Showing posts with label Nigeria data protection. Show all posts
Showing posts with label Nigeria data protection. Show all posts

Sunday, 5 November 2023

THE FLUTTERWAVE SHENANIGANS

In February and March, 2023 it was reported that Flutterwave, a fintech was hacked and customer funds, amounting to over N2.9 billion, held in Flutterwave accounts, were illegally transferred to several bank accounts in Nigeria. Flutterwave submitted a petition to the Nigeria Police concerning the hack and illegal transfer and based on the petition, the Police brought an application to freeze accounts in 27 financial institutions in Nigeria where some of the funds were transferred to and the court granted the application. In the affidavit in support of the application to freeze accounts, the Investigating Police Officer; Inspector Adebowale Michael deposed or swore in paragraphs 1, 3 and 4 as follows:

"(1) That am the above-named person as well as the investigating police officer in a case of Conspiracy and fraudulent transfer reported by Flutterwave Technology Solution Limited through his counsel Albert Onimole, legal practitioner by virtue of which I am conversant with the fact of this case.

(3) That a case of Conspiracy and Fraudulent transfer was reported to the Police via petition written by Albert Onimole & Co. on behalf of Flutterwave Technology Solution Limited bothering on allegation of Conspiracy, stealing and fraudulent transfer over Two billion naira having hacked into the complainant account. Copy of the Petition is hereby attached and marked exhibit ‘A’.

(4) That it was revealed in the course of investigation that the suspected hackers hacked into the cyber space of the complainant and transferred over two billion naira to various accounts listed on this application. Copy of the statement of the Complainant is hereby attached and marked exhibit ‘B’."

Flutterwave in its official statement, said; “During a routine check of our transaction monitoring system, we identified an unusual trend of transactions on some users’ profiles. Our team immediately launched a review (in line with our standard operating procedure), which revealed that some users who had not activated some of our recommended security settings might have been susceptible.” However, the fintech flatly denied that any user lost any funds, as its security measures were “able to address the issue before any harm could be done to our users”.

This denial is in stark contrast to the contents of the petition and affidavit earlier mentioned. If no user funds were lost, how come there was a petition to the police and an application to freeze accounts? The denial and statement shifting blame to "some users who had not activated some of our recommended security settings" is typical of what many financial institutions in Nigeria say whenever a customer complains of unauthorised withdrawals or transfers from their accounts. In the case of Barrister Wole Abidakun v. Diamond Bank Plc.(Suit No: CV/2779/18), which involved unauthorized transfer from customer account, Justice Kutigi of the High Court of the FCT, while delivering judgement on 23 June, 2021 observed thus:

“I agree that because these facilities have security features known only to the customer  and  so  the  customer  bears  some  responsibility  to  secure  them,  once however  a  customer  makes  a  serious  complaint  of  foul  play  in  his  account,  the usual  standard  and  rather  lazy  and  lame  response  by  Defendant  Bank  that  the customer has compromised the security features will not stand or fly in the absence of a forensic investigation to determine responsibility.  There must be proper in-house  and  then  police  investigations  showing  clearly  and  positively  that  the customer  must  have  indeed  compromised  the  security  features  or  given  his  PIN numbers to a third party.  Bare and empty verbal assertions will not suffice in this age of savvy and sophisticated criminals.  

Now, if it were in the United States, where data breaches and hacks are not tolerated by the financial services regulators, Flutterwave would have been in big trouble. The regulators would have carried out investigations and Flutterwave would have been fined heavily if found wanting. Flutterwave customers would have also likely filed a class action against the fintech.

For instance, in 2020 in the US, a class action was filed against Bank of America for failing to provide sufficient protections for unemployment payment debit cards after thousands across California, fell victim to fraud. Among the issues that were raised in the case against the bank was the lack of secure microchips in unemployment debit cards, a failure to secure private account information and a sluggish response to consumer fraud reports.

Also in the United States, the Consumer Financial Protection Bureau (CFPB) in 2016, found that online payment platform Dwolla, deceived consumers about its data security practices and the safety of its online payment system and therefore ordered Dwolla to pay a $100,000 penalty and fix its security practices.

