Home ยป Inside the NCBA Bank security collapse that let fraud run wild for a week
Editor's Picks

Inside the NCBA Bank security collapse that let fraud run wild for a week

The recent exposure of a major security breach at NCBA Bank, as detailed by Superb Tips Kenya Analysts, has raised serious questions about the bank’s internal safeguards.

The case involves a consultancy employee who was granted live backend access and allegedly exploited this privilege to steal millions, with the breach going undetected for around eight days.

This incident highlights a significant failure in monitoring and access control, exposing a dangerous gap in the bank’s security protocols.

The situation began on June 6, 2025, when NCBA Bank officially gave a consultant from Ronford Digital Limited, Evans Nandwa, live backend privileges to perform system maintenance for its Rwanda subsidiary.

According to court documents from the DCI Banking Fraud Investigation Unit, the employee manipulated the core application code just three minutes after receiving access.

He specifically targeted the mobile integration logic connected to the MTN mobile money network in Rwanda.

The manipulated code was designed to bypass normal validation checks for a specific set of 70 ghost accounts.

Whenever a withdrawal request came from one of these accounts, the system would skip checking the balance and automatically send a fake “Success” signal to the telecom partner.

This meant that real money was paid out from the bank’s float into these ghost accounts, even when they had no funds. By restricting the loophole to these 70 accounts, the fraudsters ensured that ordinary customers would not accidentally discover the glitch and raise an alarm.

For nearly a week, from June 6 to June 14, this exploit ran quietly in the background. Everything looked normal on the surface to NCBA Bank because the core systems continued to report standard operational metrics.

The fraud was completely invisible to the daily operational dashboards, as it was hidden deep inside the database queries.

The bank only realized it had been shortchanged when its technical risk team performed a routine end-of-week settlement and reconciliation audit on June 14.

The bank’s systems cross-reference what its internal database says was withdrawn with what the telecom partner (MTN Rwanda) actually paid out. Normally, these figures match exactly. However, on this day, the automated script flagged a massive deficit of 57.5 million shillings from 260 transactions involving the ghost accounts.

While MTN Rwanda had successfully paid out the cash, NCBA’s internal records showed no corresponding debits or even valid account holders for those transactions.

The money had simply vanished through “ghost” approvals. No security alarms went off, and no error logs were generated, making it look like normal banking activity to the automated oversight systems.

Once the reconciliation script threw a hard error, the bank’s risk team knew this was not a simple glitch. They immediately revoked all third-party access credentials and ran a forensic comparison to see exactly what code had changed since the maintenance window.

The system logs pointed directly to the unauthorized code deployment by the consultant. The bank then called in the DCI Banking Fraud Investigation Unit.

Following the forensic audit, detectives tracked down and arrested the employee. He was later arraigned in court. This case shows how granting live access without strict, real-time monitoring can have disastrous consequences, and how a lack of detection for over a week allowed a massive theft to occur right under the bank’s nose.