When money is transferred from a bank account without the customer’s authority, one of the most important questions is:

Who is responsible for the loss?

Is it the bank that processed the transaction? Is it the customer whose account was compromised? Is it the person who received the money? Or can more than one party be legally responsible?

There is no single answer for every unauthorised bank transfer.

Liability depends on how the transaction occurred, the conduct of the customer, the bank’s systems and procedures, the identity and conduct of the recipient, and the applicable legal and regulatory framework.

The Central Bank of Nigeria’s Consumer Protection Framework places obligations on financial institutions to safeguard customer assets against fraud and unauthorised access, while also placing responsibilities on customers to protect their information and promptly report suspected compromise.

This article explains how responsibility is determined when an unauthorised transfer occurs.

What Is an Unauthorised Bank Transfer?

An unauthorised bank transfer occurs where money is transferred from a customer’s account without the customer’s authority.

Examples include:

  • A fraudster transferring money through mobile banking.
  • An unauthorised internet banking transfer.
  • A third party using a compromised banking application.
  • An unauthorised USSD transfer.
  • A transfer initiated using stolen banking credentials.
  • A fraudulent transfer resulting from a compromised device.
  • A transaction carried out after a customer’s account information has been unlawfully obtained.

The circumstances surrounding the transaction determine the appropriate legal response.

Is the Bank Automatically Liable?

No.

A bank is not automatically liable simply because a customer disputes a transaction.

At the same time, a bank cannot automatically escape liability simply by showing that the transaction passed its authentication process.

The CBN’s Consumer Protection Framework requires financial institutions to establish policies and controls to safeguard consumer assets against fraud, including appropriate access controls, security measures, transaction monitoring and periodic assessment of security risks.

Therefore, the question is not merely:

“Was the transaction successful?”

The more important question is:

“Under the circumstances, did the bank discharge its legal, contractual and regulatory obligations?”

When Can a Bank Be Liable?

A bank can potentially be liable where the evidence establishes that the bank breached a duty owed to the customer and that breach caused or contributed to the customer’s loss.

Circumstances that can become relevant include:

Failure to maintain adequate security

Financial institutions are expected to maintain appropriate controls to protect customer assets and information.

The CBN Consumer Protection Framework expressly requires financial institutions to establish policies and controls to safeguard consumer assets against fraud.

Failure to respond appropriately to suspicious activity

Where a transaction displays unusual characteristics and the bank’s systems or procedures ought reasonably to have detected or addressed the activity, that can become relevant to liability.

Failure to act after receiving a fraud report

The bank’s conduct after the customer reports the transaction can also become relevant.

For example, if a customer promptly reports an unauthorised transfer and the bank has an opportunity to take appropriate action but fails to do so, the circumstances should be examined carefully.

System or security failure

Where the evidence establishes that the transaction resulted from a failure in the bank’s systems or security controls, the bank’s responsibility becomes an important issue.

Who is liable for an unauthorised bank transfer in Nigeria

Does Using an OTP Automatically Make the Customer Liable?

No.

The fact that an OTP was used does not, by itself, conclusively determine liability.

The bank may rely on the OTP as evidence that the transaction was authenticated.

However, the circumstances in which the OTP was obtained and used remain relevant.

For example, there is a substantial difference between:

  • A customer deliberately authorising a transfer; and
  • A fraudster obtaining an OTP through a compromised system or deceptive circumstances.

The complete transaction history should therefore be examined.

What If the Customer Disclosed the OTP?

This is more complicated.

Suppose a fraudster impersonates a bank employee and persuades a customer to disclose an OTP.

The fraudster then transfers ₦3 million from the customer’s account.

The bank may argue that the customer’s own conduct enabled the transaction.

That argument can be important.

The customer’s duty to protect confidential banking information is recognised within the CBN’s consumer-protection framework. Customers are expected to protect their information and promptly notify their financial institution when they observe a compromise.

However, whether the customer’s conduct completely eliminates the bank’s responsibility depends on the facts.

The bank’s own security systems, fraud controls and response to the incident remain relevant.

What If the Customer Did Not Disclose Any OTP or PIN?

