Number 1 Cause of Fintech Collapse in Nigeria Right Now

Ndubuisi Ekekwe
4 Min Read

More fintech startups in Nigeria fail due to “cyberattack & KYC/identity theft” related issues than any other problem. Our data shows that when those attacks happen, most times, the companies die over time, unable to recover from the paralysis. If you google and check recent closures, and ask questions, someone will tell you how some criminals have broken into a startup’s system, took money or distorted the company’s state of equilibrium.

Why this problem? Many people see embedded finance or finance-related APIs as marginal solutions without knowing that once you offer such solutions, you have provided vectors through which people could be hacked, if not protected. In other words, if you offer banking as a service where customers can get bank accounts via your portal, you have provided a path for them to be hacked, if you do not harden the access points. 

Indeed, in your fintech portal, your bank account is linked. A bad actor can initiate withdrawal from that account, and using the same fintech platform move the funds to another account.  Of course, many customers do not know that once they link a  bank account to the platforms, especially ones with “withdrawing” rights, they have extended withdrawing access to their bank accounts. But unfortunately, the portal where that is happening has no decent security protocol.

(Let me use PayPal to explain. Your PayPal account is linked to your bank account. From your PayPal account, you can initiate a deposit from your bank account into your Paypal wallet. If someone has access to your PayPal, that person also has access to your bank account!)

If you check some banks in Nigeria (one issue was reported today), their main bank websites and apps rarely have security failures, but their “fintech” subsidiaries do fail due to hacks. Why? While the Central Bank of Nigeria (CBN)’s security guidelines and regulations are adhered to on the core websites and apps, the fintech subsidiaries are not fully handled in the same way. So, some banks keep losing money due to such failures.

What can you do? One of Tekedia Capital startups wanted to build a fintech component as a marginal feature in its core business. We told the team to freeze the idea, encouraging them to continue to work with their banks’ partners, making it clear that a fintech-focused team should be in place before any voyage into that space.

Yes, that fintech marginal feature should be seen as a core product with every element of security thought-through before customers are allowed to use them.  Do not just get access, embed APIs and expose customers to be burnt without a team with responsibility to ensure that you (not in the finance space) have provided basic security features.

Indeed, embedding a protected and secure product in a porous portal creates vulnerabilities for your business and your customers. And that means you must ensure you are also protected, and secure, before you ask customers to use the solution.

Share This Article