Showing posts with label electronic evidence. Show all posts
Showing posts with label electronic evidence. Show all posts

Wednesday, 25 March 2026

When Power Players Expose Mass Surveillance: The El-Rufai Wiretapping Saga and the Cybercrimes Paradox


A high-profile airport confrontation has pulled back the curtain on alleged warrantless surveillance apparatus, but who investigates the investigators?

The recent clash between former Kaduna State Governor Nasir El-Rufai and National Security Adviser Nuhu Ribadu has exposed a troubling double standard at the heart of the digital rights framework in Nigeria. While legal experts like Abuja-based lawyer Pelumi Olajengbesi correctly point out that phone tapping constitutes a serious criminal offense under the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, El-Rufai's counter-allegations raise a more fundamental question: what happens when the suspected perpetrator is the state itself?

The Accusations

Following his attempted arrest at Nnamdi Azikiwe International Airport in February, 2026, El-Rufai publicly admitted to listening to an intercepted phone conversation in which Ribadu allegedly ordered his detention. But he didn't stop there. In a revealing statement, the former governor declared: "The government thinks that they're the only ones that listen to calls...the government does it all the time. They listen to our calls all the time without a court order."

This isn't just political mudslinging. These words come from someone who has operated at the highest levels of governance; a former minister and two-term governor with intimate knowledge of state security operations. His allegations carry institutional weight precisely because of this is insider perspective.

The Legal Framework vs. Reality

The legal framework for electronic surveillance appears comprehensive on paper.  Section 37 of the 1999 Constitution (as amended) guarantees the right to privacy  of  citizens,  their  homes,  correspondence,  telephone conversations  and  telegraphic  communications.

Furthermore, Section 12(1) of the Cybercrimes Act, 2015 (as amended) is explicit: "Any person, who intentionally and without authorization, intercepts by technical means, non-public transmissions of computer data, content, or traffic data... commits an offence and shall be liable on conviction to imprisonment for a term of not more than 2 years or to a fine of not more than N5,000,000.00 or to both."

The law makes no exception for government officials. The prohibition applies to "any person", a deliberate choice of words that encompasses both private individuals and state actors.

The Warrant Requirement

Section 39 of the Cybercrimes Act and the Lawful Interception of Communications Regulations, 2018 establish strict conditions for lawful interception. A judge may only authorize interception "where there are reasonable grounds to suspect that the content of any electronic communication is reasonably required for the purposes of a criminal investigation or proceedings."

The Regulations further specify that a warrant is necessary except in narrowly defined emergency situations involving: immediate danger of death or serious injury, activities threatening national security and organized crime activities.

Even in these emergency circumstances, Regulation 12(4) mandates that the authorized agency "shall apply for a Warrant to the Judge within 48 hours after the interception has occurred... and where the application is not made, or denied within 48 hours, the interception shall terminate immediately and further interception shall be treated as unlawful."

Who Can Request Interception?

Under Regulation 12(1) the Office of the National Security Adviser (represented by the NSA or designee not below Assistant Commissioner rank) or the State Security Services (represented by the Director or designee of equivalent rank).

Notably, the NSA, Nuhu Ribadu himself, is one of only the few officials empowered to seek lawful interception orders. This makes El-Rufai's allegation that Ribadu ordered his surveillance particularly significant: if such interception occurred without judicial authorization, the very official charged with seeking warrants lawfully may have bypassed the legal process entirely.

The Reality: Systematic Circumvention?

Yet El-Rufai's claims that "The government does it all the time. They listen to our calls all the time without a court order", suggest a pattern of systematic circumvention, not by rogue actors, but by the very state apparatus charged with upholding these laws.

If true, this represents a fundamental breakdown of the rule of law. The regulations impose severe penalties for non-compliance: N5,000,000 fines for violations, plus N500,000 daily penalties for continuing offenses (Regulation 16). These penalties apply to "any person, Licensee or its officers" again, no carve-out for government agencies. Section 12 of the Cybercrimes Act also criminalizes unlawful interceptions of communications.

The legal framework is therefore, clear. The alleged practice, as described by a former governor with insider knowledge, appears to violate it systematically. This gap between law and practice transforms surveillance regulations from protective shields into paper tigers which are enforced against citizens while ignored by those in power.

The Expanding Surveillance Infrastructure

El-Rufai's allegations align disturbingly with documented evidence of growing surveillance capabilities in Nigeria. According to research from the Institute of Development Studies, Nigeria has spent billions of dollars acquiring sophisticated surveillance technology. The country has procured systems capable of monitoring communications, tracking locations, and conducting mass data collection, often with minimal transparency or oversight.

The Berkman Klein Center at Harvard University reports that Nigeria's surveillance ecosystem includes partnerships with international technology vendors and deployment of invasive monitoring tools. These systems operate in what researchers describe as a legal grey zone, where the technological capacity for surveillance far outpaces regulatory frameworks designed to protect citizens' privacy.

