When money disappears

By Law & Society Magazine Investigations

The GTBank complaint raising questions about fraud detection, customer alerts and digital banking safeguards

On the morning of August 22, Onifade Isaac believed the ₦4.6 million in his GTBank savings account was still there. By the time he needed the money, it had gone.

Isaac, a warehouse manager in Alimosho, Lagos, says he did not authorise the transfer. He says he received neither an SMS alert nor an OTP and had his phone with him throughout the period. The bank statement he later obtained recorded a single outward transfer of ₦4.6 million to a Pocket App account in the name of Zahara’u Iliyasu.

What followed was not simply a dispute over a missing balance. It raised questions about how a large electronic transfer could leave a customer’s account, what warnings were available to him at the time, how quickly the banking system can trace and stop a disputed transaction, and where responsibility lies when a customer says he did not initiate it.

Isaac’s account of what happened begins with an ordinary banking transaction that he says he never made. According to documents relating to the complaint, his GTBank account had an opening balance of ₦4,395,275.11 for the period covered by his statement. On August 22, a single debit of ₦4.6 million was recorded as an “Outward Transfer to Pckapp – Zahara’u Iliyasu.” The closing balance was ₦10,446.86.

He says he discovered the problem only when he attempted to withdraw money for a family need and was informed that there was not enough money in the account.

By then, the transfer had already been processed.

Isaac contacted GTBank’s customer service the same day. In an email from the bank’s E-Fraud, Analytics and e-Channel Security Group, he was informed that his account had been blocked as a precaution against further unauthorised access and that the disputed debit had been escalated to the receiving bank.

Isaac says he was also told that the recipient’s account would be blocked and a “Do Not Debit” instruction placed on it. He later says he was informed that the recipient had already used or withdrawn the money.

That sequence raises a difficult practical question for any customer facing an electronic-fraud complaint: How much can the banking system do after the money has moved?

The warning that never came

Isaac’s complaint places particular emphasis on the absence of an SMS transaction alert.

Banks use transaction notifications as one of the most immediate ways customers monitor activity on their accounts. An alert does not prevent fraud by itself, but it can give a customer an early opportunity to identify an unauthorised transaction and notify the bank before funds are moved further.

GTBank increased its SMS transaction-alert charge from ₦4 to ₦6 in May 2025, while also providing customers with alternative notification arrangements and the option to opt out of SMS alerts. The issue, therefore, is not simply whether an SMS was sent. It is whether the notification arrangements attached to a customer’s account provide a meaningful opportunity to detect an unauthorised transaction.

Isaac says no such warning reached him.

He also says no OTP was requested or received before the ₦4.6 million transfer.

That allegation requires some care. Not every electronic banking transaction necessarily uses an OTP, and the absence of an OTP does not by itself establish that a transaction was fraudulent. The relevant question is what authentication and fraud controls were applied to this particular transaction and whether the transaction was consistent with the customer’s normal banking behaviour.

Those are matters the bank’s technical investigation should be able to establish.

A complaint that arrived at an important moment

The timing of Isaac’s complaint is also significant.

From July 1, 2026, new Central Bank of Nigeria requirements for instant payments introduced stronger expectations around fraud monitoring and customer protection. Financial institutions were required to deploy real-time enterprise fraud-monitoring systems and strengthen identity verification. The framework also introduced measures including one-device linking for mobile applications, a temporary ₦20,000 transaction limit for a newly activated device during its first 24 hours, and mechanisms allowing customers to disable instant transfers or impose lower personal transaction limits, subject to verification and risk assessment.

Isaac’s disputed transfer occurred less than two months after those requirements took effect.

That does not establish that GTBank breached any rule. It does, however, make the case a useful test of how the new safeguards operate in practice.

If a customer reports that millions of naira left his account without his authorisation, the central questions are technical and traceable. What device initiated the transaction? What authentication method was used? What IP address or digital footprint accompanied it? Was the device newly registered? Did the transaction trigger any fraud-monitoring rule? Were there behavioural indicators that should have prompted additional verification? When did the bank become aware of the complaint, and how quickly did it communicate with the receiving institution?

The answers could determine whether the transaction was the result of compromised credentials, a compromised device, social engineering, an internal control failure, or something else.

At present, Isaac’s account establishes an allegation and a disputed transaction. It does not, on its own, establish how the money left the account.

GTBank Chief Communications Officer Oyinade Adegite told National Waves that the bank was already working with Isaac to resolve the matter and would provide an update.

That response is important. The bank has not publicly accepted Isaac’s account of the transaction as established fact, and the outcome of its investigation remains material to the case.

The Innoson shadow

For GTBank, the complaint arrives against the background of another long-running dispute that began with a customer’s account.

Years before mobile banking became central to everyday transactions, industrialist Innocent Chukwuma’s Innoson Manufacturing Company became locked in a prolonged legal battle with the bank over disputed charges and deductions from its account.

Innoson alleged that GTBank had made excessive and unlawful deductions in connection with banking and loan transactions. A Multi-Wings audit commissioned by Innoson reportedly put the disputed excess charges between March 2004 and December 2011 at about ₦786.2 million. GTBank’s own audit reportedly arrived at a lower disputed figure of about ₦559.4 million. The parties also disagreed over interest and the sums ultimately payable.