This can significantly strengthen the customer’s position, depending on the evidence.

If the customer did not disclose security credentials and the transaction nevertheless occurred, the investigation should establish how the transaction was authenticated and executed.

Relevant questions include:

  • Was the customer’s device compromised?
  • Was the account accessed from an unusual device?
  • Was the transaction consistent with the customer’s normal activity?
  • Were there unusual login attempts?
  • Did the bank’s fraud-monitoring system detect anything unusual?
  • Was a new device registered?
  • Was the customer’s SIM compromised?
  • Were there previous suspicious transactions?

The answers can help determine where responsibility lies.

What If the Customer’s Phone Was Stolen?

A stolen phone does not automatically make the customer liable for every transaction subsequently carried out from the device.

The circumstances must be examined.

For example, it matters whether:

  • The phone was protected by a password or biometric security.
  • The banking application required additional authentication.
  • The customer’s SIM was also compromised.
  • The banking credentials were stored on the device.
  • The customer promptly notified the bank and telecommunications provider.
  • Transactions occurred before or after the bank was notified.

The bank’s security obligations and the customer’s conduct must both be considered.

What If the Fraudster Used the Customer’s Mobile Banking App?

The use of the customer’s mobile banking application does not automatically establish that the customer authorised the transaction.

The relevant question is how the fraudster obtained access and whether the bank’s authentication and security systems operated as required.

This is particularly important in cases involving compromised devices, SIM-related fraud, malware, phishing or social engineering.

The CBN has continued to strengthen payment-system security. In 2026, it introduced additional measures concerning instant payments, including requirements for stronger authentication, transaction limits, real-time fraud monitoring and restrictions around mobile-banking device linking.

These developments reinforce the importance of examining the bank’s systems and procedures rather than treating authentication as the end of the inquiry.

What If the Customer Was Deceived Into Making the Transfer?

This is commonly referred to as social engineering fraud.

For example, a fraudster may pretend to be:

  • A bank employee.
  • A police officer.
  • A friend.
  • A business partner.
  • A telecommunications employee.
  • A government official.

The fraudster may convince the victim to transfer money voluntarily.

This situation is different from a transaction where a fraudster independently accesses the customer’s account.

The customer physically initiated the transaction, but did so because of deception.

The legal consequences therefore require careful examination of the particular circumstances.

Who Is Liable When the Customer Personally Initiated the Transfer?

There is no automatic rule that the customer bears the entire loss simply because the customer pressed the transfer button.

However, the customer’s conduct becomes particularly important.

For example, if a customer knowingly transfers money to a person, the transaction is ordinarily authorised.

If the customer was deceived into transferring the money, the circumstances are different.

The question then becomes whether there are legal grounds for recovery against the recipient, the fraudster, the bank or another relevant party.

The CBN has also developed draft guidelines specifically addressing authorised push payment fraud, demonstrating the regulatory importance of distinguishing fraudulent transactions that customers technically authorised from transactions initiated without their participation.

Where dealing with such a case, however, the particular applicable rules should be verified before relying on any draft instrument as binding law.

Who is liable for an unauthorised bank transfer in Nigeria

Can the Person Who Received the Money Be Liable?

Yes.

Where a person receives money through fraud or without lawful entitlement, that person’s potential liability should be considered.

The recipient may be:

  • The fraudster.
  • A person acting for the fraudster.
  • An innocent recipient.
  • A person whose account was used as a money mule.
  • Another person who subsequently received the funds.

The legal position can differ substantially depending on what the recipient knew and did with the money.

What Is a Money Mule?

A money mule is a person whose account is used to receive and move funds obtained through fraud.

Sometimes the account holder knowingly participates.

In other cases, the account holder may have been deceived into allowing the account to be used.

The fact that money entered a person’s account does not automatically establish that the account holder was the person who committed the original fraud.

However, once the person becomes aware that the funds are connected to fraud, their subsequent conduct can become important.

Can an Innocent Recipient Be Made to Refund the Money?

Where money is mistakenly or fraudulently transferred into your account, the proper course is to notify your bank immediately and, where appropriate, return the money through the bank’s authorised process.