The Harvard research notes that authorities have acquired tools for intercepting mobile communications, monitoring internet traffic, and collecting metadata on citizens' digital activities which is precisely the kind of warrantless surveillance El-Rufai now alleges is routine practice.

The Financial and Human Cost

The scale of investment in surveillance infrastructure is staggering. As the IDS study reveals, the country has channeled billions into surveillance technologies even as critical public services remain underfunded. This spending occurs largely outside public scrutiny, with procurement processes that lack transparency and accountability mechanisms.

More troubling still, these surveillance capabilities have allegedly been deployed not primarily for national security purposes, but for monitoring political opposition, civil society activists, and journalists. The Harvard analysis documents cases where surveillance tools have been used to target dissenting voices rather than genuine security threats. A pattern consistent with El-Rufai's claims about politically motivated monitoring.

The Accountability Vacuum

Lawyer Olajengbesi has called for security agencies to investigate El-Rufai's admission of listening to intercepted communications. But this raises the paradox at the heart of this affair: Who investigates allegations against the government when the government controls the investigative machinery?

The Harvard research highlights a critical gap in Nigeria's digital rights architecture: the absence of independent oversight bodies with real power to monitor and sanction state surveillance activities. While the Cybercrimes Act and the Lawful Interception of Communications Regulations, 2018 theoretically requires judicial authorization for interception, researchers found that compliance mechanisms are weak and enforcement is selective.

If El-Rufai's broader allegations are accurate, i.e., that warrantless mass surveillance of citizens' phone calls and online activities is routine government practice, then Nigerians face a surveillance state operating outside its own legal framework. The Cybercrimes Act and the Lawful Interception of Communications Regulations, 2018, becomes merely decorative legislation, enforced selectively against citizens while the state enjoys de facto immunity.

The Technology Behind the Surveillance

According to IDS findings, the government of Nigeria has acquired sophisticated interception systems capable of real-time monitoring of telecommunications networks. These systems can capture voice calls, text messages, and internet communications without leaving traces detectable to the targets. The infrastructure includes both passive collection systems and active interception capabilities and this makes El-Rufai's claim about routine, warrantless call monitoring technically plausible.

The Berkman Klein Center's investigation notes that telecommunications providers in Nigeria are often compelled to cooperate with security agencies, sometimes through informal pressure rather than legal process. This creates a system where lawful interception procedures can be bypassed entirely, with communications accessed directly through telecoms infrastructure.

What This Means for Digital Rights

This confrontation between political heavyweights inadvertently validates long-held suspicions within the digital rights community: that citizens' communications are subject to systematic, warrantless monitoring. Civil society organizations have raised these concerns for years, often dismissed as conspiracy theories. When someone of El-Rufai's stature; with decades navigating power corridors, makes such allegations, it demands serious attention.

The Harvard study emphasizes that unchecked surveillance powers fundamentally undermine democratic participation. When citizens cannot communicate privately, they cannot organize effectively, hold government accountable, or exercise their rights to free expression and assembly. The chilling effect of pervasive surveillance extends far beyond those directly targeted.

The Way Forward

1.   Independent oversight mechanisms for state surveillance activities with real enforcement power as recommended by researchers at IDS, including civilian oversight boards with subpoena power and security clearances to audit surveillance operations.

2. Transparency reports from telecommunications providers and security agencies about interception requests and warrants, a practice the Berkman Klein Center identifies as essential for accountability in democratic societies.

3. Judicial reforms ensuring that interception warrants are genuinely scrutinized, not rubber-stamped, with specialized courts trained in digital rights and surveillance law.

4. Legislative review of the Lawful Interception of Communications Regulations, 2018 to close loopholes enabling abuse and align the Regulation with international human rights standards.

5.  Equal application of cybercrime laws, whether the accused is a citizen or state actor.

6.  Public disclosure of surveillance procurement contracts and capabilities, as called for by civil society researchers, to enable informed democratic debate about surveillance powers.

Conclusion

The irony is stark: laws designed to protect electronic privacy may be routinely violated by those charged with enforcing it. While El-Rufai's own admission warrants investigation, his counter-allegations expose a potentially far graver systemic problem. The documented evidence of multi-billion dollar surveillance infrastructure in the country, combined with research showing weak oversight mechanisms, suggests El-Rufai may be revealing an open secret within the power elite.

Until the country establishes genuine accountability for state surveillance activities, the Cybercrimes Act and Lawful Interception of Communications Regulations, 2018 will remain what many fear they already are i.e., tools for controlling citizens rather than protecting their digital rights.

The question remains unanswered: In a democracy, when the government allegedly breaks the law on a mass scale, who investigates?

