September 8, 2026
September 8, 2026
EFCC’s ₦700 Million Case Exposes Nigeria’s 2FA Banking Risk
Two-factor authentication is supposed to stop criminals even when passwords are compromised. But a new ₦700 million EFCC case involving an alleged 2FA bypass shows why Nigerian bank customers cannot assume an OTP or banking app alone makes their money untouchable.
Two-factor authentication is supposed to stop criminals even when passwords are compromised. But a new ₦700 million EFCC case involving an alleged 2FA bypass shows why Nigerian bank customers cannot assume an OTP or banking app alone makes their money untouchable.
The EFCC has arraigned Osaretin Osagiede over an alleged ₦700 million fraud involving the bypass of two-factor authentication on Ravenpay user accounts.
The ₦700 Million 2FA Bypass Case
For millions of Nigerians, two-factor authentication feels like the final lock on a bank account.
You enter your password. The bank sends an OTP or requests another form of authentication. Without that second factor, nobody should be able to get in.
At least, that is how it is supposed to work.
A case brought before a Lagos court by the Economic and Financial Crimes Commission (EFCC) is now drawing attention to what can happen when that additional security layer is allegedly circumvented.
On Friday, September 4, 2026, the EFCC arraigned Osaretin Osagiede before Justice Olukayode Ogunjobi of the Lagos State High Court in Ikeja.
He faces a three-count charge relating to unauthorised access to computer material and receiving alleged stolen property valued at ₦700 million.
According to the EFCC, Osagiede and another suspect, Zacharia Lorshe, who remains at large, allegedly caused the two-factor authentication system protecting Ravenpay user accounts to be bypassed between March 2025 and January 2026.
The defendants allegedly sought unauthorised access to banking data.
The EFCC also alleges that the pair dishonestly received ₦700 million belonging to Best Start Micro Finance Bank, despite having reason to believe that the money was stolen.
Osagiede pleaded not guilty.
The court ordered that he be remanded in a correctional facility and adjourned proceedings to September 16, 2026, for consideration of his bail application.
The allegations have not yet been proven at trial.
What Exactly Is Two-Factor Authentication?
Two-factor authentication, usually shortened to 2FA, requires someone attempting to access an account to provide more than one form of authentication.
Instead of relying only on a password or PIN, a banking system may require another factor such as:
An OTP sent to a registered phone number
A banking hardware token
A software-generated security code
Biometric authentication
Confirmation from a registered device
The purpose is simple.
If a fraudster steals your password, they should still be unable to access your account because they do not possess the second authentication factor.
That makes the allegation in the Osagiede case particularly important.
According to the charge reported by the EFCC, the attackers allegedly did not merely steal someone's password. They are accused of causing the 2FA mechanism itself to be bypassed to obtain unauthorised access.
Does This Mean Nigerian Banking 2FA Has Been Broken?
No.
And this distinction is important.
The publicly available information about the case does not explain precisely how the alleged 2FA bypass occurred.
It does not establish that every Nigerian banking application's two-factor authentication can suddenly be defeated, nor does it prove that ordinary customers' OTPs are useless.
There are many ways criminals can defeat or work around authentication systems without mathematically “breaking” 2FA itself.
For example, financial fraud can involve compromised credentials, social engineering, SIM swaps, device compromise, insider abuse or weaknesses elsewhere in a payment system.
The specific mechanism alleged in the Ravenpay case will require more evidence to emerge during investigation and trial.
What the case does show is something more uncomfortable:
2FA is an important security layer, but it should never be treated as an invincible one.
Nigeria Has a Much Bigger Digital Banking Fraud Problem
The Osagiede case did not appear in a vacuum.
According to the Nigeria Inter-Bank Settlement System (NIBSS), Nigerian financial institutions recorded approximately 67,518 reported digital-payment fraud cases in 2025.
Actual losses were estimated at ₦25.85 billion.
That was a substantial improvement from the ₦52.26 billion recorded in 2024, representing a decline of about 51%. NIBSS report
A 2026 data brief from Nigeria's National Institute for Legislative and Democratic Studies (NILDS) warned that electronic-payment fraud is becoming increasingly sophisticated and technologically enabled.
The report identified threats including:
Social engineering
SIM swaps
Phishing
Account compromises
Insider collusion
Mobile banking fraud
Internet banking attacks
The report is available here: https://ir.nilds.gov.ng/handle/123456789/3473
So while the number of reported cases has declined, criminals have hardly packed their laptops and chosen respectable careers.
They are adapting.
Criminals Do Not Always Need Your OTP
Many Nigerians have been trained to follow one important banking rule:
Never give anybody your OTP.
That advice remains correct.
But modern account fraud requires a wider security mindset.
A criminal may attempt to compromise the systems surrounding your authentication instead.
