It started as a normal day. Customers walked into the bank, tellers processed transactions, and managers supervised them. No alarms, no warnings. Everything looked fine.
But deep in the bank’s core system, something was happening. Certain accounts were quietly losing money. Small amounts at first. Nothing that would trigger an alert. Just a few debts here and there. Enough to go unnoticed.
By the time someone raised a red flag, it was too late.
The mystery of the disappearing money
The first real clue appeared on June 12, 2019. A customer walked into the Branch, confused. His account balance didn’t add up. He was sure he hadn’t withdrawn anything. Yet, the system showed several authorized transfers and a small balance.
On June 12, 2019, more customers came forward. Their accounts had been debited, and the money was transferred to other accounts. But the transfers were authorized. The system showed no hacking or external breach. Every transaction had the necessary approvals. The bank first checked the CCTV footage to check whether the customers had withdrawn the money through the ATMs. They had not. Money had been transferred to mobile money from their bank accounts and withdrawn at the agent points.
When the bank’s security manager was finally alerted, the money was gone. A forensic audit followed, exposing security loopholes that had been exploited for days before anyone noticed. Summit Consulting Ltd came in to determine who did what, when, why, and how. What we found was interesting.
The inside game
This was no ordinary fraud. It was clean. Precise. Almost surgical. Someone on the inside had planned this, knowing exactly how to move the money without raising suspicion.
The transfers targeted specific accounts. Not just random accounts, but dormant ones. Accounts where customers didn’t check balances often. Others belonged to people who had large deposits but rarely withdrew.
How did the fraudsters know which accounts to hit? That was the first big question.
A deep dive into the system showed suspicious logins by an IT staff member, Suspect 1. The logs suggested he had accessed the databases, searching for certain accounts. There were traces of remote access to the core banking system and mobile banking systems using IDs that could be associated with Suspect 1. The pattern was clear. The fraudsters wanted accounts with money but without frequent activity.
Once the accounts were identified, the real operation began.
A perfect crime almost
Money was moved in multiple transactions, all seemingly legitimate. Transfers were approved from inside the bank. The amounts were kept just low enough to avoid suspicion. No single transfer exceeded the threshold that would trigger automatic fraud detection.
The destination of the stolen money? That’s where Suspect 2, the admin manager, came in.
Certain accounts received the transferred money. These accounts belonged to third-party individuals (existing customers) who had no idea their accounts were being used. But once the money landed there, it didn’t stay long. Within minutes, mobile money transfers were initiated. The funds disappeared, broken down into smaller transactions, and sent to various numbers.
Here’s the problem: To withdraw money via mobile money, someone had to initiate the transfer from inside the bank to several fictitious mobile accounts that do not belong to the customers. At the time, the bank system would allow the transfer of money from a bank account to a mobile phone number, other than the registered one on the account, without the need for a one-time password, OTP.
That’s where Suspect 3, the teller, came in.
The teller’s role
Not every teller had access to mobile money withdrawals. But Suspect 3 did. And had access to the mobile banking system with the ability to add or modify customer mobile phone numbers. Records showed that on the days in question, unusual mobile transactions were processed from their workstation by logging into the system and creating new records.
The trick? The transfers were disguised as legitimate mobile banking withdrawals. If anyone checked, it looked like real customers were moving their money.
But where did the mobile money end up?
That led investigators to multiple mobile numbers, some registered under fake names, others linked to unsuspecting individuals. The cash-out points were scattered across different locations, making it hard to trace the final recipient.
Unraveling the heist
Once the forensic imaging, analysis, and investigations were done, the full picture emerged.
- Suspect 1, the IT person, accessed customer data and identified vulnerable accounts.
- Suspect 2, the admin manager, approved internal transfers that looked legitimate.
- Suspect 3, the teller, facilitated the mobile money withdrawals by creating fake mobile numbers and linking them to genuine customer accounts.
It was a coordinated, deliberate attack.
Lessons from a Silent Heist
This fraud wasn’t about brute force. It wasn’t about hacking. It was about knowing the system better than the people who built it. The insider threat is an ever-present one. People in the insiders understand the business controls and how things are done.
It was about patience.
Someone studied internal controls, understood which transactions triggered alerts, and knew who had access to what.
If you’re a bank executive reading this, ask yourself:
- Do you know who has access to your customer database?
- Can you detect unauthorized logins before the damage is done?
- Are you monitoring internal transfers in real time?
- Who controls mobile money withdrawals in your institution?
Because here’s the truth:
This won’t be the last heist. And the next one will be even smarter.
Copyright 2025. All rights reserved.