 

Sunday, 1 September 2024

The FBI's Exaggerated Claims of Going Dark: A Closer Look


 The FBI has often claimed that its ability to fight crime is being hampered by "going dark"—a term used to describe the challenges law enforcement faces when encrypted communications prevent them from accessing crucial evidence. According to former FBI Director James Comey on page 5 of the House Homeland Security Committee report titled: "Going Dark, Going Forward: A Primer on the Encryption Debate", “Going Dark” refers to the phenomenon in which law enforcement personnel have the “legal authority to intercept and access communications and information pursuant to court order,” but “lack the technical ability to do so.”

While encryption is an important tool for protecting privacy, the FBI's assertions of going dark have been criticized as exaggerated.

The FBI argues that encryption impedes investigations into serious criminal activities, from terrorism to child exploitation. They suggest that tech companies' refusal to create backdoors for law enforcement is creating a significant barrier to solving these crimes. This stance has fueled public debates and legislative efforts to mandate decryption capabilities.

However, critics argue that the FBI's claims are overstated. For one, there's little evidence that encryption has directly prevented major investigations. Many successful cases have been solved without requiring direct access to encrypted communications. One of such cases is the recent indictment of Seth Herrera for transportation, receiving and possession of child pornography.

According to Nate Anderson who writes for Ars Technica:

“I've never seen anyone who, when arrested, had three Samsung Galaxy phones filled with "tens of thousands of videos and images" depicting CSAM (child sexual abuse material), all of it hidden behind a secrecy-focused, password-protected app called "Calculator Photo Vault." Nor have I seen anyone arrested for CSAM having used all of the following: Potato Chat ("Use the most advanced encryption technology to ensure information security.") Enigma ("The server only stores the encrypted message, and only the users client can decrypt it.") nandbox [presumably the Messenger app] ("Free Secured Calls & Messages.") Telegram ("To this day, we have disclosed 0 bytes of user data to third parties, including governments.") TOR ("Browse Privately. Explore Freely.") Mega NZ ("We use zero-knowledge encryption.") Web-based generative AI tools/chatbots”

The indictment did not state in details exactly how Seth’s criminal activities were discovered. However, according to the indictment, Seth’s criminal conduct was finally uncovered after he tried to access a link containing apparent CSAM.  This link described CSAM  depicting  prepubescent  minor  females  around  the  same  age  as  Seth’s young daughter.

Anderson also observed that: “Presumably, this "apparent" CSAM was a government honeypot file or web-based redirect that logged the IP address and any other relevant information of anyone who clicked on it. In the end, given that fatal click, none of the "I'll hide it behind an encrypted app that looks like a calculator!" technical sophistication accomplished much.”

Despite Seth’s use of encrypted messaging applications such as Potato Chat, Enigma, nandbox, and Telegram, he was still found out by law enforcements presumably using honeypot file or web-based redirect that logged the IP address and any other relevant information of Seth Herrera when he clicked on it.

Therefore, Seth’s indictment clearly shows that in spite of the use of encryption messaging applications by criminals, there are still many other ways of unearthing their criminal activities without breaking encryption, therefore the “going dark” claim by the FBI can be said to be an exaggeration of the true state of affairs.

Also, the prosecution being cagey in the indictment, about exactly how the alleged criminal acts of Seth were discovered, reminds me of the Nigerian Police Force who, when announcing the arrest of some notorious criminals, would simply say they acted on "credible intelligence". They would rarely disclose the details of how and what was done that led to the arrest with the use of credible intelligence.

The going dark debate highlights a broader tension between national security and individual privacy. While it's crucial to support law enforcement in their efforts to combat crime, it's equally important to consider the potential risks of compromising encryption standards. Balancing these needs requires careful consideration and a nuanced approach to both technology and security policy.

Wednesday, 7 November 2018

A GREAT DAY FOR ATM USERS IN NIGERIA


In February, 2016, a customer of FCMB Ltd tried to withdraw the sum of N8,000 from the ATM of UBA Plc. The ATM dispensed cash but before he could take it, the cash was retracted, nevertheless N8,000 was deducted from his account with FCMB Ltd. Efforts by the customer to get a refund of the N8,000 failed, as UBA insisted that the ATM paid him. The customer thereafter sued both banks for breach of contract and negligence.

In the case: Barr. Timothy Tion v FCMB Ltd and UBA Plc (MHC/161/16), filed at the Benue State High Court on Friday 13th May, 2016, the Plaintiff (customer) asked the court for the following reliefs:
(i)                        A declaration that the debit of the Plaintiff’s account to the tune of N8,000.00 only (Eight Thousand Naira) even as he got no value for the transaction amounts to a breach of contract by the Defendant’s jointly and severally.
(ii)                    A declaration that the debit of the Plaintiff’s account to the tune of N8,000.00 only (Eight Thousand Naira) when he got no value for the transaction amounts to negligence by the Defendant’s jointly and severally.
(iii)                 An order directing the Defendants jointly and severally to forthwith refund the sum of N8, 000.00 only (Eight Thousand Naira) debited from the Plaintiff’s account in spite of the fact that the ATM which the Plaintiff carried out the transaction partially dispensed cash but retracted the cash before the Plaintiff could take it.
(iv)                  An order awarding to the Plaintiff against the Defendants jointly and severally damages of N10, 000.00 (Ten Million Naira) for the untold hardship and inconveniences suffered by the Plaintiff as a result of the unlawful conduct of the Defendants.
(v)                      10% Per Annum as allowed by the High Court of Benue State (Civil Procedure) Rules 2007 on the entire judgement sum from the date of judgement till the entire judgement sum is finally liquidated.