For example, SIM-swap fraud can allow an attacker to gain control of a victim's mobile number. Because many services use phone numbers for OTPs and account recovery, control of the SIM can potentially expose other connected accounts.
Phishing can also lead victims to voluntarily enter banking credentials into fraudulent websites designed to resemble legitimate services.
Social engineering may involve someone pretending to be:
A bank employee
A fintech support agent
An EFCC official
A telecommunications representative
A loan company
A merchant
A family member
The objective is usually the same: obtain enough information or access to compromise the victim.
CBN Is Already Tightening Digital Banking Security
Nigeria's banking regulator has also been strengthening security requirements around digital payments.
The Central Bank of Nigeria (CBN) introduced measures taking effect from July 1, 2026, including requirements around stronger authentication, fraud monitoring and device controls.
Among other provisions, the CBN says financial institutions should deploy real-time enterprise fraud-monitoring systems and strengthen identity verification.
Mobile banking applications are also expected to be linked to one device at a time, while activation on a new device attracts temporary transaction restrictions. CBN information.
These controls matter because banking security increasingly has to detect suspicious behaviour, not simply wait for a customer to enter the right PIN and OTP.
How Nigerian Bank Customers Can Protect Their Accounts
There is no security practice that can guarantee that an account will never be compromised.
But Nigerians can significantly reduce their exposure.
1. Never Share an OTP
No legitimate bank employee needs you to read an OTP to them over the telephone, WhatsApp or social media.
Treat OTPs like cash.
2. Protect Your SIM
Your phone number is connected to far more than telephone calls.
It may be connected to:
Your bank
Email account
WhatsApp
Social media
Password recovery services
If your phone suddenly loses network service unexpectedly while people around you still have service, contact your network operator.
3. Never Install Apps Sent by Supposed Bank Agents
Fraudsters may convince victims to install applications under the pretence of:
Fixing banking problems
Reversing transactions
Updating KYC information
Receiving loans
Verifying accounts
Use applications downloaded through official channels.
4. Keep Your Email Secure
Your email can become the back door into multiple financial accounts.
Use a strong, unique password and enable multi-factor authentication.
Do not reuse your banking password on other websites.
5. Take Unexpected Banking Notifications Seriously
If you receive an OTP, login alert, device-registration notification or password-reset message that you did not initiate, do not ignore it.
Someone may already be attempting to access your account.
6. Reduce Transaction Limits
You do not necessarily need a ₦5 million daily transfer limit because your bank is willing to give you one.
Set limits based on what you genuinely need.
A lower transaction limit can reduce potential losses if an account is compromised.
7. Keep Your Banking Device Updated
Install operating-system and banking-app updates from legitimate sources.
Avoid using modified or untrusted banking applications.
8. Monitor Your Accounts
Review transactions regularly instead of waiting for the end of the month.
Early detection can make an enormous difference in how quickly your bank can respond.
If Money Suddenly Leaves Your Account
Speed matters.
If you notice an unauthorised transfer:
Contact your bank immediately.
Ask the bank to:
Restrict or freeze the affected account where appropriate
Disable compromised digital banking access
Trace the transaction
Escalate the recipient account
Open a formal fraud complaint
Give you a complaint or reference number
Preserve:
SMS alerts
Emails
Screenshots
Transaction references
Account statements
Phone numbers
WhatsApp conversations
URLs or phishing messages
The CBN's consumer fraud guidance specifically advises victims to contact their financial institution immediately and secure compromised accounts.
CBN fraud and scam awareness:
https://www.cbn.gov.ng/supervision/cpdfraudandscam.html
Suspected financial crime can also be reported to the EFCC:
The Person Behind the Transaction Matters Too
Technology is only one part of digital fraud.
Many successful financial attacks begin with human trust.
A person contacts you pretending to represent your bank. A supposed investment adviser convinces you to transfer money. Someone claims to be customer support. A fake business asks for sensitive information.
That is why verifying who you are communicating with can be just as important as securing your banking application.
Profiled Nigeria's tools are designed to help Nigerians conduct additional verification before trusting unfamiliar people or organisations online.
Conclusion
The Osaretin Osagiede ₦700 million case should not be interpreted as evidence that every Nigerian banking application's two-factor authentication has been compromised.
The case remains before the court, Osagiede has pleaded not guilty, and important technical details about the alleged breach have not yet been made public.
But the allegation matters.
It demonstrates the direction financial crime is taking in Nigeria.
As banks strengthen their security, criminals increasingly look for ways around passwords, authentication systems, identities, devices and the people using them.
NIBSS data shows that Nigeria made progress in reducing digital-payment fraud losses in 2025. Yet ₦25.85 billion in reported losses and more than 67,000 reported cases show that digital banking fraud remains a serious problem.
