August 22, 2026
Nairobi, Kenya
News

How a three-minute code change triggered Sh57.5 million NCBA fraud

NCBA Bank is facing serious questions over how an external contractor was able to alter live banking systems and leave a Sh57.5 million gap that went unnoticed for several days.

According to court filings by the DCI Banking Fraud Investigation Unit, the incident happened at the bank’s Rwanda subsidiary during a scheduled system maintenance exercise on June 6, 2025.

At about 5:30 a.m., NCBA activated a vendor contract that gave Evans Nandwa, an employee of consultancy firm Ronford Digital Limited, access to the bank’s live backend systems.

The access was meant to support maintenance and system upgrades linked to the bank’s mobile banking connection with MTN Rwanda.

However, investigators allege that only three minutes after receiving access, Nandwa changed part of the core application code.

The changes affected the system’s mobile money integration. According to the court documents, the altered code allowed withdrawal requests from 70 selected accounts to receive a false “Success” response without going through the normal checks.

The system allegedly did not confirm whether the accounts had sufficient funds, whether they were genuine or whether the person requesting the money was properly identified. Investigators said the accounts were ghost profiles, with many linked to cloned or fraudulently registered SIM cards using stolen identity information.

The narrow nature of the change appears to have helped the operation remain hidden. Instead of opening the loophole to all customers, the system was allegedly programmed to respond only to transactions involving the selected accounts.

For several days, NCBA’s normal monitoring systems did not raise an alarm. From June 6 to June 14, the bank’s dashboards continued showing what appeared to be ordinary mobile banking activity.

The fraud was discovered during an end-of-week reconciliation. NCBA compared its transaction records with figures from MTN Rwanda and found a major difference.

MTN records showed that Sh57.5 million had been paid out through 260 transactions involving the 70 accounts.

NCBA’s internal records, however, did not show corresponding account debits, fees or legitimate account holders behind the transactions.

The discovery triggered an internal investigation. NCBA reportedly cancelled third-party access tokens and vendor credentials before examining the system changes made during the maintenance period.

Engineers allegedly traced the modifications to activity carried out under Nandwa’s credentials.

The DCI Banking Fraud Investigation Unit was later brought into the matter. Nandwa was arrested in Nairobi and presented before Milimani Law Courts, where he appeared before Magistrate Benmark Ekhubi.

The case has exposed a major weakness that goes beyond the alleged loss itself. A single external worker with temporary access was allegedly able to make changes to a live banking system, while the altered rules remained undetected for days.

The incident raises questions about how banks monitor contractors, how much access external vendors receive and whether real-time systems can detect unusual transactions before large amounts of money leave the system.

NCBA moved to contain the problem once the mismatch was detected. However, the bigger challenge is ensuring that future maintenance work cannot create a similar gap.

With millions of transactions passing through banking systems every day, relying mainly on later reconciliation to detect a major security breach can leave institutions exposed for too long.

Leave feedback about this

  • Quality
  • Price
  • Service

PROS

+
Add Field

CONS

+
Add Field
Choose Image
Choose Video