UBA in rejecting the Plaintiff’s claim tendered in evidence ATM Electronic Journal Logs, ATM Camera Snapshots, CCTV Footage and Snapshots whereas FCMB did not tender any evidence in disproving the Plaintiff’s claim but only argued that they acted on a debit alert sent to them via Interswitch network by UBA to deduct N8,000 from the Plaintiff’s account and that they have they have their own ATMs yet the Plaintiff chose to use that of UBA.

In entering judgement for the Plaintiff the court found that UBA failed to show that the ATM paid to the Plaintiff the amount he set out to withdraw. The court also found FCMB liable for breach of contract and negligence for acting on the debit alert from UBA without ensuring that Plaintiff was actually paid. The court equally found UBA negligent for causing the Plaintiff’s account to be debited, even when the ATM failed to pay him the cash he had requested to withdraw.

According to His Lordship Justice S. O. Itodo who delivered judgement in the case on September 26, 2018:
“There is no doubt, that between the plaintiff and the 1st defendant, a Banker/customer relationship exists by a contract. The plaintiff’s case that he was not paid was not disputed by the 1st defendant which contend that it took steps to unravel the issue and resolve same, and that the debit of the plaintiff's account was caused by the 2nd defendant. Granted that the 1st defendant was not directly responsible for the deduction of the plaintiff's account but that it acted on a signal or alert from a third party which is the 2nd defendant, what step did the 1st defendant take to ascertain the genuineness of the alert from the 2nd defendant. In other words, did the 1st defendant verify the alert sent to it before deducting or debiting the plaintiff’s account? There is no evidence by the 1st defendant of the steps it took (if any) to ensure that the plaintiff was paid the sum of money he set out to withdraw other than the electronic message it received before debiting the account. It is not its case, that this electronic message was fool proof and admit of no error or that there could not be mechanical failure in its operation.
His Lordship also stated that:
“The 2nd defendant’s witness in his oral testimony did not adduce evidence showing which of the exhibits identified the plaintiff, which of them showing the transaction, and which of them which show the payment of the money to the plaintiff. The court not being a party to the dispute cannot be expected to do that for the defendant. Even though the court may not do so but nonetheless did, that exercise did not show, and therefore disprove the plaintiff's assertion that he was not paid. In any case the 2nd defendant is mindful that the ATM operation may not in all cases be without controversy and dispute such as there is in the present case, hence it went the extra mile to install cameras whose photographs are exhibits tendered by it. However as has been demonstrated, the pictures have not shown that the plaintiff was paid the money he went out to withdraw. In the circumstance, the 2nd defendant, just like the 1st defendant, cannot say that it was not negligent in ensuring that the plaintiff was paid, as a duty of care was created by virtue of the 2nd defendant displaying and making its ATM available to the banking public and not only its customers.”
In conclusion His Lordship held that:
“…the plaintiff established and proved his case that the defendants were negligent in not ensuring that he was paid before deducting or debiting his account. Consequently Judgment is entered in his favour in terms of reliefs 46(1)(ii) (iii) and (v) while a further sum of Five Hundred Thousand Naira (N500,000.00) is awarded for the hardship and inconveniences suffered by him.”
This decision, unlike the one in Kume Bridget Ashiemar v. GT Bank Plc and UBA Plc, is a welcome relief to many bank customers in Nigeria who have experienced ATM dispense errors and failed to get a refund. It also demonstrates that customers can sue banks in such cases and get justice. The decision should therefore serve as a source of courage to bank customers in Nigeria who wish to sue errant banks.  Until the banks are sued and decisions given against them, the sole efforts of their regulator, the Central Bank of Nigeria, in ensuring that they serve their customers better may not be enough.

Tuesday, 12 June 2018

DOWNLOAD A COPY OF THE JUDGEMENT IN ATM DISPENSE ERROR CASE

>


On the 24th of May, 2018 a Benue State High Court, sitting in Makurdi, delivered judgement in the case of of KUME BRIDGET v. GTBANK PLC & UBA PLC (SUIT No. MHC/198/14). A case that has been reported as the "First Nigerian Case on ATM Dispense Error". A copy of the judgement has been obtained and can be downloaded here and here. Please download, read and make your comments and suggestions in the comments section of this page or send them to timoteetion@gmail.com.

