 2025 and January 2026.

The defendants allegedly sought unauthorised access to banking data.

The EFCC also alleges that the pair dishonestly received ₦700 million belonging to Best Start Micro Finance Bank, despite having reason to believe that the money was stolen.

Osagiede pleaded not guilty.

The court ordered that he be remanded in a correctional facility and adjourned proceedings to September 16, 2026, for consideration of his bail application.

The allegations have not yet been proven at trial.

What Exactly Is Two-Factor Authentication?

Two-factor authentication, usually shortened to 2FA, requires someone attempting to access an account to provide more than one form of authentication.

Instead of relying only on a password or PIN, a banking system may require another factor such as:

  • An OTP sent to a registered phone number

  • A banking hardware token

  • A software-generated security code

  • Biometric authentication

  • Confirmation from a registered device

The purpose is simple.

If a fraudster steals your password, they should still be unable to access your account because they do not possess the second authentication factor.

That makes the allegation in the Osagiede case particularly important.

According to the charge reported by the EFCC, the attackers allegedly did not merely steal someone's password. They are accused of causing the 2FA mechanism itself to be bypassed to obtain unauthorised access.

Does This Mean Nigerian Banking 2FA Has Been Broken?

No.

And this distinction is important.

The publicly available information about the case does not explain precisely how the alleged 2FA bypass occurred.

It does not establish that every Nigerian banking application's two-factor authentication can suddenly be defeated, nor does it prove that ordinary customers' OTPs are useless.

There are many ways criminals can defeat or work around authentication systems without mathematically “breaking” 2FA itself.

For example, financial fraud can involve compromised credentials, social engineering, SIM swaps, device compromise, insider abuse or weaknesses elsewhere in a payment system.

The specific mechanism alleged in the Ravenpay case will require more evidence to emerge during investigation and trial.

What the case does show is something more uncomfortable:

2FA is an important security layer, but it should never be treated as an invincible one.

Nigeria Has a Much Bigger Digital Banking Fraud Problem

The Osagiede case did not appear in a vacuum.

According to the Nigeria Inter-Bank Settlement System (NIBSS), Nigerian financial institutions recorded approximately 67,518 reported digital-payment fraud cases in 2025.

Actual losses were estimated at ₦25.85 billion.

That was a substantial improvement from the ₦52.26 billion recorded in 2024, representing a decline of about 51%. NIBSS report

A 2026 data brief from Nigeria's National Institute for Legislative and Democratic Studies (NILDS) warned that electronic-payment fraud is becoming increasingly sophisticated and technologically enabled.

The report identified threats including:

  • Social engineering

  • SIM swaps

  • Phishing

  • Account compromises

  • Insider collusion

  • Mobile banking fraud

  • Internet banking attacks

The report is available here: https://ir.nilds.gov.ng/handle/123456789/3473

So while the number of reported cases has declined, criminals have hardly packed their laptops and chosen respectable careers.

They are adapting.

Criminals Do Not Always Need Your OTP

Many Nigerians have been trained to follow one important banking rule:

Never give anybody your OTP.

That advice remains correct.

But modern account fraud requires a wider security mindset.

A criminal may attempt to compromise the systems surrounding your authentication instead.

For example, SIM-swap fraud can allow an attacker to gain control of a victim's mobile number. Because many services use phone numbers for OTPs and account recovery, control of the SIM can potentially expose other connected accounts.

Phishing can also lead victims to voluntarily enter banking credentials into fraudulent websites designed to resemble legitimate services.

Social engineering may involve someone pretending to be:

  • A bank employee

  • A fintech support agent

  • An EFCC official

  • A telecommunications representative

  • A loan company

  • A merchant

  • A family member

The objective is usually the same: obtain enough information or access to compromise the victim.

CBN Is Already Tightening Digital Banking Security

Nigeria's banking regulator has also been strengthening security requirements around digital payments.

The Central Bank of Nigeria (CBN) introduced measures taking effect from July 1, 2026, including requirements around stronger authentication, fraud monitoring and device controls.

Among other provisions, the CBN says financial institutions should deploy real-time enterprise fraud-monitoring systems and strengthen identity verification.

Mobile banking applications are also expected to be linked to one device at a time, while activation on a new device attracts temporary transaction restrictions. CBN information.

These controls matter because banking security increasingly has to detect suspicious behaviour, not simply wait for a customer to enter the right PIN and OTP.

How Nigerian Bank Customers Can Protect Their Accounts

There is no security practice that can guarantee that an account will never be compromised.

But Nigerians can significantly reduce their exposure.

1. Never Share an OTP

No legitimate bank employee needs you to read an OTP to them over the telephone, WhatsApp or social media.

Treat OTPs like cash.

2. Protect Your SIM

Your phone number is connected to far more than telephone calls.

It may be connected to:

  • Your bank

  • Email account

  • WhatsApp

  • Social media

  • Password recovery services

If your phone suddenly loses network service unexpectedly while people around you still have service, contact your network operator.

3. Never Install Apps Sent by Supposed Bank Agents

Fraudsters may convince victims to install applications under the pretence of:

  • Fixing banking problems

  • Reversing transactions

  • Updating KYC information

  • Receiving loans

  • Verifying accounts

Use applications downloaded through official channels.

4. Keep Your Email Secure

Your email can become the back door into multiple financial accounts.

Use a strong, unique password and enable multi-factor authentication.