As of May 2015, Dwolla had more than 650,000 users and had transferred as much as $5 million per day. For each account, Dwolla collected personal information including the consumer’s name, address, date of birth, telephone number, Social Security number, bank account and routing numbers, a password, and a unique 4-digit PIN.

From December 2010 until 2014, Dwolla claimed to protect consumer data from unauthorized access with “safe” and “secure” transactions. On its website and in communications with consumers, Dwolla claimed its data security practices exceeded industry standards and were Payment Card Industry Data Security Standard compliant. They claimed also that they encrypted all sensitive personal information and that its mobile applications were safe and secure.

However, it was found that Dwolla’s data security practices in fact fell far short of its claims. Specifically, the CFPB found, among other issues, that Dwolla misrepresented its data-security practices by:

(1)Falsely claiming its data security practices “exceed” or “surpass” industry security standards: Contrary to its claims, Dwolla failed to employ reasonable and appropriate measures to protect data obtained from consumers from unauthorized access.

(2)Falsely claiming its “information is securely encrypted and stored”: Dwolla did not encrypt some sensitive consumer personal information, and released applications to the public before testing whether they were secure.

The above action of the CFPB in the US represents how a regulator should act in the face of continuous data breaches and/or hacks.  In 2022 it was MTN Mobile Money Bank that was hacked but it is unclear what actions, if any, the  regulators in Nigeria took or made against MTN, concerning the breach or hack. The Federal Competition and Consumer Protection Commission, the Central Bank of Nigeria, the Nigeria Deposit Insurance Corporation, and the newly created Nigeria Data Protection Commission needs to sit up and do more.

It is therefore, high time that the regulators in Nigeria mentioned above woke up to their responsibilities and took punitive action against erring financial institutions in Nigeria for data breaches and hacks. Perhaps the fear of sanctions will make the financial institutions to improve on their cyber security practices and better protect customer funds/deposits in their custody.

It is also recommended that there should be a quarterly or yearly report made available to the public, showing financial institutions that were sanctioned for failing to comply with relevant industry cybersecurity framework and/or data protection regulations.


 

 

Tuesday, 11 July 2017

RE EMPLOYEES OF NIGERIAN BANKS AND THEFT OF CUSTOMERS' MONIES

In an earlier article: EMPLOYEES OF NIGERIAN BANKS AND THEFT OF CUSTOMERS' MONIES, I quoted a New York Times report thus:

"As concerns over identity theft and foreign cyber attacks rise, customers are largely in the dark about a growing threat just around the corner: bank tellers and managers with instant access not only to their critical personal information, but also to their cash.
Though much of the focus on bank fraud has been on sophisticated hackers, it is the more prosaic figure of the teller behind the window who should worry depositors, according to prosecutors, government officials and security experts."
The report further stated that the Manhattan District Attorney's office approximately files at least a case a month against a bank teller. This indicates that such cases of theft are now common place in Manhattan.

In the article, I also wondered about the scale or extent of theft of customer's monies by bank employees in Nigeria and concluded that the scale is unclear or unknown. I also cited in the article, two instances of bank employees in Nigeria pilfering customers’ funds. However, it appears there are more of such cases occurring and it seems the employees of Nigerian banks are trying to catch up with their colleagues in Manhattan. This seems so because of a report in the Punch. According to the spokesperson of the Special Fraud Unit of the Nigeria Police, ASP Lawal Audu as quoted in the report:
“The work of the network provider suspects was to assist the bankers to swap the SIM cards of the targeted bank customers so that they were unable to receive alerts of any transactions on their accounts within the period that money was stolen from their accounts.
The suspects, after successful withdrawals of the money, transferred the money into about 40 different accounts to avoid being detected. They carried out their operations at weekends and public holidays so as to evade being detected by the bank monitoring mechanisms or the owners of the accounts. They defrauded their victims to the tune of over N150m.”
This fraud story by the Punch is somewhat similar to the one reported in the Times of India. In that story a bank employee stole personal details of customers, got a police report indicating that the customers’ SIM cards were lost and then requested for a SIM cards from the network providers. He then transferred from those customers accounts and they could not get debit alerts sent to their phone numbers.

