When money is transferred from a bank account without the customer’s authority, one of the most important questions is: Who is responsible for the loss? Is it the bank that processed the transaction? Is it the customer whose account was compromised? Is it the person who received the money? Or can more than one party be legally responsible? There is no single answer for every unauthorised bank transfer. Liability depends on how the transaction occurred, the conduct of the customer, the bank’s systems and procedures, the identity and conduct of the recipient, and the applicable legal and regulatory framework. The Central Bank of Nigeria’s Consumer Protection Framework places obligations on financial institutions to safeguard customer assets against fraud and unauthorised access, while also placing responsibilities on customers to protect their information and promptly report suspected compromise. This article explains how responsibility is determined when an unauthorised transfer occurs. What Is an Unauthorised Bank Transfer? An unauthorised bank transfer occurs where money is transferred from a customer’s account without the customer’s authority. Examples include: A fraudster transferring money through mobile banking. An unauthorised internet banking transfer. A third party using a compromised banking application. An unauthorised USSD transfer. A transfer initiated using stolen banking credentials. A fraudulent transfer resulting from a compromised device. A transaction carried out after a customer’s account information has been unlawfully obtained. The circumstances surrounding the transaction determine the appropriate legal response. Is the Bank Automatically Liable? No. A bank is not automatically liable simply because a customer disputes a transaction. At the same time, a bank cannot automatically escape liability simply by showing that the transaction passed its authentication process. The CBN’s Consumer Protection Framework requires financial institutions to establish policies and controls to safeguard consumer assets against fraud, including appropriate access controls, security measures, transaction monitoring and periodic assessment of security risks. Therefore, the question is not merely: “Was the transaction successful?” The more important question is: “Under the circumstances, did the bank discharge its legal, contractual and regulatory obligations?” When Can a Bank Be Liable? A bank can potentially be liable where the evidence establishes that the bank breached a duty owed to the customer and that breach caused or contributed to the customer’s loss. Circumstances that can become relevant include: Failure to maintain adequate security Financial institutions are expected to maintain appropriate controls to protect customer assets and information. The CBN Consumer Protection Framework expressly requires financial institutions to establish policies and controls to safeguard consumer assets against fraud. Failure to respond appropriately to suspicious activity Where a transaction displays unusual characteristics and the bank’s systems or procedures ought reasonably to have detected or addressed the activity, that can become relevant to liability. Failure to act after receiving a fraud report The bank’s conduct after the customer reports the transaction can also become relevant. For example, if a customer promptly reports an unauthorised transfer and the bank has an opportunity to take appropriate action but fails to do so, the circumstances should be examined carefully. System or security failure Where the evidence establishes that the transaction resulted from a failure in the bank’s systems or security controls, the bank’s responsibility becomes an important issue. Does Using an OTP Automatically Make the Customer Liable? No. The fact that an OTP was used does not, by itself, conclusively determine liability. The bank may rely on the OTP as evidence that the transaction was authenticated. However, the circumstances in which the OTP was obtained and used remain relevant. For example, there is a substantial difference between: A customer deliberately authorising a transfer; and A fraudster obtaining an OTP through a compromised system or deceptive circumstances. The complete transaction history should therefore be examined. What If the Customer Disclosed the OTP? This is more complicated. Suppose a fraudster impersonates a bank employee and persuades a customer to disclose an OTP. The fraudster then transfers ₦3 million from the customer’s account. The bank may argue that the customer’s own conduct enabled the transaction. That argument can be important. The customer’s duty to protect confidential banking information is recognised within the CBN’s consumer-protection framework. Customers are expected to protect their information and promptly notify their financial institution when they observe a compromise. However, whether the customer’s conduct completely eliminates the bank’s responsibility depends on the facts. The bank’s own security systems, fraud controls and response to the incident remain relevant. What If the Customer Did Not Disclose Any OTP or PIN? This can