For Nigerians, the lesson is bigger than protecting an OTP.
Protect your phone. Secure your email. Monitor your bank account. Question unexpected requests. Verify the people you transact with. And act immediately when something looks wrong.
In the age of increasingly sophisticated financial fraud, 2FA is a security layer. Verification must become a habit.
The EFCC has arraigned Osaretin Osagiede over an alleged ₦700 million fraud involving the bypass of two-factor authentication on Ravenpay user accounts.
The ₦700 Million 2FA Bypass Case
For millions of Nigerians, two-factor authentication feels like the final lock on a bank account.
You enter your password. The bank sends an OTP or requests another form of authentication. Without that second factor, nobody should be able to get in.
At least, that is how it is supposed to work.
A case brought before a Lagos court by the Economic and Financial Crimes Commission (EFCC) is now drawing attention to what can happen when that additional security layer is allegedly circumvented.
On Friday, September 4, 2026, the EFCC arraigned Osaretin Osagiede before Justice Olukayode Ogunjobi of the Lagos State High Court in Ikeja.
He faces a three-count charge relating to unauthorised access to computer material and receiving alleged stolen property valued at ₦700 million.
According to the EFCC, Osagiede and another suspect, Zacharia Lorshe, who remains at large, allegedly caused the two-factor authentication system protecting Ravenpay user accounts to be bypassed between March 2025 and January 2026.
The defendants allegedly sought unauthorised access to banking data.
The EFCC also alleges that the pair dishonestly received ₦700 million belonging to Best Start Micro Finance Bank, despite having reason to believe that the money was stolen.
Osagiede pleaded not guilty.
The court ordered that he be remanded in a correctional facility and adjourned proceedings to September 16, 2026, for consideration of his bail application.
The allegations have not yet been proven at trial.
What Exactly Is Two-Factor Authentication?
Two-factor authentication, usually shortened to 2FA, requires someone attempting to access an account to provide more than one form of authentication.
Instead of relying only on a password or PIN, a banking system may require another factor such as:
An OTP sent to a registered phone number
A banking hardware token
A software-generated security code
Biometric authentication
Confirmation from a registered device
The purpose is simple.
If a fraudster steals your password, they should still be unable to access your account because they do not possess the second authentication factor.
That makes the allegation in the Osagiede case particularly important.
According to the charge reported by the EFCC, the attackers allegedly did not merely steal someone's password. They are accused of causing the 2FA mechanism itself to be bypassed to obtain unauthorised access.
Does This Mean Nigerian Banking 2FA Has Been Broken?
No.
And this distinction is important.
The publicly available information about the case does not explain precisely how the alleged 2FA bypass occurred.
It does not establish that every Nigerian banking application's two-factor authentication can suddenly be defeated, nor does it prove that ordinary customers' OTPs are useless.
There are many ways criminals can defeat or work around authentication systems without mathematically “breaking” 2FA itself.
For example, financial fraud can involve compromised credentials, social engineering, SIM swaps, device compromise, insider abuse or weaknesses elsewhere in a payment system.
The specific mechanism alleged in the Ravenpay case will require more evidence to emerge during investigation and trial.
What the case does show is something more uncomfortable:
2FA is an important security layer, but it should never be treated as an invincible one.
Nigeria Has a Much Bigger Digital Banking Fraud Problem
The Osagiede case did not appear in a vacuum.
According to the Nigeria Inter-Bank Settlement System (NIBSS), Nigerian financial institutions recorded approximately 67,518 reported digital-payment fraud cases in 2025.
Actual losses were estimated at ₦25.85 billion.
That was a substantial improvement from the ₦52.26 billion recorded in 2024, representing a decline of about 51%. NIBSS report
A 2026 data brief from Nigeria's National Institute for Legislative and Democratic Studies (NILDS) warned that electronic-payment fraud is becoming increasingly sophisticated and technologically enabled.
The report identified threats including:
Social engineering
SIM swaps
Phishing
Account compromises
Insider collusion
Mobile banking fraud
Internet banking attacks
The report is available here: https://ir.nilds.gov.ng/handle/123456789/3473
So while the number of reported cases has declined, criminals have hardly packed their laptops and chosen respectable careers.
They are adapting.
Criminals Do Not Always Need Your OTP
Many Nigerians have been trained to follow one important banking rule:
Never give anybody your OTP.
That advice remains correct.
But modern account fraud requires a wider security mindset.
A criminal may attempt to compromise the systems surrounding your authentication instead.
For example, SIM-swap fraud can allow an attacker to gain control of a victim's mobile number. Because many services use phone numbers for OTPs and account recovery, control of the SIM can potentially expose other connected accounts.
Phishing can also lead victims to voluntarily enter banking credentials into fraudulent websites designed to resemble legitimate services.