For more on bank employees in Nigeria stealing from customers’ account see the following:
Banker jailed 39 years for stealing N30m from dead customer-

Banker arrested for withdrawing N50m from customers’ accounts- http://www.informationng.com/2013/12/police-arrest-banker-for-stealing-n50m.html

Banker accused of stealing customers’ N8.4m-

Rogue bankers steal customers’ funds online-

In view of the foregoing, it might not to be out of place to make a freedom of information request to the Nigeria Police and other relevant authorities for information on the number of bank employees standing trial and those convicted for theft of customers' funds or hacking into customers' accounts. This would enable one to have a better idea of the scale of such thefts or hacking of customers' accounts by bank employees in Nigeria.

Friday, 30 September 2016

HISTORICAL CELL SITE LOCATION INFORMATION AND TELCOS IN NIGERIA


According to Wikipedia.com, a telco i.e. telephone company, telephone service provider or telecommunications operator:
is a kind of communications service provider (CSP) (more precisely a telecommunications service provider or TSP) that provides telecommunications services such as telephony and data communications access…With the advent of mobile telephony, telephone companies now include wireless carriers, or mobile network operators. Most telephone companies now also function as internet service providers (ISPs), and the distinction between a telephone company and an ISP may disappear completely over time, as the current trend for supplier convergence in the industry continues.

Historical cell site location information or mobile/cell phone location data is a collection of past connections between a mobile phone and cell towers or telecommunications masts. A cell site is mobile phone base station or antenna where radio signals are sent and received. In  the United States case of State v. Earls, it was stated that “Cell or (mobile) phones register or identify themselves with nearby cell towers every seven seconds. Cell providers (like MTN, Glo, Etisalat and Airtel in Nigeria) collect data from those contacts, which allow carriers to locate cell phones on a real-time basis and to reconstruct a phone’s movement from recorded data.”

Most times when you call the call centre of your GSM network provider or telco in Nigeria such MTN, Glo, Etisalat or Airtel, to make a complaint or inquiry, the customer care representative will ask you what town or city and local government you are calling from. I am usually taken aback by this question because they (telcos) already know or at least can approximate my location so why bother to ask me.

Whenever a mobile telephone makes a call, the call is routed through a cell site located at a fixed geographic location. Mobile telephone companies keep records of which cell site processes a call, and through this information law enforcement agents can locate the position of the SIM card, and therefore infer the location of the telephone user. This was used by the Nigerian Police to obtain the location of Timothy Dung, an armed robbery suspect in the case of The State v. Timothy Dung. On page three of the judgement it was stated thus:
According to the PW2 on the 20/8/2010 a case of armed robbery was transferred from the ‘E’ Division Police Station to the State Criminal Investigation Department (CID). PW1 volunteered a statement before the police.
According to the PW2 they swung into action by applying their detective mechanism to arrest the person because the line snatched was still going. Police applied to court to obtain a court order to serve Airtel/Zain who was the service provider of the line (Zain) snatched from the PW1. Airtel/Zain complied with the court order and released the coordinate to the Police. The coordinate enabled the Police to set a security trapping system that showed them the exact direction and position where the accused (that) was using that particular line at that time was standing. The system gave the latitude and longitude on google earth. lt shows(sic) that the accused person who was with the stolen line was at Abuja and the call history of the line after the robbery was within Abuja town and a town in Plateau State.  However, about three' days back, the line was showing that it, was in Abuja. The Police went to Abuja and the system directed them to Federal Fire Service in Abuja town and they went there. When the PW2 and his team called the number/line, it rang and the accused received the call. The PW2 then arrested the accused and interviewed him.
The case of United States v. Allums, also shows that telcos know or can estimate the location of their subscribers or customers at any given time using historical cell site location information (CSLI) or cell site analysis. James Edward Allums on 30th November, 2007, robbed a bank in Salt Lake City, Utah, United States. A bank employee dropped a chair from the second floor balcony onto Allums’ head as he stood brandishing a knife at a teller on the first floor.  In anger Allums removed his ski mask to look up and curse at the chair-dropper and in the process glowered directly into the surveillance camera. Allums had a mobile phone on him on 30th November.