significantly strengthen the customer’s position, depending on the evidence. If the customer did not disclose security credentials and the transaction nevertheless occurred, the investigation should establish how the transaction was authenticated and executed. Relevant questions include: Was the customer’s device compromised? Was the account accessed from an unusual device? Was the transaction consistent with the customer’s normal activity? Were there unusual login attempts? Did the bank’s fraud-monitoring system detect anything unusual? Was a new device registered? Was the customer’s SIM compromised? Were there previous suspicious transactions? The answers can help determine where responsibility lies. What If the Customer’s Phone Was Stolen? A stolen phone does not automatically make the customer liable for every transaction subsequently carried out from the device. The circumstances must be examined. For example, it matters whether: The phone was protected by a password or biometric security. The banking application required additional authentication. The customer’s SIM was also compromised. The banking credentials were stored on the device. The customer promptly notified the bank and telecommunications provider. Transactions occurred before or after the bank was notified. The bank’s security obligations and the customer’s conduct must both be considered. What If the Fraudster Used the Customer’s Mobile Banking App? The use of the customer’s mobile banking application does not automatically establish that the customer authorised the transaction. The relevant question is how the fraudster obtained access and whether the bank’s authentication and security systems operated as required. This is particularly important in cases involving compromised devices, SIM-related fraud, malware, phishing or social engineering. The
How to Recover Money Lost Through Bank Fraud in Nigeria
Losing money through bank fraud can be devastating, particularly when a substantial amount is involved. You may discover that money has been transferred from your account without your authorisation, sent to an unknown account, withdrawn through an ATM, or used for an online transaction you did not make. The immediate question is usually: Can the money be recovered? In many cases, there are steps you can take to pursue recovery. However, recovery is not automatic, and the appropriate approach depends on how the fraud occurred, how quickly it was reported, whether the recipient can be identified and the evidence available. The most important rule is simple: Act immediately. The Central Bank of Nigeria advises customers who suspect fraud or a compromise to contact their financial institution immediately and report the matter to the appropriate authorities. What Is Bank Fraud? Bank fraud generally involves the use of deception, unauthorised access or other fraudulent means to obtain money or financial benefits through a bank or other financial institution. Examples include: Unauthorised transfers from a bank account. Fraudulent ATM withdrawals. Unauthorised card transactions. Mobile banking fraud. Internet banking fraud. Phishing scams. Social engineering scams. SIM-related compromise. Fraudulent direct debits. Fraudulent use of banking credentials. Deception that causes a customer to transfer money to a fraudster. The legal and recovery options differ depending on the particular circumstances. Can Money Lost Through Bank Fraud Be Recovered? Yes, money lost through bank fraud can be recovered in appropriate circumstances. Recovery can occur through several routes, depending on the facts. These include: Immediate intervention by the bank. Internal bank complaints and investigation. Regulatory intervention through the CBN. Criminal investigation by appropriate law-enforcement agencies. Recovery from the recipient of the funds. Civil proceedings. Appropriate court orders to preserve or recover funds. However, there is no guarantee that every fraudulent transaction will be reversed. The speed with which the victim acts can be particularly important. What Should You Do Immediately After Discovering the Fraud? 1. Contact Your Bank Immediately Do not wait until the next business day if you discover the fraud outside normal banking hours. Use the bank’s official emergency or fraud-reporting channels and inform the bank that the transaction is disputed. Ask the bank to: Restrict further transactions where necessary. Secure the account. Investigate the transaction. Attempt to recall or recover the funds where possible. Place appropriate restrictions on the recipient account where the applicable process permits. Give you a complaint or tracking reference. The CBN specifically advises customers who suspect fraud to contact their financial institution immediately. 2. Change Your Banking Credentials If your account or banking credentials have been compromised, change your relevant passwords and security credentials immediately. You should also secure the device used for mobile or internet banking. Do not continue using compromised credentials simply because the fraudulent transaction has already occurred. 