An innocent recipient should not treat the money as their own merely because it has been credited to their account.

For example, if ₦2 million is mistakenly transferred into your account by another customer, you should notify your bank and allow the bank to investigate and facilitate the appropriate reversal or return of the funds. You should not withdraw or spend the money.

Similarly, where you receive money that appears to be connected with fraud, you should immediately notify your bank and cooperate with any investigation.

The position is different where a recipient knows that the money does not belong to them but deliberately retains, withdraws, transfers or spends it. In such circumstances, the recipient’s conduct can give rise to legal consequences and potential recovery proceedings.

Therefore, the fact that money was credited to a person’s account does not by itself establish that the recipient committed the original fraud or is automatically liable for it. The circumstances in which the money was received and the recipient’s conduct after becoming aware of the error or fraud are important.

Can More Than One Person Be Liable?

Yes.

There are circumstances in which claims may properly involve more than one party.

For example, a case might involve:

  • The bank that maintained the victim’s account.
  • Another financial institution that maintained the recipient’s account.
  • The person who fraudulently obtained the money.
  • A person who knowingly assisted in moving the funds.

However, the mere fact that several parties were involved in the transaction does not mean they are all automatically liable.

Each party’s legal responsibility must be established.

What If the Bank Says the Customer Was Negligent?

This is a common defence.

The bank may argue that the customer:

  • Shared an OTP.
  • Disclosed a PIN.
  • Disclosed a password.
  • Clicked a fraudulent link.
  • Installed malicious software.
  • Allowed another person access to the banking application.
  • Failed to report the compromise promptly.

These allegations can affect the outcome.

The CBN’s Consumer Protection Framework expressly places responsibilities on customers, including taking immediate steps to notify financial institutions of observed compromise and lodging complaints promptly and honestly.

However, customer negligence does not automatically resolve every question concerning the bank’s own obligations.

The evidence must be considered as a whole.

What If the Bank’s System Was Compromised?

If the evidence shows that the bank’s system or security infrastructure was compromised and that this caused the customer’s loss, the bank’s potential liability becomes a serious issue.

Financial institutions are required to maintain security controls and safeguards against fraud and unauthorised access.

The precise legal claim will depend on the nature of the failure and the relationship between the bank and customer.

What If the Bank Detected the Fraud but Failed to Act?

This can be particularly significant.

Suppose the bank’s systems detect unusual activity but the bank does not take appropriate action, and further transactions occur.

The question then becomes whether the bank had a duty to respond in the circumstances and whether its failure caused or increased the customer’s loss.

The evidence surrounding the alerts, monitoring systems and bank’s internal response can therefore become important.

Does the Bank Have a Duty to Monitor Transactions for Fraud?

Banks and other financial institutions operate within a regulatory framework that includes fraud prevention and transaction-security obligations.

The CBN Consumer Protection Framework requires financial institutions to implement fraud controls, transaction-monitoring mechanisms and security measures.

The CBN has also established the Nigeria Electronic Fraud Forum to coordinate efforts among stakeholders to address electronic fraud in the financial sector.

The existence of these obligations does not mean that a bank is an insurer against every fraudulent transaction.

Rather, the question in a particular dispute is whether the bank complied with the duties applicable to the transaction.

What Should You Do If You Are the Victim?

If you discover an unauthorised transfer, act immediately.

Step 1: Contact your bank

Report the transaction through the bank’s official fraud-reporting channels.

Step 2: Secure your account

Change compromised credentials and request appropriate restrictions where necessary.

Step 3: Obtain a complaint reference

Make the complaint formally and obtain the bank’s tracking number.

Step 4: Preserve evidence

Keep transaction alerts, statements, screenshots and correspondence.

Step 5: Report suspected criminal conduct

Where appropriate, make a report to the relevant law-enforcement authority.

Step 6: Escalate the complaint

Where the bank does not satisfactorily resolve the matter, use the applicable CBN complaints process. The CBN’s complaints portal instructs customers to first lodge the complaint with their financial institution and obtain a complaint reference/tracking number before escalation.

Step 7: Obtain legal advice

If substantial funds are involved or recovery is disputed, a lawyer can assess the evidence and determine the appropriate legal strategy.

