Online Banking Security for Individuals and Small Businesses

Black USB two-factor authentication security key lying on white fabric


The most expensive lesson in Nigerian banking rarely arrives as a technical failure. It arrives as a phone call from a polite young man who says your account has been suspended and asks you to confirm your details on a number he is calling from, or as a transfer to a supplier whose details were changed by somebody you never spoke to. Both are account compromise dressed up as customer service. Good online banking security is not about sophisticated software. It is about who is allowed to do what, and how quickly you find out.

What fraud actually looks like here

Start with the scale, because it explains why the controls below are not optional and why account security beats a better antivirus. Nigeria Inter-Bank Settlement System, the body owned by the licensed banks, has reported that digital payment fraud losses fell by about half to roughly 25.85 billion naira in 2025, from about 52.26 billion in 2024 and 17.67 billion in 2023. Incident counts have fallen too, from 123,918 in 2021 to 67,518 in 2025, and industry measures are reported to have prevented around 20 billion naira more. That is real progress, and those figures say where losses concentrate: e-commerce and internet banking remain the most affected channels, and Lagos accounts for most reported fraud. Customers and banks share the loss, which is often lost in the argument.

Over a longer window, the UN Office on Drugs and Crime put Nigeria’s cybercrime losses between 2017 and 2023 at about 1.1 trillion naira across banks, telecoms and government agencies. Its assessment of cybercrime in Nigeria sets out the legal and institutional framework. Two features matter to an account holder. The country’s cybercrime legislation, passed in 2015 and amended in 2024, places a duty on institutions operating networks and computer systems to report incidents, and those routes are real. And the burden of proof after a disputed transaction is not automatically on you, which is why the online banking process, properly followed, exists.

Online banking security: getting access under control

Before anything else, the account must not be reachable from a device or a phone number an attacker might already hold. That means a unique password used nowhere else, a second factor a phished password cannot defeat, and recovery details that are not your mother’s maiden name. This part of online banking security is entirely within your control, so do it first.

The second factor, ranked honestly

Almost nobody chooses their second factor thoughtfully, because the app offers one option and you accept it. CISA’s phishing-resistant multifactor authentication fact sheet is unusually clear about the ordering, and it matches what banks here can offer.

Second factor Resists a phished login Known weakness Our view
Passkey or hardware security key Yes, the credential is bound to the real site Needs a compatible device, and bank support varies Best option; ask your bank whether it supports one
Authenticator app code Yes, if the code is only ever typed into the genuine site Users still sometimes paste it into a phish Good default where it is offered
App push with number matching Partly; resists approval fatigue User error on a rushed login Acceptable, and the prompt names a matching number
App push without number matching No An attacker can spam prompts until you approve one Weak; refuse it if the bank also offers something better
SMS or voice code No Phishable, interceptable, and exposed to a swapped SIM Last resort only

The SMS problem is not theoretical. Text codes travel over infrastructure that can be attacked directly, and a SIM swap moves your number to another card. CISA names all three weaknesses, phishing, signalling attacks and SIM swap, in one paragraph, and recommends text or voice only as a last resort. If your bank supports an authenticator app, move to it. If it supports a passkey, move to that. Email security and phishing explains why a phished password plus a real-time code is the combination attackers are after.

Alerts, limits and your security habits

Alerts are the cheapest fraud detection available and the most commonly disabled. Turn on every alert your bank offers: transactions, balance thresholds, new beneficiaries, new devices, password changes and standing instructions. The last three are the early signal, and the early signal is the difference between a disputed transaction and a drained account. They cost nothing to enable.

Then do the unglamorous part. Read the statement monthly, and treat an unfamiliar small debit as more alarming than an unfamiliar large credit, because that is what an attacker probing a limit looks like in practice. Set a per-transaction and per-day limit with the bank rather than relying on discipline. A limit is not a security control in the technical sense, but it is the difference between a bad afternoon and a bad year, and for a business paying suppliers it is the most valuable switch in the app. If a transaction goes wrong the chargeback process exists, but it depends on how fast you report, and on whether you noticed at all.

