Connect with us

E-Financial

Digital “Pickpockets” Compromise Over a Million Banking Accounts – Kaspersky

Published

on

Kindly share this post

More than one million online banking accounts were compromised by infostealers last year, as financial cyberthreats shifted toward credential theft and data reuse.

Digital "Pickpockets" Compromise Over a Million Banking Accounts - Kaspersky

Pic credit…cybelangel.com

Attackers are moving away from traditional PC banking malware and increasingly relying on social engineering and dark web marketplaces, while mobile financial malware continues to grow.

Detailed information on current financial cyberthreat trends is available in Kaspersky’s new report.

These digital “pickpockets” often exfiltrate data and remove themselves within seconds, making them difficult to detect.

They are a primary source of initial access for ransomware and identity theft

Traditional financial phishing has not gone away. Pages that mimicked e-shops dominated the financial phishing landscape (48.5% in 2025, up 10.3% from 2024), followed by banks (26.1% in 2025, down by 16.5% from 2024) and payment systems (25.5% in 2025, up by 6.2% from 2024). The decline in bank phishing may suggest that these services are becoming increasingly difficult to successfully impersonate, and fraudsters are turning to easier ways to access users’ finances.

Advertisement

Attackers are adapting campaigns to regional digital habits. In the Middle East, financial phishing is overwhelmingly concentrated on e-commerce (85.8%), indicating a heavy reliance on online retail lures, whereas in Africa bank-related phishing leads (53.75%), which may indicate that user account security there is still insufficient. Latin America shows a more balanced distribution but with a higher share of e-commerce and bank targeting, while APAC and Europe display a more even spread across all three categories, pointing to diversified attack strategies.

In 2025, the decline in users affected by financial PC malware continued as users increasingly rely on mobile devices to manage their finances. Contrary to PC banking malware, mobile banker attacks grew by 1.5 times in 2025 compared to the previous year.

Complementing traditional financial malware, infostealers played a significant role in enabling financial crime both on PCs and mobile devices by harvesting login credentials, cookies, bank card numbers, crypto wallet seed phrases, and autofill data from browsers and applications, which attackers then used for account takeovers or direct banking fraud. Kaspersky data pointed to a surge in infostealer detections (up by 59% globally, 53% in Africa and 26% in the Middle East, on PCs from 2024 to 2025), fueling credential-based attacks.

According to Kaspersky Digital Footprint Intelligence (DFI), in 2025 over one million online banking accounts served by the world’s 100 largest banks fell victim to infostealers: credentials for these accounts were being freely shared on the dark web. The countries with the highest median number of compromised accounts per bank were India, Spain, and Brazil.

74% of payment cards that were compromised by infostealer malware, published on dark web resources and identified by Kaspersky DFI team in 2025, remained valid as of March 2026. This means that attackers could still use cards that had been stolen months or even years prior.

Advertisement

“The dark web has become a central hub for financial cybercrime. Stolen credentials and bank cards that have been harvested by infostealers are aggregated, repackaged, and sold there, while phishing kits targeted at users of financial products are offered as ready-to-use services.

This creates a self-sustaining ecosystem where data theft and fraud operations reinforce each other, making attacks scalable and easy to carry out by fraudsters with minimal experience. Breaking this cycle requires proactive threat intelligence on the part of organisations, and increased awareness and scrutiny from individual users,” comments Polina Tretyak, Kaspersky Digital Footprint Intelligence analyst.

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Financial

NDIC Begins Payment to Depositors of 46 Failed Microfinance Banks

Published

on

Kindly share this post

Nigeria Deposit Insurance Corporation (NDIC) has begun paying insured deposits to customers of the 46 recently failed microfinance banks.

NDIC Begins Payment to Depositors of 46 Failed Microfinance Banks

Mr Thompson Sunday, managing director and chief executive, NDIC, disclosed this in an interview with the News Agency of Nigeria (NAN) in Abuja.

The interview took place on the sidelines of the International Association of Deposit Insurers Africa Regional Committee meeting.

