Nigerian banks lost ₦52 billion to fraud in 2024. The CBN is shifting liability, not closing the gap.

Nigerian banks lost N52bn to fraud in 2024 and the CBN is shifting liability under the draft APP rules instead of closing the AP gap. The grammar tell that once flagged African BEC is gone. Here is the structural fix.

Share
Wire transfer confirmation on a phone screen, petroleum-orange light, blurred Lagos skyline behind
PAPSS will move the money. PAPSS will not tell you whether the account you are paying is the supplier you think it is.

The number from NIBSS is ₦52.26 billion. That is what Nigerian financial institutions lost to fraud across 2024, up from ₦17.67 billion the year before. Not a doubling. Closer to a tripling, in twelve months. Over five years the increase is 196 percent.

NIBSS does not publish a breakdown by attack type, so I cannot tell you how much of that loss was business email compromise specifically. What I can tell you is that secondary analysis of the same period named social engineering as the dominant vector, and that the Central Bank of Nigeria saw the same data and decided the existing rules were not going to work.

The CBN response was the draft Authorised Push Payment fraud guidelines, exposed in November 2025. If a customer is deceived into authorising a transfer and reports inside 72 hours, the bank reimburses, with a 48-hour payout window. Where neither the sending nor the receiving bank is at fault, the two share liability. Board-level oversight is required. Read alongside the NIBSS loss curve, the draft is a deliberate move of the cost of APP fraud from the customer back to the bank, and onward to whatever counterparties were involved in moving the money.

It does not stop the fraud. It changes who pays for it.

That is the part the regulation is honest about and the press release is not. The CBN is rewriting the loss curve. It is not closing the gap that produced the loss in the first place.

I went into this thinking the gap was a training problem. Most of the conversations I have with treasury and AP leads at Nigerian and pan-African mid-market companies start there. The shopping list is familiar enough. More awareness sessions. More phishing simulations. A refreshed poster in the AP room every quarter. A line about BEC in the new starter induction. I have sat in those meetings and the energy in the room is genuine. I no longer think it is going to move the number.

The reason I changed my mind is what INTERPOL put in the Africa Cyberthreat Assessment Report 2025. The bit that matters is the language tell. Through 2022 the easy way to flag an African BEC email was the grammar. Awkward salutation, slightly off register, a tense slip in the second paragraph, sometimes a sentence that read like it had been pasted from a translation tool. By 2024 those tells are gone. INTERPOL's assessment, as reported in secondary coverage and pending my own read of the PDF, is that attackers now produce convincing emails in victims' native languages. That covers English written in the register a Lagos procurement manager would actually use, and it covers Yoruba, French for the West African corridor, Portuguese for Angola and Mozambique, and Arabic for the North.

I spent last week looking at a handful of recent vendor email compromise attempts a friend at a Nigerian oil services firm shared with me, names redacted. I went in expecting the usual signals. A reply-to domain that did not quite match the supplier's actual one. A signature block referencing a wrong legal entity. A bank account sitting in a jurisdiction the supplier had no obvious business with. Sometimes a request timed to land late on a Friday. There were a few of those. Most of them, though, were clean. The salutation matched the supplier's actual style. The signature block carried the correct CAC-registered name. One referenced a real PO from a previous month. The "new bank details" paragraph read like a polite supplier doing a perfectly ordinary thing.

I would have approved most of them. So would the AP manager who has been told to "look out for anything unusual."

Now stack the AfCFTA dimension on top of that. Intra-African cross-border payment volume is projected to move from around $329 billion in 2025 to a trillion by 2035. PAPSS is live and integrated with NIBSS. The AfCFTA Digital Trade Protocol calls for e-KYC interoperability and the linking of NIN, BVN, CAC and regional IDs, but no implementation timetable has been disclosed. Analysis from earlier this year was blunt about it. Compliance, not payment rails, is the biggest source of cross-border friction. Seventy-one percent of African firms are unfamiliar with the Digital Trade Protocol at all.

Translate that into AP terms. Your Lagos manufacturer is about to start exchanging supplier bank details with a counterparty in Côte d'Ivoire, with no shared corporate identity layer underneath, in the same email-driven way that BEC has been exploiting for a decade in the West. PAPSS will move the money. PAPSS will not tell you whether the account you are paying is the supplier you think it is.

The structural fix is to take that decision off the human entirely.

What we have been building is a split-record model. There is a treasury-vetted bank account, which is the only one a payment can be released against. There is a supplier-profile bank account, which is what the supplier sees and can edit in their portal. Those tables sit parallel by design. The supplier can update their profile account whenever they want. The treasury account only changes after an independent confirmation from a second channel the buyer trusts, recorded as a workflow with named approvers and a stored audit trail, and never triggered by an inbound email.

The AP manager is no longer being asked "does this email read like Femi from procurement." They are being asked "has the verified record on file moved." Those are different questions. One is a vibes check against a language model. The other is a yes-or-no read against a system of record.

I want to be careful about what I am claiming. Calabash does not have a production customer running this end-to-end yet. We are in build mode. Every conversation we have had with a Nigerian or pan-African mid-market AP lead ends in the same place though. The current process is "the AP manager calls a number on the invoice," and the number on the invoice is the number the attacker put there. The CBN draft will move the cost of that decision when it goes wrong. It will not stop the decision from going wrong.

If you run AP or treasury at a mid-market business trading inside Nigeria or across an AfCFTA corridor, and you want to compare what we have built against the workflow you have today, sign up at calabash.app. Bring a recent bank account change request from a real supplier. We will walk through what the verified-record check would have done with it.