Terrorists using dead persons’ accounts, crowdfunding – NFIU

The Nigeria Financial Intelligence Unit (NFIU) has uncovered an emerging crowdfunding network allegedly being exploited to raise and channel funds to support terrorist activities.

The agency also disclosed that terrorist financiers were opening bank accounts in women’s names and using telephone numbers for mobile banking or account alerts that were not registered to the account holders or the actual beneficiaries.

The findings were contained in the NFIU’s 2025 Annual Report, obtained by The PUNCH from a senior official.

According to the report, the crowdfunding network involves foreign-based facilitators who use social media platforms to solicit donations under the guise of humanitarian relief or educational support. The funds are subsequently moved through several layers before reaching terrorist operatives in Nigeria.

The NFIU said hundreds of sympathisers were encouraged to make relatively small donations, typically between $50 and $500, through PayPal pages or conventional bank accounts. The amounts were deliberately kept low to avoid triggering automated anti-money laundering alerts.

“The following is a case study on Crowdfunding Network identified during the year: A foreign-based facilitator runs social-media campaigns claiming humanitarian relief or educational support and uses encrypted apps (Telegram, Signal) to share links to convincing PayPal pages or standard bank accounts.

“Hundreds of sympathiser donors contribute $50–$500 each, amounts small enough to avoid most automated AML alerts,” the report read.

The funds are then consolidated into a “master account” controlled by a senior member of the network who resides legally outside Nigeria.

“When the pool reaches a threshold, that account becomes the hub for onward movement,” the report stated.

The NFIU said the money was subsequently divided into numerous smaller transfers and sent through International Money Transfer Operators and remittance applications to a network of money mules in Nigeria.

Students, small-business owners and relatives were among those identified as being used as money mules. The strategy, according to the report, was intended to stay below reporting thresholds while concealing the source and destination of the funds.

“Rather than sending one large transfer, the senior member fractures the funds and sends dozens of sub-threshold payments through IMTOs and remittance apps to a network of money mules in Nigeria; students, small-business owners, or relatives, avoiding reporting triggers.

“Upon receipt, the money was either converted to cash, used to purchase dual-use items such as motorcycles, fertilisers and satellite internet equipment, or transferred through mobile banking channels to logistics managers and field operatives,” it added.

The report described the final stage of the process as the “integration” of the funds into terrorist operational financing.

Gender-based proxy accounts

The NFIU also identified the use of gender-based proxy accounts as another emerging method of terrorist financing.

According to the agency, terrorist financiers were opening bank accounts in women’s names while male commanders or logistics managers secretly controlled the accounts.

“Terrorist financiers are opening bank accounts in women’s names while male commanders and logistics managers secretly control them.

“They exploit cultural norms that make women less likely to be suspected by authorities, using wives, sisters, or female associates as fronts to distance illicit funds from the true operatives.

“This tactic functions as identity laundering: women’s accounts are managed by men who hold ATM cards, mobile-banking credentials, and PINs, while the women often remain unaware of the transactions and volumes,” the report stated.

The report further revealed that terrorist facilitators were using telephone numbers that were not registered to account holders or the actual beneficiaries for mobile banking and transaction alerts.

It said pre-registered SIM cards, numbers belonging to deceased persons and SIMs connected to gender-based proxies were being used to break the link between bank accounts, SIM cards and Bank Verification Numbers.

“Terrorist facilitators use phone numbers for mobile banking or account alerts that are not registered to the account holder or the true beneficiary.

“They bypass the security link between SIM cards and BVNs by using pre-registered SIMs, SIMs registered to deceased people, or SIMs tied to gender-based proxies. This severs the audit trail: when a transaction is flagged, investigators trace the phone to an unrelated person, letting the real facilitator stay anonymous and continue operations,” it stated.

Terrorists use coded transaction descriptions

The NFIU also uncovered sophisticated methods allegedly used to disguise terrorist transactions through detailed or coded payment narrations.

The agency said cells, particularly those linked to the Islamic State West Africa Province, used specific transaction descriptions to maintain what analysts described as an internal accounting system.

According to the report, frequent logistics-related payments containing detailed narrations were often transferred from a single source to multiple recipients, suggesting a structured financial system within the terrorist network.