Thursday, 24 May 2018

UPDATE AND MY INITIAL OPINION ABOUT THE JUDGEMENT IN KUME BRIDGET vs GTBANK PLC & UBA PLC


INTRODUCTION
A Benue State High Court of Justice, sitting in Makurdi, today the 24th of May, 2018, delivered judgement in the case of KUME BRIDGET v. GTBANK PLC & UBA PLC (SUIT No. MHC/198/14). The case involved a claim of failed ATM transaction as alleged by the plaintiff  and it was probably the first Nigerian case to seek to address the failure of ATM to dispense cash as other ATM cases had dealt with unauthorized ATM withdrawals. In unauthorized withdrawals the customer goes to the bank or ATM to make withdrawals and then learns that certain amount has been debited from his account or he is in possession of his ATM card and suddenly receives debit alerts on his account while in non-dispense or partial dispense of cash, the customer has sufficient funds in his account, attempts to make a withdrawal and the ATM does not dispense cash but his account is debited or dispenses less cash than that requested by the customer.

BRIEF FACTS OF THE CASE
The Plaintiff sometimes in October, 2013 attempted severally to withdraw money from the ATM of 2nd Defendant but according to the plaintiff the ATM failed to dispense cash nevertheless her account was debited. The Plaintiff claimed that on she had on 2nd October, 2013 withdrawn money and her account balance showed N95, 213.07. However, when she attempted to withdrawn N20,000.00 only on 3rd October, 2013 the machine displayed a message that she had insufficient funds. She further tried withdrawing N20,000.00 twice but the same message displayed. She left the ATM and came back to the same ATM on 4th October, 2013 to withdraw N20,000.00 and then N10,000.00 but the same message of the previous day was displayed. According to the Plaintiff she was engaged in some other pressing engagements so she was only able to make a complaint to her bank; the 1st Defendant (GTBANK Plc) on 8th October, 2013 as 5th and 6th were Saturday and Sunday respectively.

According to the defendants the withdrawal attempts were successful. Plaintiff disagreed and sued the Defendants. The Defendants relied on the debit entries in the Plaintiff’s Statement of Account, the ATM Electronic Journal Log of 2nd Defendant and the ATM Camera footages to contend that the ATM of the 2nd Defendant dispensed cash which was picked up by the Plaintiff. The 2nd Defendant also contended that the Plaintiff is not a credible witness because she failed to instantly report the failed transaction to her bank.

DECISION OF THE COURT
The court held that plaintiff failed to prove that the ATM of the 2nd Defendant (UBA Plc) didn't dispense cash to her the various times she attempted to make withdrawals. In reaching this conclusion the court found that the Plaintiff isn't a credible witness because she didn't report the alleged failed transactions until after 5 days. The court also relied on the debit entries in Plaintiff's Statement of Account and the entries of PIN entered, Cash Presented and Cash Taken recorded in the 2nd Defendant's ATM Electronic Journal logs regarding the Plaintiff's withdrawal transactions. The court further reasoned that the documentary evidence namely; the statement of account and ATM Electronic Journal log supersedes the oral evidence of the Plaintiff that she didn't get money from the ATM of 2nd Defendant.

The court in the judgement said it sympathised with the Plaintiff but that court judgements are based on law and evidence and not on sentiments.

OPINIONS
I had the opportunity of reading through ALL the processes filed in the case. In appraising the evidence in the case the court failed to consider the inconsistent entries in the ATM journal logs and the fact that both the 1st and 2nd Defendants' witnesses admitted under cross examination that entries or record of transactions in the ATM journal aren't always accurate or error proof, meaning that the court ought not to have attached much weight to such a piece of evidence that is not reliable even though it is documentary evidence, which is held to be superior to oral evidence.

The court also didn't appraise the ATM camera footage presented by the 2nd Defendant which didn't show the ATM of 2nd Defendant dispensing cash and the Plaintiff picking up the said cash. In fact the ATM camera images (still photos and not video recording) were so blurred that one could not make out the person in the photo and whether it was in front of an ATM, let alone the ATM of the 2nd Defendant). 

The court also failed to consider the admission under cross examination of both defendants’ witnesses that the Central Bank of Nigeria (CBN) in 2014 directed banks to refund to customers, monies trapped in ATMs as a result of ATM non-dispense or partial dispense errors.

POSERS
How can a bank customer be expected to successfully prove that the ATM of a bank didn't pay her cash when she attempted a withdrawal transaction but her account was nevertheless debited and the debit was recorded in her statement of account? On whom should the burden of proof lie in such a case? Who has  superior access, control and custody of evidence of a successful ATM withdrawal transaction; the bank customer or the bank? 

SOLUTIONS/ANSWERS TO POSERS
All you readers are enjoined to attempt answers or provide solutions to the posers above. After all, Anton Chekov, once said: “The task of a writer is not to solve the problem but to state the problem correctly.” I have stated the problem correctly so you readers provide answers. 