Prosecutors introduced evidence that cell site tracking records showed that Allums’ phone, and presumably Allums, was located in close proximity to the bank and to two other locations also robbed by Allums. Thus, Allums was convicted on three counts of armed robbery.

Apart from historical CSLI mobile phone location can also be determined through GPS and mobile phone triangulation. At this juncture it is appropriate to state how mobile phone communications work as captured or explained in Re: Application for Telephone Information Needed for a Criminal Investigation:
Cell (mobile) phones operate through the use of radio waves.  To facilitate cell phone use, cellular service providers maintain a network of radio base stations—also known as cell towers (popularly referred to in Nigeria as mast)—throughout their coverage areas.
Whenever a cell phone makes or receives a call, sends or receives a text message, or otherwise sends or receives data, the phone connects via radio waves to an antenna on the closest cell tower, generating cell site location information (CSLI).  The resulting CSLI includes the precise location of the cell tower and cell site serving the subject cell phone during each voice call, text message, or data connection.  If a cell phone moves away from the cell tower with which it started a call and closer to another cell tower, the phone connects seamlessly to that next tower.
CSLI may be generated in the absence of user interaction with the cell phone. For example, CSLI may still be generated during an incoming phone call that is not answered.  Additionally, most modern smartphones have applications that continually run in the background, sending and receiving data without a user having to interact with the cell phone.
Indeed, cell phones, when turned on and not in airplane mode, are always scanning their network’s cellular environment. In so doing, cell phones periodically identify themselves to the closest cell tower—i.e., the one with the strongest radio signal—as they move throughout their network’s coverage area.  This process, known as “registration” or “pinging,” facilitates the making and receiving of calls, the sending and receiving of text messages, and the sending and receiving of cell phone data. Pinging is automatic and occurs whenever the phone is on, without the user’s input or control. A cell phone that is switched on will ping the nearest tower every seven to nine minutes. (Emphasis mine)
From the above it is crystal clear that CSLI can be used to estimate the location of an individual by identifying the nearest cell tower or mast and sector used when a call is made. It therefore presents circumstantial evidence of a person’s location.  This ability to locate a cell phone presents obvious benefits to law enforcement and intelligence authorities  as seen in the two cases referred to above. CSLI also poses a significant threat to privacy. Thus in State v. Earls (supra) the court observed that:
Advances in technology offer great benefits to society in many areas. At the same time, they can pose significant risks to individual privacy rights. This case highlights both principles as we consider recent strides in cell-phone technology. New improvements not only expand our ability to communicate with one another and access the Internet, but the cell phones we carry can also serve as powerful tracking devices able to pinpoint our movements with remarkable precision and accuracy.

Tuesday, 2 September 2014

EFCC AND ATTEMPTED HACKING

On the 30th of August, 2014 Sahara Reporters posted a news story on their website; captioned: “EFCC Arrests Three Suspected Fraudsters for Attempted Hacking.” The gist of the story is that some persons conspired to break into or compromise the computer systems/computer networks of a bank using an electronic device, for the purpose of stealing funds. However; their plan failed as an insider reported them to the Economic and Financial Crimes Commission (EFCC) and they were arrested.

The caption of the story got me wondering whether there is a law in Nigeria which directly criminalizes attempted hacking or hacking or breaking into someone’s computer networks or computer systems. To the best of my knowledge there is no such law in Nigeria that directly criminalizes hacking or breaking into or compromising someone’s computer networks or computer systems? Therefore, the caption: “EFCC Arrests Three Suspected Fraudsters for Attempted Hacking.” by Sahara Reporters is inappropriate or misleading.

In the US the Computer Fraud and Abuse Act, has prohibited certain computer crimes. The Act prohibits accessing or attempting to a computer without authorization and subsequently transmitting classified government information, theft of financial information, computer fraud, transmitting code that causes damage to a computer system, trafficking in computer passwords for the purpose of affecting interstate commerce or a government computer, etc. Also in South Africa, under the Electronic Communications and Transactions (ECT) Act 25 of 2002; unauthorised access to, interception of or interference with data on a computer or computer networks is  criminalized.

