A Senegalese petroleum company nearly wired $7.9 million to a fraudster. The thing that stopped it was not their AP system.
INTERPOL's Operation Sentinel stopped a $7.9 million wire transfer in Senegal last November. The fraud was supplier impersonation — the exact failure mode now spreading through African construction and infrastructure payments. The AP system did not catch it. A phone call to a bank did.
On 22 December 2025 INTERPOL published a press release that most treasury teams in West Africa did not read. The release was the closing note on Operation Sentinel, a one-month coordinated sweep across 19 African countries that ran from 27 October to 27 November. The headline number was 574 arrests and roughly $21 million in losses linked across BEC, digital extortion, and ransomware.
Inside the release there is one paragraph that is doing more work than the rest of the document. A major petroleum company in Senegal detected a sophisticated BEC scheme. Fraudsters had infiltrated internal email systems and impersonated executives to authorise a fraudulent wire transfer of USD 7.9 million. Senegalese authorities froze the destination accounts before the funds could be withdrawn. That is the entire account of it in the official release. No company name. No bank. No timeline of how close to the wire the freeze came.
It is the second-largest single-incident BEC near-miss publicly disclosed on the continent that I can find in 2025, and it is being held up as a win. By the metric the press release is using, it is a win. The money is still there. Nobody lost their job. The destination accounts are part of a criminal case now, not a recovery problem.
But the win is not the AP workflow. The win is a phone call to a bank.
The thing the petroleum company's payments stack did was authorise the transfer. The thing that caught it was an emergency account freeze on the receiving side, done by people who do not work at the company and who would not have been in the picture at all if the destination bank had been outside the cooperative reach of Operation Sentinel. The buyer's AP system did its job exactly as designed. The design is the problem.
I keep coming back to that paragraph because the mechanism is identical to a case I wrote about earlier this year out of Victoria, Australia, where AU$900,000 actually did leave the building. A real supplier email, a real PDF template, a substituted bank account, an AP team with no second record to compare against. The Senegal case is the same attack run at almost ten times the size, against a much larger target, and the only reason the cash did not move was that an out-of-band actor reached the receiving bank in time.
That is not a control. That is luck wearing a uniform.
The construction-sector version is already in court
If the petroleum case is the BEC version of the failure mode, the Nigerian Railway Corporation case is the construction-adjacent version. On 25 February 2026 the EFCC arraigned three NRC directors at Ikeja over N2.04 billion (about $1.3 million) the agency says was diverted through personal and shadow-company bank accounts. The accounts named in the arraignment sit at Zenith Bank, Polaris Bank, and Access Bank. The pattern in the charge sheet is consistent. NRC contractors paid invoices into accounts that were not NRC's. One of the defendants is alleged to have received N240,940,000 through a Zenith Bank account in the name of FC Njoku and Company between January and December 2024.
The standard reading of the NRC case is that this is insider corruption, and on the legal facts it is. The directors are charged. The contractors paid the wrong account because someone inside the buyer told them to. That is a different attack from Senegal. The fraudster in Senegal is external. The defendants in Lagos are internal.
The reason I am putting these two cases next to each other is that the failure inside the buyer is the same in both. The contractor making the payment, the AP clerk releasing the wire, the treasurer signing off on the run, none of them had a second record of where the legitimate NRC account actually was. If they had, they would have had to override it. The insider attack and the external attack converge on the same workflow hole. The hole is the absence of a treasury-vetted bank account record that is separate from whatever account is sitting on the invoice or the contract or the supplier master.
This is the part I had wrong for most of last year.
The admission
I used to describe the dual-record bank account model as a defence against the external attack, the email compromise, the impersonated supplier. That framing came out of the Australian and US cases I was reading at the time and it sounded right in conversations with security teams. It mostly bounced off finance directors in Lagos and Nairobi and I assumed it was because the BEC pattern was not as widespread yet.
That was wrong on both counts. The pattern is widespread. NIBSS reported that Nigerian financial institutions lost N52.26 billion to fraud in 2024, up from N17.67 billion in 2023, and attempted fraud volumes increased 338% year on year. The reason finance directors were not reacting to my external-attack framing was that they were already mentally pricing in the internal-attack version, and the dual-record model has to defend against both or it is not worth implementing.
Once I switched the framing, the calls changed. Practitioner reporting from the Nigerian market describes a pattern that matches: a subcontractor's bank details altered in a forwarded email chain, the change caught by a finance manager who happened to have the subcontractor MD's WhatsApp number from a prior site visit and called to confirm. No incident report filed. The amount, in the accounts I have seen cited, was north of N40 million. The wire did not go, so nothing was recorded. That is the shape of the data treasury teams are missing. The wires that go out are recorded as paid invoices. The wires that get caught are recorded as nothing at all. There is no count of how many times each AP team has been targeted in the last twelve months, because the workflow has no slot for a logged near-miss.
The PAPSS surface is the next thing to worry about
AfCFTA is doing exactly what it was designed to do, which is push more cross-border trade through African banks. PAPSS is now in 17 countries with 150-plus banks connected. The CBN simplified PAPSS transaction documentation in April 2025 for corporate payments under $5,000 per month. The number of suppliers a Nigerian buyer can now pay across border, in local currency, without invoking the dollar correspondent rail, is rising fast.
Every one of those suppliers shows up the same way to the buyer's AP system. An email. An invoice. A bank account on the invoice. Probably a WhatsApp number for the relationship.
There is no PAPSS feature that tells the buyer's treasurer which of those bank accounts has been verified out of band and which one arrived as a string of digits on a PDF that was emailed at 3 pm on a Friday. That is not a flaw in PAPSS. PAPSS is a settlement rail. The verification is the buyer's problem to solve, and it is the problem the AP system has to be designed around, not bolted onto.
What a treasurer in this market can do this quarter
If you are running AP for a mid-market buyer in Lagos or Dakar or Nairobi and you do not have a separate treasury-vetted record of supplier bank accounts, you do not need a procurement cycle to start closing the gap. Pick the top thirty suppliers by spend over the last twelve months. For each one, send a one-line email from a real human to a known contact and ask them to confirm the bank account on file. Store the confirmation somewhere that is not the supplier master, with the verifier's name and the date the confirmation came back.
That is a treasury-vetted table. It lives in a spreadsheet until it does not. The next time an invoice arrives with a bank account that does not match the spreadsheet, you have a signal. Today you have nothing, which is the same thing the Senegalese petroleum company had on the morning of the wire that did not happen.
If the spreadsheet eventually wants to become a system, sign up at calabash.app and we will compare what we have built against what you have today. We will tell you where our model would have caught the Senegal wire before it reached the receiving bank. We will also tell you where it would not have helped, because the honest framing is the only framing that survives in this category.