Sunday said the corporation was using the Nigeria Inter-Bank Settlement System (NIBBS) and customers’ Bank Verification Numbers (BVN) for the payments.

He said the NDIC had traced depositors’ alternative bank accounts and credited them directly without requiring physical visits.

Advertisement

He advised depositors without BVNs to visit the nearest NDIC zonal office for verification and payment processing

“The CBN revoked the licences of the 46 microfinance banks on July 1, 2026,” he said.

He said the NDIC automatically became the provisional liquidator after the revocation, in line with the law.

Sunday said the corporation had commenced payment of the insured maximum deposit of N2 million to eligible customers.

He explained that further payments would depend on the recovery of the failed banks’ assets and outstanding debts.

Advertisement

He said proceeds realised from recoveries would be distributed as liquidation dividends to eligible depositors.

Sunday cited Heritage Bank, Aso Savings and Union Homes as examples of the NDIC’s prompt reimbursement efforts.

He said insured depositors of Heritage Bank were paid within four days of the revocation of its licence.

He added that customers of Aso Savings and Union Homes received payments within 72 hours.

“The law allows us 30 days, but we are working to surpass our previous records,” he said.

Advertisement

The Central Bank of Nigeria (CBN) revoked the banks’ licences for failing to meet regulatory requirements for continued operations.

The apex bank said the action was aimed at protecting depositors, strengthening financial stability and ensuring regulatory compliance.

Kindly share this post
Continue Reading

E-Financial

FG Says Rumours, Fear, Can Crash Banks

Published

on

Kindly share this post

Mr Taiwo Oyedele, minister of Finance and Coordinating Minister of the Economy, has warned that fear, rumours and misinformation could trigger instability in the banking sector if not properly managed.

FG Says Rumours, Fear, Can Crash Banks

Mr Taiwo Oyedele, minister of Finance and Coordinating Minister of the Economy

Oyedele gave the warning in Abuja at the 2026 International Association of Deposit Insurers (IADI) Africa Regional Committee (ARC) Annual Meeting and Workshop, with the theme: “Safeguarding Stability: Public Awareness and Crisis Readiness for a Stronger Future.”

The minister said public confidence remained the foundation of every stable financial system, stressing that panic triggered by false information could create liquidity challenges even for financially sound institutions.

According to him, “there can be no economic growth without financial system stability, and there can be no financial stability without public trust.”

He explained that in the digital age, misinformation could spread rapidly across social media platforms, causing depositors to react out of fear.

“Public trust is fragile. In the digital age, rumours and misinformation can spread across social platforms in seconds, creating liquidity shocks even for solvent institutions,” Oyedele said.

Advertisement

He stressed that building public awareness should not be viewed as a public relations activity, but as a key risk management strategy capable of protecting depositors and strengthening the financial system.

Oyedele noted that deposit insurance had evolved beyond a mechanism for handling bank failures, describing it as a strategic tool for promoting confidence and economic stability.

He said effective crisis preparedness required clear frameworks, communication channels, simulation exercises and coordination among financial sector regulators before emergencies occur.

“Preparedness is not an event, it is a culture,” he said, adding that the strongest crisis response was one that prevented panic from occurring in the first place.

Highlighting Nigeria’s financial sector reforms, the minister said the country’s banking recapitalisation exercise, concluded in March 2026, strengthened the resilience of banks.

Advertisement

He disclosed that 33 out of Nigeria’s 37 banks met the new capital requirements, raising a combined N4.65 trillion in fresh capital, with over 70 per cent sourced from domestic investors.

Oyedele said a better-capitalised banking system would be better positioned to absorb shocks, sustain lending and reduce pressure on the deposit insurance fund.

He also pointed to Nigeria’s removal from the Financial Action Task Force (FATF) grey list in October 2025 as another milestone that strengthened confidence in the country’s financial system.

Also speaking, Mr Olayemi Cardoso, governor, Central Bank of Nigeria (CBN), said public awareness and crisis preparedness were central to maintaining financial stability.