3. Preserve the Evidence Do not delete transaction alerts, SMS messages, emails or screenshots. Preserve: Bank statements. Transaction alerts. Transaction reference numbers. Screenshots. Emails. SMS messages. WhatsApp or other communications with the fraudster. Recipient account details. The bank’s correspondence. Your complaint reference. Any police or EFCC report. Evidence of the amount lost. This evidence can become important if the matter proceeds to regulatory investigation or litigation. Can the Bank Reverse the Transaction? It can, depending on the circumstances and the stage at which the transaction is reported. The bank can investigate the transaction and take appropriate steps within the banking system where recovery or reversal is possible. This is why immediate reporting is important. However, you should not assume that contacting the bank automatically guarantees a refund. The bank will investigate matters such as how the transaction was initiated, whether it was authenticated, whether the customer’s credentials were compromised and whether the transaction can be traced. What If the Money Has Already Been Transferred to Another Account? This does not necessarily mean that recovery is impossible. The recipient account details can provide an important starting point for tracing the funds. Depending on the circumstances, the relevant financial institutions and authorities can investigate the transaction trail. If the funds remain identifiable or traceable, appropriate recovery measures can be considered. Where the recipient has transferred the money to another account, the investigation may become more complicated, but that does not necessarily end the possibility of recovery. Can the Recipient’s Bank Freeze the Money? The recipient’s bank can take appropriate action within its regulatory and operational framework when notified of a suspected fraudulent transaction. However, a victim should not assume that merely reporting the matter guarantees that the recipient’s account will be frozen. The bank may need appropriate documentation, internal verification, instructions from competent authorities or other lawful grounds before taking particular action. This is one reason why prompt reporting is important. What If the Fraudster Has Already Withdrawn the Money? Recovery can become more difficult once the money has been withdrawn. However, withdrawal does not necessarily make recovery impossible. The investigation can consider: Who withdrew the money. Where the withdrawal occurred. The account into which the money was initially transferred. Whether CCTV or other records exist. Whether the funds were transferred elsewhere. Whether the recipient can be identified. Whether the recipient has identifiable assets. The available evidence will determine the appropriate recovery strategy. Should You Report Bank Fraud to the Police? Yes, where the circumstances disclose suspected criminal conduct, you should make an appropriate report to law enforcement. The CBN advises victims of fraud to report suspected fraud and scams to relevant authorities, including the Nigerian Police Force and the EFCC. A report can assist with investigation and identification of the persons involved. However, a criminal complaint and civil recovery are not the same thing. Reporting the fraud does not automatically put the money back into your account. Where recovery is required, additional legal steps may be necessary. Can the EFCC Help Recover Money Lost Through Fraud? The EFCC is one of the agencies that can investigate economic and financial crimes within its statutory mandate. Where the circumstances fall within the agency’s
What to Do When a Bank Refuses to Reverse an Unauthorised Transaction in Nigeria
You check your bank account and discover that ₦500,000 has been transferred without your authorisation. You immediately contact your bank, report the transaction and ask for your money to be returned. Then the bank tells you: “The transaction was successful.” Or: “You authorised the transaction.” Or simply: “Our investigation shows that the transaction was valid.” What should you do next? A bank’s refusal to reverse an unauthorised transaction does not necessarily mean that you have no further remedy. Nigerian bank customers have access to internal complaint mechanisms, regulatory escalation and, where appropriate, legal remedies. The important thing is to act systematically and preserve your evidence. First, Understand Why the Bank Refused the Reversal Before deciding what to do next, obtain the bank’s position in writing. The bank may argue that: The transaction was properly authenticated. Your PIN, password, OTP or other credentials were used. You disclosed your banking credentials. The transaction originated from your registered device. The transaction was authorised by you. The bank’s investigation did not establish a system failure. The recipient has already withdrawn or transferred the funds. Do not rely solely on a verbal explanation from a customer-service representative. Ask the bank to provide its response formally and retain it. Does the Bank Have a Right to Reject Your Complaint? A bank is entitled to investigate a disputed transaction and determine whether it is liable. However, a customer also has a right to have a complaint properly considered. The Central Bank of Nigeria states that bank customers have a right to a complaints-management system through which they can seek redress. Customers also have a right to be kept informed about the resolution process and the basis of the bank’s decision. Where a customer is dissatisfied, the CBN states that the customer has a right of review by the bank, the CBN or the courts. Therefore, a bank’s rejection of your complaint is not necessarily the end of the matter. What Should You Do After the Bank Rejects Your Complaint? If the bank has refused to reverse the transaction, take the following steps. 