CONCLUSION
The judgement is a sad one for the multitude of ATM users in Nigeria who suffer from ATM non-dispense or dispense errors and which even the Central Bank of Nigeria is aware of and once directed the banks to refund  to customers, monies trapped in banks' ATMs due to partial or non-dispense errors. About two years after the initial directive by the CBN issued in 2014, it was reported that "inundated by complaints from bank customers over delays and most times non-reversal of dispense errors encountered during electronic transactions, CBN has said it will start monitoring banks to ensure that dispense errors are automatically reversed and the account of the customer credited."


Thursday, 9 November 2017

FAILED ATM TRANSACTION CASE: UBA WITNESS TESTIFIES, CASE ADJOURNED FOR ADOPTION OF FINAL WRITTEN ADDRESS




The Defence specifically, the 2nd Defendant (UBA Plc.), closed their case today in the very important test case of KUME BRIDGET ASHIEMAR v GT BANK PLC. &UBA PLC. (SUIT No. MHC/198/14). The case involves a claim of failed ATM transaction as alleged by the plaintiff  and it is probably the first Nigerian case to seek to address the failure of ATM to dispense cash as other ATM cases had dealt with unauthorized ATM withdrawals.

The Plaintiff sometimes in October, 2013 attempted severally to withdraw money from the ATM of 2nd Defendant but according to the plaintiff the ATM failed to dispense cash nevertheless her account was debited. According to the defendants the withdrawal attempts were successful. Plaintiff disagreed and sued the Defendants.

The Plaintiff opened her case, testified and was cross-examined, while the 1st Defendant opened their case on Thursday, 22nd June, 2017 calling their sole witness who testified and was cross-examined. The case was then adjourned to 20th July, 2017 for 2nd defendant to call their own witness to testify. On 20th July, 2017 the court did not sit. The case then suffered several adjournments between 20th July, 2017 and 9th November, 2017 owing the court going on its annual vacation and strike action by the Benue State civil servants.


However, today, 9th November, 2017, the 2nd Defendant proceeded to call her sole witness who testified and was cross-examined, after which the case for the Defence was closed. The case has now been adjourned to 21st December, 2017 for adoption of final written address. After the adoption of final written address the case would be slated for judgment. Whatever the court decides will go a long way in developing Nigerian law with regards to failed ATM transactions.

Thursday, 6 July 2017

Senator Ali Ndume, Computer Generated Evidence & Law Reporting


The case of Federal Republic of Nigeria v. Senator Mohammed Ali Ndume  is among the pioneer criminal cases that dealt with admissibility or otherwise of e-evidence or computer generated evidence e.g. call logs, SMS etc. under section 84 of the Evidence Act, 2011. In that case the trial court admitted some computer generated items in evidence but on appeal the evidence was ruled inadmissible. Therefore, the Court of Appeal judgements in Senator Mohammed Ali Ndume v. FRN delivered on 17/12/13 in Appeal No. CA/A/78/CR/2013 and CA/A/78A/CR/2013, are watershed cases with regards to interpretation or application of section 84 of the Evidence Act in CRIMINAL trials yet it seems that no law report in Nigeria has reported them.

The appellate court decisions ought to be reported so as to make them more readily or easily available to many lawyers and thus contribute to the development of our evidence law. The importance of many a lawyer having access to the appellate court judgement has become critical as many criminal trials, especially those involving highly placed persons, to a large extent is hinged on the admissibility or otherwise of text messages, call data records, bank statements and other forms of computer generated evidence. For instance one of the reasons for the court in upholding the no case submission in Ndume's case was the expulsion from evidence, certain computer generated evidence by the Court of Appeal, which pieces of evidence were vital to the prosecution’s case.

Also in the trial of Rickey Tarfa SAN on a two-count charge of obstruction of justice and attempting to pervert the course of justice, the prosecution tendered in evidence details of alleged telephone conversations and text messages between the accused and a High Court judge in an ongoing bribery case.

Furthermore, in the ongoing trial of Nwobike SAN by the EFCC on 11 counts bordering on perverting the course of justice and offering gratification to public officials, the accused was confronted with various text messages he was alleged to have sent to court officials to illegally influence court cases he was handling.

Thursday, 22 June 2017

UPDATE ON FAILED ATM TRANSACTION CASE

The very important test case of KUME BRIDGET ASHIEMAR v. GT BANK PLC. and UBA PLC. (SUIT No. MHC/198/14) is steadily making progress at the High Court of Justice of Benue State of Nigeria specifically High Court No. 7, sitting in Makurdi. The case seeks to address a trend which has bothered many bank customers in Nigeria. The case involves a failed ATM transaction or ATM non-dispense error as alleged by the plaintiff  and it is probably the first Nigerian case to seek to address failure of ATM to dispense cash as other ATM cases had dealt with unauthorized ATM withdrawals.