Represented by Solaja Olayemi, director, Other Financial Institutions Supervision Department represented, Cardoso said financial systems globally were undergoing rapid transformation due to technological innovation, digital finance, changing consumer behaviour and increasing market interconnectedness.

Advertisement

According to him, while these developments create opportunities, they also introduce new risks that require stronger cooperation among financial safety-net institutions.

The CBN boss warned that misinformation could spread quickly through digital channels, amplifying depositor reactions and creating potential threats to financial stability.

He added that institutions must continuously strengthen crisis management frameworks, operational resilience and coordination mechanisms to respond effectively to emerging challenges.

The apex bank governor also highlighted the impact of Nigeria’s banking sector recapitalisation policy, saying stronger capital buffers would reduce the likelihood of bank failures and reinforce depositor confidence.

“No single institution can safeguard financial stability in isolation. It is through the coherence and complementarity of this institutional relationship that Nigeria’s financial safety net derives its strength,” he noted.

Advertisement

Earlier, Mr Thompson Sunday, managing director/chief executive officer, Nigeria Deposit Insurance Corporation (NDIC),  said confidence remained the most valuable asset in any financial system.

The NDIC boss said trust could take years to build but could be lost quickly if stakeholders perceived uncertainty or instability. He said deposit insurers must ensure that the public understands and trusts existing protection frameworks during both normal periods and times of crisis.

He noted that the 2023 global banking turmoil highlighted the need for institutions to invest in crisis simulation exercises, contingency planning and effective communication strategies.

According to him, the NDIC has continued to strengthen its operational readiness through improved depositor reimbursement systems, public awareness initiatives and enhanced crisis management capabilities.

 

Advertisement

Kindly share this post
Continue Reading

E-Financial

EU Debunks Fake Compensation Scheme Targeting West African Bank Customers

Published

on

Kindly share this post

European Union (EU) has warned the public against a fraudulent document circulating online which falsely claims that the bloc, in collaboration with the World Bank, is offering compensation to individuals whose funds are allegedly trapped in banks and financial institutions across West Africa.

EU Debunks Fake Compensation Scheme Targeting West African Bank Customers

In a statement issued on Wednesday in Abuja, the EU Delegation to Nigeria and ECOWAS described the purported compensation programme as a scam, stressing that neither the European Union nor the World Bank is involved in any such initiative.

The fake document, fraudulently attributed to Thérèse Blanchet, secretary-general of the Council of the European Union, claimed that a special EU-World Bank recovery programme has been established to compensate citizens of Europe and other countries whose legally transferred funds were allegedly withheld by banks in the region.

It also falsely stated that the EU Ambassador to Nigeria and ECOWAS has been mandated to supervise the compensation exercise and directs potential claimants to contact him for processing.

However, the EU categorically dismissed the claims, describing every aspect of the document as fabricated.

Advertisement

“The document in its entirety is a scam. The information and claims contained therein are false. The European Union is neither aware of any such bogus programme nor part of it,” the Delegation stated.

The EU further disclosed that the email addresses and telephone numbers listed in the fraudulent document, purportedly belonging to Ms. Blanchet and Ambassador Gautier Mignot, EU Ambassador to Nigeria and ECOWAS, , are fake and are being used by fraudsters to deceive unsuspecting victims.

The Delegation urged members of the public to ignore the fraudulent claims and avoid engaging with anyone promoting the scheme.

It emphasized that all official announcements from the European Union Delegation to Nigeria and ECOWAS are published exclusively through its official website and verified social media platforms.

The warning comes amid increasing cases of cyber-enabled financial fraud in which criminal syndicates impersonate international organisations, government institutions and senior officials to lure victims into paying fictitious processing fees or divulging sensitive personal and financial information.

Advertisement

The EU reiterated its commitment to combating fraud and misinformation while urging citizens to remain vigilant against scams exploiting the names and identities of reputable international institutions.

Kindly share this post
Continue Reading

Trending