The dispute grew into years of litigation, garnishee proceedings, appeals and enforcement battles. Figures that began as disputed account charges became much larger as interest and subsequent court processes accumulated.

The legal history is more complicated than the shorthand that has sometimes appeared in public commentary.

In one phase of the litigation, the Supreme Court in 2019 dismissed GTBank’s appeal. But in 2022, the Supreme Court set aside that dismissal after finding that the bank’s brief had been filed but had not been brought to the attention of the panel. The appeal, SC.694/2014, was ordered to be relisted for determination on its merits.

More recent enforcement proceedings have generated further disagreement between the parties. Reports of a writ of fieri facias obtained by Innoson should not be confused with a court order handing over GTBank or its assets to Innoson. GTBank has disputed Innoson’s characterization of the enforcement process and maintained that the relevant judgment concerned garnishee proceedings involving an account of the Nigerian Customs Service domiciled with the bank, rather than a judgment against GTBank itself.

The Innoson dispute and Isaac’s complaint are not legally the same case. One concerns a long-running commercial and banking dispute that went through several layers of litigation; the other concerns an alleged unauthorised electronic transfer. But both illustrate a basic feature of banking disputes: once money moves through a financial institution, the customer needs more than an assurance that an investigation is under way. The customer needs to know what happened, who authorised it, what controls were triggered and what can be done to recover the money.

What happens after a disputed transfer?

The first few hours can be critical.

Electronic transfers can move through several institutions almost instantly. By the time a customer discovers an unauthorised debit, the receiving account may have been credited and the funds transferred elsewhere, withdrawn or converted into another form.

This is why fraud prevention cannot depend entirely on what happens after a customer complains.

The CBN’s payments-system framework places emphasis on safety, soundness, internal controls, transparency, accountability and effective supervision. Its consumer-protection framework also recognises customers’ rights to information, privacy, confidentiality and redress, while requiring banks to maintain accessible and timely complaint mechanisms.

Customers, for their part, are expected to report suspected fraud or errors promptly.

That creates a two-way obligation, but it does not answer every dispute. A customer can report a transaction immediately and still find that the money has already disappeared from the receiving account. The practical question then becomes whether the financial system’s controls were capable of detecting the transaction before the money moved beyond recovery.

That is where real-time monitoring becomes more than a regulatory phrase.

Where does the customer’s responsibility end?

Digital banking has shifted much of the work of banking from the branch to the customer’s phone.

A customer can open an account, transfer millions of naira, pay bills and move money between institutions without speaking to a bank employee. The convenience is enormous. So is the potential speed of loss when something goes wrong.

Customers have responsibilities. They must protect their devices, passwords, PINs and authentication credentials. They must be cautious about links, fraudulent calls and requests for confidential information. They must report suspicious transactions without delay.

But the banking system has responsibilities too.

A sophisticated digital banking platform should not rely on customer vigilance alone. It should be capable of identifying unusual behaviour, applying transaction limits and authentication controls, detecting suspicious patterns and responding quickly when a customer reports a potentially fraudulent transaction.

The CBN’s latest instant-payment requirements reflect that reality. They place greater emphasis on institutional fraud monitoring and on giving customers additional control over instant-transfer functionality.

The test is whether those controls work when they are needed.

Nigeria’s banking system is moving faster

The scale of Nigeria’s shift to electronic payments makes that test increasingly important.

Internet and web transfers accounted for more than half of non-cash retail payment volume by June 2024, according to CBN payments data. Mobile channels and point-of-sale transactions have also become routine parts of everyday commerce.

The country is moving toward a financial system in which physical cash and bank branches play a smaller role in many transactions. The CBN’s Payments System Vision 2028, launched in June 2026, places security, trust, consumer protection and stronger regulatory oversight among its stated priorities.

The logic is straightforward: the more Nigeria depends on electronic payments, the more damaging a failure of confidence in those systems becomes.

A customer who loses ₦4.6 million does not experience the problem as a technical failure. He experiences it as money that was there and then was not.

The real value is trust

Isaac’s affidavit, filed at the Chief Magistrate Court of Lagos State, Yaba Magisterial District, on August 26, says he did not authorise the transfer and asks for immediate reversal and full restitution.

A police crime diary extract dated August 27 also records his complaint.

Those documents do not determine liability. They record the customer’s account of events and the steps he took after discovering the debit. The bank’s investigation, transaction logs and any evidence from the receiving institution will be needed to establish what actually happened.

That evidence should answer the questions at the heart of the complaint.

If Isaac authorised the transfer, the evidence should show how. If his account or device was compromised, the evidence should show that too. If a security control failed, the failure should be identifiable. And if the money cannot be recovered because it was moved after the bank was notified, the chronology should establish when the bank received the warning and what action followed.

For millions of Nigerians using mobile and internet banking every day, those answers are bigger than one account.

The promise of digital banking is that money can move quickly, securely and conveniently. The obligation on banks and regulators is to ensure that the systems built for that speed can also detect when something has gone wrong, contain the damage and give customers a credible path to recovery.

The future of banking is already here. The safeguards have to keep pace with it.

Follow our WhatsApp Channel

Related Articles

Stay Connected.

1,169,000FansLike
34,567FollowersFollow
1,401,000FollowersFollow
0SubscribersSubscribe
- Advertisement -

Latest Articles