The first hour of a suspected compromise

Order matters more than speed, and the sequence is short enough to do from a phone. Call the bank on the number printed on your card, not the one in the message that alarmed you, and ask for the fraud line. Ask them to block the account, stop any standing instructions and reverse what has already gone out. Then change the banking password from a different device, and revoke active sessions, because a new password alone does not end a session an attacker is already holding. Then change that password, or a close variant, everywhere else it was used, starting with the registrar and the hosting panel. Then enable the second factor. Then check whether recovery details, limits or beneficiary lists were changed, and undo them.

Then preserve evidence before you tidy up. Screenshots of the messages, the transaction list with timestamps and the call reference number are what let a bank or the police act. Nigeria’s cybercrime framework expects incidents to be reported, and reporting makes a pattern visible. Outside the country, the FBI’s IC3 accepts reports, and IdentityTheft.gov is the starting point if personal details rather than money are affected. Do not delay the report while you tidy your device.

Controls for a business treasury function

A small business’s banking risk differs from a household’s, because the money moves on somebody else’s instruction and the person giving it may be phished. Three controls cover most of it. No payment leaves on a standing instruction created in the same email thread that requested it; the instruction is phoned through on a number already on file. One person does not both request and release a payment, even in a two-person business, because the two-person version of that is a shared login, and a shared login has no accountability. And the bank relationship has two named contacts with authority, so one compromised mailbox cannot lock the business out of its own money.

Add the technical side. The accounts that can move money, or reset the email they are recovered through, are the crown jewels: registrar, hosting panel, banking portal and the social accounts customers use to reach you. Each gets a unique password and a second factor, none is reachable from a shared device, and the password habits that make it sustainable are in our guide. This belongs in a continuity plan alongside ransomware preparation for a plain reason: a business that cannot move money for three days cannot buy diesel, pay a technician or take a job. A VPN on the device used for treasury work is the smallest part of the answer.

Frequently asked questions

Is it safe to use my banking app on public wifi?

Use your own mobile data, and treat hotel and café networks as a last resort. If you must, connect the tunnel first and read any certificate warning rather than clicking through it. The reasoning, including where a tunnel stops helping, is in our VPN explanation; the network-side practices are in public wifi security.

My bank says it will call to verify a transaction. Genuine?

Do not use the number they gave you, including a mobile number. Call the number printed on your card or in your app, or the security line on your statement. There is one narrow exception, where your bank registered a number for authentication in advance, but you will already know that number, which is exactly why you should never take it from an incoming message. This habit is worth writing down, because it is the one that fails under pressure.

A transfer left my account and I did not authorise it. What now?

Call the fraud line immediately, ask for a block and a reversal, then report it. Speed is the single thing that affects the outcome, because reporting windows exist and a dispute raised days later is a weaker claim. Keep screenshots and the call reference number. The full sequence is in the first hour section above.

Should a business have two people able to authorise payments?

Yes, and neither should share a login. Two named contacts is the single most useful control in a small treasury function, because it survives one person being unavailable, one mailbox compromised and one phone lost. It does not survive a shared password, so give each contact their own credentials and second factor.

Key Takeaways

  • Digital fraud losses in Nigeria fell sharply in 2025, but internet banking and e-commerce remain the most affected channels and customers share the losses.
  • Move off SMS codes. An authenticator app is better, a passkey is better still, and CISA ranks text codes a last resort.
  • Turn on every alert your bank offers, especially for new beneficiaries, new devices, password changes and standing instructions.
  • Set transaction and daily limits with the bank. A limit is not clever, it is the difference between a bad day and a bad year.
  • In a suspected compromise, call the number on your card, block and reverse first, then change passwords and revoke sessions from a clean device.
  • In a business, no payment leaves on an instruction created in the same thread that requested it, and two people hold authority with their own logins.

Most of this sits on one foundation: password security for 2026 and the second factor protecting the account behind it.

Sources: Nigeria Inter-Bank Settlement System on digital payment fraud losses, incident counts and the most affected channels; UNODC assessment of cybercrime in Nigeria and the reporting framework; CISA fact sheet on implementing phishing-resistant multifactor authentication; FBI IC3 reporting routes and advisories; online banking processes and how disputes are handled; chargeback process; IdentityTheft.gov.

0 Comments

Your email address will not be published. Required fields are marked *