Social engineering may involve someone pretending to be:
A bank employee
A fintech support agent
An EFCC official
A telecommunications representative
A loan company
A merchant
A family member
The objective is usually the same: obtain enough information or access to compromise the victim.
CBN Is Already Tightening Digital Banking Security
Nigeria's banking regulator has also been strengthening security requirements around digital payments.
The Central Bank of Nigeria (CBN) introduced measures taking effect from July 1, 2026, including requirements around stronger authentication, fraud monitoring and device controls.
Among other provisions, the CBN says financial institutions should deploy real-time enterprise fraud-monitoring systems and strengthen identity verification.
Mobile banking applications are also expected to be linked to one device at a time, while activation on a new device attracts temporary transaction restrictions. CBN information.
These controls matter because banking security increasingly has to detect suspicious behaviour, not simply wait for a customer to enter the right PIN and OTP.
How Nigerian Bank Customers Can Protect Their Accounts
There is no security practice that can guarantee that an account will never be compromised.
But Nigerians can significantly reduce their exposure.
1. Never Share an OTP
No legitimate bank employee needs you to read an OTP to them over the telephone, WhatsApp or social media.
Treat OTPs like cash.
2. Protect Your SIM
Your phone number is connected to far more than telephone calls.
It may be connected to:
Your bank
Email account
WhatsApp
Social media
Password recovery services
If your phone suddenly loses network service unexpectedly while people around you still have service, contact your network operator.
3. Never Install Apps Sent by Supposed Bank Agents
Fraudsters may convince victims to install applications under the pretence of:
Fixing banking problems
Reversing transactions
Updating KYC information
Receiving loans
Verifying accounts
Use applications downloaded through official channels.
4. Keep Your Email Secure
Your email can become the back door into multiple financial accounts.
Use a strong, unique password and enable multi-factor authentication.
Do not reuse your banking password on other websites.
5. Take Unexpected Banking Notifications Seriously
If you receive an OTP, login alert, device-registration notification or password-reset message that you did not initiate, do not ignore it.
Someone may already be attempting to access your account.
6. Reduce Transaction Limits
You do not necessarily need a ₦5 million daily transfer limit because your bank is willing to give you one.
Set limits based on what you genuinely need.
A lower transaction limit can reduce potential losses if an account is compromised.
7. Keep Your Banking Device Updated
Install operating-system and banking-app updates from legitimate sources.
Avoid using modified or untrusted banking applications.
8. Monitor Your Accounts
Review transactions regularly instead of waiting for the end of the month.
Early detection can make an enormous difference in how quickly your bank can respond.
If Money Suddenly Leaves Your Account
Speed matters.
If you notice an unauthorised transfer:
Contact your bank immediately.
Ask the bank to:
Restrict or freeze the affected account where appropriate
Disable compromised digital banking access
Trace the transaction
Escalate the recipient account
Open a formal fraud complaint
Give you a complaint or reference number
Preserve:
SMS alerts
Emails
Screenshots
Transaction references
Account statements
Phone numbers
WhatsApp conversations
URLs or phishing messages
The CBN's consumer fraud guidance specifically advises victims to contact their financial institution immediately and secure compromised accounts.
CBN fraud and scam awareness:
https://www.cbn.gov.ng/supervision/cpdfraudandscam.html
Suspected financial crime can also be reported to the EFCC:
The Person Behind the Transaction Matters Too
Technology is only one part of digital fraud.
Many successful financial attacks begin with human trust.
A person contacts you pretending to represent your bank. A supposed investment adviser convinces you to transfer money. Someone claims to be customer support. A fake business asks for sensitive information.
That is why verifying who you are communicating with can be just as important as securing your banking application.
Profiled Nigeria's tools are designed to help Nigerians conduct additional verification before trusting unfamiliar people or organisations online.
Conclusion
The Osaretin Osagiede ₦700 million case should not be interpreted as evidence that every Nigerian banking application's two-factor authentication has been compromised.
The case remains before the court, Osagiede has pleaded not guilty, and important technical details about the alleged breach have not yet been made public.
But the allegation matters.
It demonstrates the direction financial crime is taking in Nigeria.
As banks strengthen their security, criminals increasingly look for ways around passwords, authentication systems, identities, devices and the people using them.
NIBSS data shows that Nigeria made progress in reducing digital-payment fraud losses in 2025. Yet ₦25.85 billion in reported losses and more than 67,000 reported cases show that digital banking fraud remains a serious problem.
For Nigerians, the lesson is bigger than protecting an OTP.
Protect your phone. Secure your email. Monitor your bank account. Question unexpected requests. Verify the people you transact with. And act immediately when something looks wrong.
In the age of increasingly sophisticated financial fraud, 2FA is a security layer. Verification must become a habit.










