BusinessCorporateCourtsCrime WatchHomeIn-Depth NewsIn-Depth News and InvestigationsMain StoryNational NewsNewsPoliticsReal estateTechTechnology

How Stanbic Bank’s systems were breached, stolen phone unlocking Sh1million fraud

Court ruling exposes vulnerabilities in digital banking systems as criminals exploit identity documents, phones and weak verification to access customers’ savings. Besides the amount awarded, the ruling raises a more unsettling question for bank customers on how secure is money in an account when the information used to identify its owner can be stolen alongside the phone used to authenticate transactions.

A robbery that left James Njoroge without his phone and identity card quickly turned into a financial nightmare when fraudsters allegedly used the stolen items to unlock a digital banking channel he had never requested and siphon more than Sh1million from his Stanbic Bank account.

The case has exposed a potentially wider vulnerability facing millions of bank customers as lenders increasingly move transactions from branches to mobile and internet platforms—where possession of a customer’s phone, identification details and SIM card can potentially become the keys to their savings.

Njoroge, a Stanbic customer for more than a decade, had never enrolled for mobile or internet banking. He preferred visiting a physical branch to transact.

But after he was robbed on July 13, 2025, fraudsters used information obtained during the incident to create an OMNI digital banking profile linked to his account.

Court records show that the new profile was registered at 2.48pm. Just 21 minutes later, the first of three transactions was processed.

Between 3.09pm and 3.25pm, Sh1,001,000 was transferred from the account.

The speed with which an account that had never previously operated through digital banking was converted into an active digital channel and used to move more than Sh1 million became central to the subsequent court battle.

Njoroge’s wife notified Stanbic at 5.19pm, after which the bank restricted the account. The lender recovered Sh490,000 from one of the recipient accounts and returned the money to him.

The dispute proceeded to the Small Claims Court, where Njoroge accused the bank of failing to adequately protect his money.

In a judgment delivered on August 25, the court found Stanbic partly liable and ordered it to refund the unrecovered Sh511,000, together with interest at 12 per cent per annum from the date the suit was filed.

See also  Bio Foods, USAID partner to combat aflatoxins for safe milk

Besides the amount awarded, the ruling raises a more unsettling question for bank customers on how secure is money in an account when the information used to identify its owner can be stolen alongside the phone used to authenticate transactions.

When authentication becomes the vulnerability

Evidence before the court showed that Stanbic’s self-registration process required a national identity card number, date of birth, account number and a one-time password (OTP).

The problem, the court found, was that the fraudsters had access to the same information.

They had allegedly stolen Njoroge’s identity documents and mobile phone, meaning the information required to establish his identity—and the device required to receive the OTP—were simultaneously in the hands of criminals.

The court found that information originally supplied years earlier to open Njoroge’s physical account was being relied upon to activate a completely new digital banking channel.

“The information provided 10 years ago to open a physical account is the same information that the fraudster now possesses. It does not serve as a robust verification for a new and powerful channel,” the court said.

The judge held that activating mobile or internet banking on an existing account represents a significant change in the relationship between a bank and its customer and therefore requires stronger safeguards than those used when the original account was opened.

“The loss would have been prevented if the bank had a robust verification process for new digital profiles. The delay in reporting does not excuse the bank’s structural negligence,” the court ruled.

Sh1million moved in 16 minutes

The court also questioned why the unusual transaction pattern did not trigger an immediate intervention.

See also  Killer squad Hessy targets gangsters freed on bond, say police sources

Njoroge’s account had no history of digital banking activity. Yet within minutes of the new profile being activated, more than Sh1 million was moved through three rapid transactions to recipient accounts.

The court said such activity should have been detected as suspicious.

“Large, rapid transfers to a new, unrelated account after the activation of a digital profile on a previously dormant account are exactly the kind of red flags that a reasonably competent bank should have systems in place to detect and halt,” the court said.

The ruling therefore shifted the focus from whether the transactions had been technically authenticated to whether the bank’s fraud-detection systems were capable of recognising behaviour that was plainly inconsistent with the customer’s established banking pattern.

OTP protection questioned

Stanbic argued that the transactions had been properly authenticated using the customer’s credentials and that the bank had no way of knowing they were fraudulent.

It also cited the delay in reporting the robbery, arguing that nearly 11 hours had elapsed before the incident was reported.

The court rejected that defence, finding that Njoroge had been robbed, drugged and incapacitated, while his wife reported the matter as soon as reasonably practicable.

The judge also questioned whether SMS-based OTP authentication remains adequate where criminals can steal the customer’s phone and SIM card.

The court described reliance on the “closed-loop” SMS OTP system as commercially unreasonable given the known risks associated with stolen mobile devices and SIM cards.

The vulnerability is stark: the same phone used to prove that a customer is authorised to access an account can also become the instrument through which criminals gain access.

See also  Be guided by your professional ethos, President Kenyatta tells new KDF officers

An OTP may confirm that someone has possession of a particular phone, but it does not necessarily establish that the person holding it is the legitimate account holder—especially when the device has been stolen together with identification documents.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button