Do not reuse your banking password on other websites.

5. Take Unexpected Banking Notifications Seriously

If you receive an OTP, login alert, device-registration notification or password-reset message that you did not initiate, do not ignore it.

Someone may already be attempting to access your account.

6. Reduce Transaction Limits

You do not necessarily need a ₦5 million daily transfer limit because your bank is willing to give you one.

Set limits based on what you genuinely need.

A lower transaction limit can reduce potential losses if an account is compromised.

7. Keep Your Banking Device Updated

Install operating-system and banking-app updates from legitimate sources.

Avoid using modified or untrusted banking applications.

8. Monitor Your Accounts

Review transactions regularly instead of waiting for the end of the month.

Early detection can make an enormous difference in how quickly your bank can respond.

If Money Suddenly Leaves Your Account

Speed matters.

If you notice an unauthorised transfer:

Contact your bank immediately.

Ask the bank to:

  • Restrict or freeze the affected account where appropriate

  • Disable compromised digital banking access

  • Trace the transaction

  • Escalate the recipient account

  • Open a formal fraud complaint

  • Give you a complaint or reference number

Preserve:

  • SMS alerts

  • Emails

  • Screenshots

  • Transaction references

  • Account statements

  • Phone numbers

  • WhatsApp conversations

  • URLs or phishing messages

The CBN's consumer fraud guidance specifically advises victims to contact their financial institution immediately and secure compromised accounts.

CBN fraud and scam awareness:

https://www.cbn.gov.ng/supervision/cpdfraudandscam.html

Suspected financial crime can also be reported to the EFCC:

https://www.efcc.gov.ng/

The Person Behind the Transaction Matters Too

Technology is only one part of digital fraud.

Many successful financial attacks begin with human trust.

A person contacts you pretending to represent your bank. A supposed investment adviser convinces you to transfer money. Someone claims to be customer support. A fake business asks for sensitive information.

That is why verifying who you are communicating with can be just as important as securing your banking application.

Profiled Nigeria's tools are designed to help Nigerians conduct additional verification before trusting unfamiliar people or organisations online.

Conclusion

The Osaretin Osagiede ₦700 million case should not be interpreted as evidence that every Nigerian banking application's two-factor authentication has been compromised.

The case remains before the court, Osagiede has pleaded not guilty, and important technical details about the alleged breach have not yet been made public.

But the allegation matters.

It demonstrates the direction financial crime is taking in Nigeria.

As banks strengthen their security, criminals increasingly look for ways around passwords, authentication systems, identities, devices and the people using them.

NIBSS data shows that Nigeria made progress in reducing digital-payment fraud losses in 2025. Yet ₦25.85 billion in reported losses and more than 67,000 reported cases show that digital banking fraud remains a serious problem.

For Nigerians, the lesson is bigger than protecting an OTP.

Protect your phone. Secure your email. Monitor your bank account. Question unexpected requests. Verify the people you transact with. And act immediately when something looks wrong.

In the age of increasingly sophisticated financial fraud, 2FA is a security layer. Verification must become a habit.

YOUR FIRST STEP

Learn More About Our Mission

My job is to make sure you leave the first call with a clear, actionable plan.

Confident professional woman representing verified identity, authenticity, and digital trust with Profiled Nigeria.

Favour Ajayi

Client Success Manager

YOUR FIRST STEP

Learn More About Our Mission

My job is to make sure you leave the first call with a clear, actionable plan.

Confident professional woman representing verified identity, authenticity, and digital trust with Profiled Nigeria.

Favour Ajayi

Client Success Manager

YOUR FIRST STEP

Learn More About Our Mission

My job is to make sure you leave the first call with a clear, actionable plan.

Confident professional woman representing verified identity, authenticity, and digital trust with Profiled Nigeria.

Favour Ajayi

Client Success Manager

13

Ready to start?

Get in touch

Whether you have questions or just want to explore options, we’re here.

By submitting, you agree to our Terms and Privacy Policy.

We are Based in Lagos, Nigeria.

Profiled logo - Nigeria’s trusted digital verification ecosystem for people, businesses, and products.
f
f
b
b
i
i
g
g
b
b
e
e
x
x
B
B
a
a
c
c
k
k
 
 
t
t
o
o
 
 
t
t
o
o
p
p
Soft abstract gradient with white light transitioning into purple, blue, and orange hues

13

Ready to start?

Get in touch

Whether you have questions or just want to explore options, we’re here.

By submitting, you agree to our Terms and Privacy Policy.

We are Based in Lagos, Nigeria.

Profiled logo - Nigeria’s trusted digital verification ecosystem for people, businesses, and products.
f
f
b
b
i
i
g
g
b
b
e
e
x
x
B
B
a
a
c
c
k
k
 
 
t
t
o
o
 
 
t
t
o
o
p
p
Soft abstract gradient with white light transitioning into purple, blue, and orange hues

13

Ready to start?

Get in touch

Whether you have questions or just want to explore options, we’re here.

By submitting, you agree to our Terms and Privacy Policy.

We are Based in Lagos, Nigeria.

Profiled logo - Nigeria’s trusted digital verification ecosystem for people, businesses, and products.
f
f
b
b
i
i
g
g
b
b
e
e
x
x
B
B
a
a
c
c
k
k
 
 
t
t
o
o
 
 
t
t
o
o
p
p
Soft abstract gradient with white light transitioning into purple, blue, and orange hues