Equity Bank is facing serious questions over customer data and internal controls after a police investigation linked one of its tellers to a syndicate accused of targeting the bank accounts of recently deceased customers.
The case exposes how an employee with legitimate access to sensitive banking information could allegedly use that access to help criminals steal millions of shillings from grieving families.
The matter came to light in early 2021 when Alex Ngata noticed that his late father’s phone had lost network connection.
He went to a Safaricom shop and replaced the SIM card. What followed raised immediate concerns. Old text messages began appearing on the phone, revealing transactions involving large amounts of money from his father’s bank accounts.
Ngata contacted the banks where his father held accounts, including Equity Bank. His inquiries showed that about Sh2.8 million had already been transferred and sent to a single mobile number.
The discovery came at a painful time for the family, which was already dealing with the death of their father.
Investigators soon discovered that the mobile number receiving the money was registered to a man who had already died months earlier.
This raised questions about who was controlling the number and how the criminals had obtained enough information to access the accounts.
Detectives from the DCI Crime Research and Intelligence Bureau followed the digital trail and uncovered a suspected connection inside the banking system.
Their investigation pointed to Equity Bank teller Eutycus Mutembei, whose login details showed that he had accessed information belonging to customers who had recently died.
According to the investigation, Mutembei had no official reason to view the particular accounts.
However, the information he allegedly accessed could provide criminals with details needed to identify vulnerable accounts.
Members of the suspected syndicate could then use SIM-swap tactics to take control of phone numbers, receive banking verification messages and move money from the accounts.
The alleged operation was particularly disturbing because the suspects were not simply waiting for random victims. Investigators found that the group followed death notices published in newspapers.
They allegedly used information surrounding funerals and burials to identify people who had recently died and whose accounts could potentially be targeted.
Once the suspects had information from inside the bank, the next stage became easier. The criminals could allegedly obtain control of the deceased person’s phone number and use it to access mobile banking services.
For families, the theft could remain unnoticed until they checked the accounts after the burial arrangements had been completed.
Detectives later arrested Mutembei and other alleged members of the group. Police also recovered 39 illegally registered SIM cards from the vehicle in which they were travelling.
The recovery added to the investigators’ case that the group had access to multiple phone lines that could be used in fraudulent activities.
The case raises a difficult question for banks. Customer information is among the most sensitive assets held by a financial institution.
Banks invest heavily in digital security, passwords and authentication systems, but those protections can become less effective when an authorised employee deliberately misuses access.In this case, the bank’s digital records reportedly helped investigators trace the teller’s activity.
That is an important part of the story, but it also raises another concern. If the suspicious access could be identified after an investigation, why was it not stopped before money was stolen?
Customers should not have to discover that their savings have disappeared before suspicious activity receives attention.
Internal monitoring should be strong enough to flag unusual access to accounts, particularly when an employee repeatedly checks information belonging to recently deceased customers without a clear business reason.
The alleged targeting of grieving families makes the case even more troubling. Relatives dealing with a death are often focused on funeral arrangements and family responsibilities.
They may not immediately think about checking bank accounts or monitoring mobile banking activity. That period of vulnerability can create an opportunity for criminals.
For Equity Bank, the issue is therefore bigger than the actions of one employee. The bank has built a large customer base by convincing ordinary Kenyans that their savings are safe within the formal banking system.
That trust carries a responsibility to ensure that employees cannot misuse private information without being detected quickly.
The allegations should also serve as a warning to the wider banking sector. Insider threats can be just as serious as attacks coming from outside.
A criminal sitting far away from a bank may struggle to identify a suitable target, but an employee with access to customer information can potentially provide the missing link.
The responsibility now lies with financial institutions to make internal controls stronger, monitor employee access more closely and respond quickly when unusual behaviour is detected. Customers deserve to know that their personal and financial information is being treated with the same seriousness as the money held in their accounts.
The Sh2.8 million allegedly taken from Ngata’s late father’s accounts is more than a figure in a police investigation. It represents money that a family believed was protected by the banking system.
The case is a reminder that technology alone cannot guarantee security. Behind every secure banking system are people with access to sensitive information, and when that access is abused, the consequences can be severe.











Add Comment