The plaintiff sometimes in October, 2013 attempted severally to withdraw money from the ATM of 2nd defendant but according to the plaintiff the ATM failed to dispense cash nevertheless her account was debited. According to the defendants the withdrawal transaction was successful. Plaintiff disagreed and sued the defendants.


The plaintiff opened her case and testified while the 1st defendant opened their case on Thursday, 22nd June, 2017 calling their sole witness who testified and was cross-examined. The case has been adjourned to 20th July, 2017 for 2nd defendant to call their own witness to testify.

Friday, 28 October 2016

ATM DISPENSE ERROR: COURT RULES THAT THERE IS CAUSE OF ACTION AGAINST FCMB ALTHOUGH ATM USED WAS THAT OF ANOTHER BANK

FCMB Ltd and UBA Plc were sued in May, 2016 by Barrister Timothy Tion; customer of FCMB Ltd, over non-dispense of cash when he attempted to withdraw money at the ATM of UBA Plc in February, 2016. The defendant banks filed their respective statements of defence in response to the suit by Barrister Tion. The 1st defendant (FCMB Ltd) also filed a preliminary objection urging the court to strike off its name from the case as the plaintiff has not disclosed any cause of action against her on the ground that the ATM where the disputed transaction occurred belongs to 2nd defendant (UBA Plc.) and not FCMB Ltd. Specifically, the 1st defendant in her P.O. contended:
1.That  the  transaction  that  gave  rise  to  this  suit  took  place  at  the ATM  Stand  of  the  2nd  defendant  and  not  the  1st  defendant’s  as clearly  stated  in  paragraph  5  of  the  statement  of  claim.
2.  That  the  1st  defendant  has  its  ATM Stand  for  the  use  of  its  various customers  including  the  plaintiff  and  the  plaintiff  wilfully  decided  to  use  the  2nd  defendant’s  ATM.
3.  That  the  report  from  the  2nd defendant  showed  that  the  2nd defendant’s  ATM  paid the plaintiff the  said  N8,000  and the  1st defendant  passed  same  information  to  the plaintiff.
4.  That  there  is  no  paragraph  of  the  statement  of  claim  that  disclosed a cause  of  action  against  the  1st defendant  in  this  suit.  This  can  be clearly shown from Paragraphs  5  to  46  of  the  statement  of  claim particularly  paragraphs  30  and  32  of  it.
The plaintiff also filed a reply in response to the P.O. filed by 1st defendant. Hearing of arguments of parties on the P.O. took place on the 17th October, 2016. The court on 27th October, 2016 dismissed the preliminary objection. Itodo J. on page 3 of the ruling stated thus:
The plaintiff, see paragraph 6’and 7 of his statement of claim, said that even though the 2nd defendants ATM. produced the sum of N8 ,000.00, which he viewed, before he could reach out to collect same, the machine retracted the money into its bowels, but nonetheless the 1st defendant debited his account with it upon report to that effect from 2nd defendant.        It is clear that the plaintiff is saying that he was not paid the sum and that the 1st defendant ought not to have debited his account as the report to that effect from the 2nd defendant to it was incorrect. It, of course stands to reason that if the plaintiff was indeed not paid his account should not be debited. This in my view appears to be the basis for suing the 1st defendant. On the other hand, if the plaintiff was paid, then he has no case against either of the defendants. It may be added that it was immaterial where the plaintiff chose to carry out his transaction.

The Plaintiff is to file his replies to the statements of defence filed by the defendants and his additional statement on oath after which a date would be fixed for pre-trial conference.

Friday, 30 September 2016

HISTORICAL CELL SITE LOCATION INFORMATION AND TELCOS IN NIGERIA


According to Wikipedia.com, a telco i.e. telephone company, telephone service provider or telecommunications operator:
is a kind of communications service provider (CSP) (more precisely a telecommunications service provider or TSP) that provides telecommunications services such as telephony and data communications access…With the advent of mobile telephony, telephone companies now include wireless carriers, or mobile network operators. Most telephone companies now also function as internet service providers (ISPs), and the distinction between a telephone company and an ISP may disappear completely over time, as the current trend for supplier convergence in the industry continues.

Historical cell site location information or mobile/cell phone location data is a collection of past connections between a mobile phone and cell towers or telecommunications masts. A cell site is mobile phone base station or antenna where radio signals are sent and received. In  the United States case of State v. Earls, it was stated that “Cell or (mobile) phones register or identify themselves with nearby cell towers every seven seconds. Cell providers (like MTN, Glo, Etisalat and Airtel in Nigeria) collect data from those contacts, which allow carriers to locate cell phones on a real-time basis and to reconstruct a phone’s movement from recorded data.”