“Terrorist cells, particularly those linked to ISWAP, routinely use precise, professional-sounding transaction narrations to maintain internal accounting. Operating like “shadow states” with strict bureaucratic controls, they require detailed descriptions so field commanders can justify expenses to central financial controllers. Although truthful narrations appear counterintuitive, they create an internal audit trail; analysts repeatedly observe high-frequency, logistics-related payments with accurate narrations sent from a single source to multiple recipients,” the report said.

However, the NFIU said some facilitators used seemingly harmless words, secret codes and alphanumeric combinations in transaction descriptions, sometimes switching between languages to conceal the purpose of payments and evade automated banking filters.

“Transaction descriptions employ innocuous words, secret codes, or alphanumeric strings to conceal intent. Facilitators use this coded language, often switching languages to evade banks’ automated keyword filters that flag terms like ‘Jihad,’ ‘Arms,’ or ‘Boko.’

“This practice obscures the true purpose of transfers, preventing detection and enabling continued financing,” it said.

Fraud, fintech gaps raise concerns

The NFIU said its risk and crime analysis for the year revealed an increasingly interconnected threat environment involving financial crime, technology and cross-border activities.

It identified fraud as a dominant predicate offence, with an increase in Ponzi schemes, fraudulent crowdfunding arrangements, cryptocurrency-enabled investment scams and hacking-related fraud.

The Unit said the schemes were increasingly exploiting weaknesses in fintech onboarding, including tiered accounts with minimal identification requirements, while digital platforms were being used to recruit victims and move funds rapidly.

The report also identified continued weaknesses in public sector financial management, including the diversion of state and local government funds through accounts belonging to finance officers and associated third parties.

Procurement processes and cash transactions were identified as significant risk areas, with the NFIU noting that cash usage makes audit trails and the tracing of illicit assets more difficult.

The agency said its findings had been converted into targeted advisories, executive alerts and strategic intelligence products to support relevant authorities, reporting entities and policy responses.

“Financial Fraud and Investment Scams: Fraud remains a dominant predicate offence, with notable growth in Ponzi schemes, fraudulent crowdfunding arrangements, cryptocurrency-enabled investment scams, and hacking-related fraud (including compromised social media and messaging accounts).

“Analytical reviews during the period examined these trends and informed internal advisories and alerts, some of which remained restricted for operational purposes.

“These schemes increasingly exploit fintech onboarding gaps, including tiered accounts with minimal identification requirements, and leverage digital platforms to rapidly scale victim recruitment and fund movement.

“Corruption and Misappropriation of Public Funds Analysis highlighted persistent vulnerabilities in public sector financial management, including the diversion of state and local government funds through accounts of finance officers and associated third parties.

“Procurement processes remain a significant risk area, while utilisation of cash transactions complicates audit trails and asset tracing efforts,” the report said.

Experts call for stronger intelligence sharing

A security expert, Chidi Omeje, urged Nigeria’s security and financial intelligence agencies to strengthen their strategies to respond to the increasing sophistication of non-state actors.

Omeje said criminal groups were constantly developing new methods to circumvent existing security systems.

He called on agencies including the Nigeria Police Force, Department of State Services and financial regulatory authorities responsible for monitoring banking transactions to intensify their efforts, stay ahead of criminal networks and trace illicit financial flows.

“Every single day, these guys grow in sophistication and desperation, and we must also devise means to bring them to their knees.

“The state must ultimately deal with them. They must follow the money trail to monitor these movements and effectively tackle the situation,” he said.

Omeje stressed that the government and security agencies could not afford to lose ground to criminal groups, adding that intelligence-led operations and financial tracking remained crucial to national security.

Another security analyst, Lawrence Alobi, called for stronger intelligence sharing between security agencies and closer cooperation with financial institutions.

Alobi said security agencies needed to improve their information-gathering capabilities to identify criminals attempting to evade detection through fraudulent account arrangements.

“It behoves us now, the security agencies, to intensify their intelligence sharing and information gathering, because it is through information that we can get some of these things.

“Security agencies need to work with the banks and also warn them. Any bank found to have connived or aided this act should be sanctioned,” he said.

He also called for stricter compliance and verification procedures within the banking sector to prevent proxy accounts from being used for illicit activities.

“The banks themselves must sit up and ensure they properly verify every individual’s identity so that there is a real, verifiable person behind every account, not just someone acting by proxy. Intelligence agencies must go the extra mile to hold banks accountable for any loopholes exploited within their system,” he added.

NFIUTerrorists