However, with regard to Nigeria, there is no law like that of the US and South Africa mentioned above. It is therefore, high time that a law regulating computer/internet crime in Nigeria is enacted. The need for a law criminalizing computer crime/cybercrime in Nigeria becomes more urgent considering the drive by the Government (Central Bank of Nigeria) to encourage cashless transactions which compels people to use electronic(computer) means of transactions. Criminals may exploit weaknesses in these electronic means of transactions to defraud customers but a computer crime/cybercrime law would be able to curb such criminal acts by punishing criminals who contravene the law.

In addition to the above, many Nigerians are now taking to online transactions/ecommerce. This can be inferred from the growth and popularity of the two leading online shops in Nigeria: Konga and Jumia. It is has therefore become necessary to pass computer crime/cybercrime laws to protect users of these ecommerce channels/shops. Apart from such computer crime /cybercrime laws there is also need for a data protection law to guard against the misuse/abuse of the personal data which operators of these ecommerce sites gather and hold concerning their customers/users. For instance in China, P.R.C. Criminal Law  stipulates criminal penalties for improper sales, provision and collection of personal data. In the same China, three men were arrested for illegal sales of millions of items of personal information.

Monday, 6 January 2014

Nigeria and Data Protection

“We live in an age of “big data.” Data has become the raw material of production, a new source of immense economic and social value. Advances in data mining  and  analytics  and  the  massive  increase  in  computing  power  and  data storage capacity have expanded, by orders of magnitude, the scope of information available to businesses, government, and individuals. In addition, the increasing  number  of  people,  devices,  and  sensors  that  are  now  connected  by digital networks has revolutionized the ability to generate, communicate, share, and access data. Data create enormous value for the global economy, driving innovation, productivity, efficiency, and growth.  At the same time, the “data deluge” presents privacy concerns that could stir a regulatory backlash, dampening the data economy and stifling innovation."

It is therefore clear from the above that data, especially personal data(any data or information in connection with a specific individual, which can be used, separately or in combination with other data, to identify an individual) has acquired an immense value in the age we are living(the digital age) and serious steps ought to be taken to protect the personal data of citizens but Nigeria seems to be lagging behind as the best we have at the moment is the guidelines on personal data issued by National Information Technology Development Agency(NITDA) which is good gut not enough(what we need is a law) and there is also a draft bill on Personal Information and Data Protection which is pending before the federal lawmakers.

This does not augur well for the citizens whose personal data is scattered all over the place (banks, the Federal Road Safety Commission (FRSC), the National Identity Management Commission (NIMC), the Nigeria Communications Commission (NCC), GSM service providers and online retailers like Jumia and Konga who are currently making waves in the Nigeria internet sphere as online shopping is becoming increasingly popular among Nigerians).

In China they have taken serious steps to guard and protect the personal data of their citizens with the passage of such laws as the Peoples’ Republic of China Law on the Protection of Consumer Rights and Interests and persons who flout the law are been arrested and prosecuted. For instance the Police in China, apprehended a 10-member gang in Beijing and Shanghai for illegally obtaining and selling nearly one million...You can find the rest of the story here

Monday, 18 November 2013

Barr. Timothy Tion discusses the NCC directive to cybercafe owners and cybercrime Part 1


Recently I was on “ICT WORLD”, a radio Benue program to discuss the Nigeria Communication Commission (NCC) directive to cybercafé operators which came into effect on the 1st of November, 2013 directing all cybercafé licencees and operators in the country to maintain an up to date data base of its subscribers/users detailing information such as; full names, names of corporate body (in the case of a corporate establishment), traceable physical address, full faced passport photograph, telephone numbers, permanent residential address(not P. O. Box), evidence of registration with Corporate Affairs Commission(CAC)(applicable to corporate bodies only) and other forms of identification including international passport, driver’s licence, national identity card, etc.
According to the NCC, this database is to aid law enforcement authorities in fighting the increasing rate of cybercrime committed through cybercafés across the country.
Here is the link to download the discussion. To download; click the "download" icon in green. Listen and let me get your feedback. Thank you.

UPDATE 22 DECEMBER 2020
The above link to the discussion is dead. Here is a new link to the discussion which is divided into parts 1 and 2. Listen to part 1 here and part 2 here