Most times when you call the call centre of your GSM network provider or telco in Nigeria such MTN, Glo, Etisalat or Airtel, to make a complaint or inquiry, the customer care representative will ask you what town or city and local government you are calling from. I am usually taken aback by this question because they (telcos) already know or at least can approximate my location so why bother to ask me.

Whenever a mobile telephone makes a call, the call is routed through a cell site located at a fixed geographic location. Mobile telephone companies keep records of which cell site processes a call, and through this information law enforcement agents can locate the position of the SIM card, and therefore infer the location of the telephone user. This was used by the Nigerian Police to obtain the location of Timothy Dung, an armed robbery suspect in the case of The State v. Timothy Dung. On page three of the judgement it was stated thus:
According to the PW2 on the 20/8/2010 a case of armed robbery was transferred from the ‘E’ Division Police Station to the State Criminal Investigation Department (CID). PW1 volunteered a statement before the police.
According to the PW2 they swung into action by applying their detective mechanism to arrest the person because the line snatched was still going. Police applied to court to obtain a court order to serve Airtel/Zain who was the service provider of the line (Zain) snatched from the PW1. Airtel/Zain complied with the court order and released the coordinate to the Police. The coordinate enabled the Police to set a security trapping system that showed them the exact direction and position where the accused (that) was using that particular line at that time was standing. The system gave the latitude and longitude on google earth. lt shows(sic) that the accused person who was with the stolen line was at Abuja and the call history of the line after the robbery was within Abuja town and a town in Plateau State.  However, about three' days back, the line was showing that it, was in Abuja. The Police went to Abuja and the system directed them to Federal Fire Service in Abuja town and they went there. When the PW2 and his team called the number/line, it rang and the accused received the call. The PW2 then arrested the accused and interviewed him.
The case of United States v. Allums, also shows that telcos know or can estimate the location of their subscribers or customers at any given time using historical cell site location information (CSLI) or cell site analysis. James Edward Allums on 30th November, 2007, robbed a bank in Salt Lake City, Utah, United States. A bank employee dropped a chair from the second floor balcony onto Allums’ head as he stood brandishing a knife at a teller on the first floor.  In anger Allums removed his ski mask to look up and curse at the chair-dropper and in the process glowered directly into the surveillance camera. Allums had a mobile phone on him on 30th November.

Prosecutors introduced evidence that cell site tracking records showed that Allums’ phone, and presumably Allums, was located in close proximity to the bank and to two other locations also robbed by Allums. Thus, Allums was convicted on three counts of armed robbery.

Apart from historical CSLI mobile phone location can also be determined through GPS and mobile phone triangulation. At this juncture it is appropriate to state how mobile phone communications work as captured or explained in Re: Application for Telephone Information Needed for a Criminal Investigation:
Cell (mobile) phones operate through the use of radio waves.  To facilitate cell phone use, cellular service providers maintain a network of radio base stations—also known as cell towers (popularly referred to in Nigeria as mast)—throughout their coverage areas.
Whenever a cell phone makes or receives a call, sends or receives a text message, or otherwise sends or receives data, the phone connects via radio waves to an antenna on the closest cell tower, generating cell site location information (CSLI).  The resulting CSLI includes the precise location of the cell tower and cell site serving the subject cell phone during each voice call, text message, or data connection.  If a cell phone moves away from the cell tower with which it started a call and closer to another cell tower, the phone connects seamlessly to that next tower.
CSLI may be generated in the absence of user interaction with the cell phone. For example, CSLI may still be generated during an incoming phone call that is not answered.  Additionally, most modern smartphones have applications that continually run in the background, sending and receiving data without a user having to interact with the cell phone.
Indeed, cell phones, when turned on and not in airplane mode, are always scanning their network’s cellular environment. In so doing, cell phones periodically identify themselves to the closest cell tower—i.e., the one with the strongest radio signal—as they move throughout their network’s coverage area.  This process, known as “registration” or “pinging,” facilitates the making and receiving of calls, the sending and receiving of text messages, and the sending and receiving of cell phone data. Pinging is automatic and occurs whenever the phone is on, without the user’s input or control. A cell phone that is switched on will ping the nearest tower every seven to nine minutes. (Emphasis mine)
From the above it is crystal clear that CSLI can be used to estimate the location of an individual by identifying the nearest cell tower or mast and sector used when a call is made. It therefore presents circumstantial evidence of a person’s location.  This ability to locate a cell phone presents obvious benefits to law enforcement and intelligence authorities  as seen in the two cases referred to above. CSLI also poses a significant threat to privacy. Thus in State v. Earls (supra) the court observed that:
Advances in technology offer great benefits to society in many areas. At the same time, they can pose significant risks to individual privacy rights. This case highlights both principles as we consider recent strides in cell-phone technology. New improvements not only expand our ability to communicate with one another and access the Internet, but the cell phones we carry can also serve as powerful tracking devices able to pinpoint our movements with remarkable precision and accuracy.