1. Request the Bank’s Final Position in Writing Ask the bank to provide a written explanation of why it rejected your complaint. Your request should identify: The disputed transaction. The date and amount. The transaction reference. Your complaint reference number. The reason given for rejecting your complaint. The action you want the bank to take. Keep a copy of the correspondence. 2. Ask for the Complaint Tracking Number Make sure you have the bank’s complaint or tracking reference. The CBN’s current complaints process requires customers to first lodge their complaint with the financial institution and obtain a complaint reference/tracking number. This number becomes important if you later escalate the complaint. 3. Preserve All Evidence Keep all documents and communications relating to the transaction. These can include: Bank statements. Transaction alerts. SMS messages. Emails. Screenshots. Transaction references. The recipient’s account details. Your complaint to the bank. The bank’s response. Communications with the suspected fraudster. Police or other law-enforcement reports. Do not delete or alter potentially relevant electronic evidence. Can You Escalate the Complaint to the CBN? Yes. If the bank fails to resolve the complaint within the applicable period, you can escalate the matter to the Consumer Protection Department of the Central Bank of Nigeria. The CBN’s official guidance states that customers should first complain to their financial institution. Where the complaint remains unresolved within the applicable timeline, the customer can escalate it to the CBN. The CBN’s current complaints portal also requires the customer to first lodge the complaint with the financial institution and obtain a tracking number before using the escalation process. How Long Should You Wait Before Escalating to the CBN? This is an area where you should be careful about relying on outdated information. Older CBN guidance refers to a two-week period for unresolved complaints, while more recent CBN materials refer to the timelines stipulated under the applicable Consumer Protection Regulations. The safest approach is to lodge the complaint formally with the bank, obtain the tracking number and follow the current CBN escalation process applicable to your complaint. Do not simply send a complaint to the CBN without first complaining to your bank. What Should You Include in a CBN Complaint? Your complaint should clearly explain: Your name and contact details. The name of the bank. The disputed transaction. The date and amount involved. Your account details, without disclosing your PIN or password. What happened. When you discovered the transaction. The complaint you made to the bank. The bank’s response. The resolution you are requesting. Supporting documents. The CBN specifically advises complainants not to include sensitive credentials such as PINs and passwords in their complaint. Can the CBN Order the Bank to Refund Your Money? The CBN has a consumer-protection and complaints-resolution role in relation to financial institutions under its regulatory purview. Its Consumer Protection Framework requires financial institutions to have customer compensation policies addressing categories including unauthorised or erroneous debits and financial loss resulting from staff negligence or fraudulent activities. However, a CBN complaint should not be treated as an automatic guarantee that the customer will receive a refund. The regulator will consider the complaint, the bank’s response and the available evidence. Where the dispute involves issues that require judicial determination, court proceedings may become necessary. What If the Bank Says You Authorised the Transaction? This is one of the most important situations to address. The bank may argue that the transaction was authorised because: An OTP was entered. The customer’s PIN was used. The transaction came from the customer’s device. The customer’s password was used. The transaction passed the bank’s authentication process. But the existence of authentication does not necessarily answer every question concerning liability. The circumstances in which the credentials were obtained and used, the security systems involved, the customer’s conduct and the bank’s own obligations can all be relevant. For example, a customer may have been deceived through phishing, social engineering or another form of fraud. The