What Evidence Can Help Establish Liability?

Evidence can include:

  • Bank statements.
  • Transaction alerts.
  • Transaction reference numbers.
  • Account-access records.
  • Device information.
  • Login records.
  • OTP records.
  • Communications with the bank.
  • Fraud-reporting records.
  • Recipient account information.
  • Police or EFCC reports.
  • Screenshots.
  • Emails.
  • Text messages.
  • WhatsApp messages.
  • Other electronic evidence.

The particular evidence required depends on the claim.

Can You Sue the Bank and the Recipient Together?

Possibly.

Whether it is appropriate to sue both depends on the facts and the causes of action available against each party.

It is not enough to add every person or institution connected with a transaction as a defendant.

The claimant should identify the parties against whom there is a proper legal basis for relief.

This is one of the reasons a proper investigation should precede litigation.

What Remedies Can a Victim Seek?

Depending on the circumstances, a victim may pursue:

  • Recovery of the principal sum.
  • Interest where legally recoverable.
  • Damages where legally sustainable.
  • Declaratory relief.
  • Appropriate interim or preservation orders.
  • Orders directed at recovery of identifiable funds.
  • Other reliefs arising from the applicable cause of action.

The appropriate remedy depends on the facts and the legal basis of the claim.

Does the CBN Determine Who Is Legally Liable?

The CBN provides a regulatory complaints mechanism and can intervene in complaints against financial institutions within its regulatory purview.

The CBN has reported resolving thousands of customer complaints and facilitating refunds in disputes with financial service providers.

However, regulatory complaint resolution and judicial determination of liability are not the same thing.

Where a dispute requires a binding judicial determination, court proceedings may be necessary.

How Do You Determine Who Is Actually Liable?

The best approach is to reconstruct the transaction from beginning to end.

Ask:

1. Who initiated the transaction?

Was it the customer, a fraudster or another person?

2. How was authentication achieved?

Was a PIN, OTP, biometric authentication, password or another mechanism used?

3. How did the fraudster obtain access?

Was there phishing, SIM compromise, malware, credential theft or another method?

4. What did the customer do?

Did the customer disclose confidential information or otherwise contribute to the transaction?

5. What did the bank’s systems do?

Were there warnings, unusual activity indicators or security controls that should have been triggered?

6. When was the bank notified?

Prompt reporting can be important.

7. What happened to the money?

Was it withdrawn, transferred or converted into another asset?

8. Who received the funds?

Can the recipient be identified?

The answers to these questions help determine the appropriate parties and remedies.

Do Not Assume That Every Unauthorised Transaction Is a Bank’s Liability

This is perhaps the most important point.

A bank is not an insurer against every form of fraud.

For example, where a customer voluntarily transfers money to a fraudster after being deceived, the legal position requires a different analysis from a case where a fraudster independently accesses the customer’s account.

Similarly, where a customer knowingly discloses confidential credentials in circumstances that materially contribute to the loss, that conduct can affect the customer’s claim.

On the other hand, where the bank’s own security failure, negligence or breach of applicable obligations contributed to the loss, the bank’s responsibility must be properly examined.

Liability follows the facts.

Conclusion

So, who is liable for an unauthorised bank transfer in Nigeria?

There is no universal answer.

Depending on the circumstances, responsibility can potentially rest with the bank, the fraudster, the recipient of the funds, the customer or more than one party.

The key issues are how the transaction occurred, whether the customer authorised or contributed to it, whether the bank complied with its obligations, how promptly the fraud was reported and what happened to the money afterwards.

The CBN’s regulatory framework places obligations on financial institutions to protect customer assets and maintain appropriate fraud controls, while customers also have responsibilities to protect their information and report suspected compromise promptly.

If you have suffered an unauthorised transfer, do not assume that the bank is automatically liable—or that the bank’s refusal to refund automatically ends the matter.

Preserve the evidence, report the transaction immediately and obtain legal advice where substantial funds are involved or liability is disputed.

Lexforte Attorneys can assist with banking disputes, unauthorised transactions, fraud-related recovery and civil proceedings against the appropriate parties.