Terrorists Exploit Dead Persons’ Accounts, Crowdfunding To Fund Operations – NFIU
By Sabiu Abdullahi
The Nigeria Financial Intelligence Unit has uncovered new methods allegedly used by terrorist financiers to raise, transfer and conceal funds for operations in Nigeria.
The agency said its investigations found that terrorist networks were exploiting crowdfunding platforms, proxy bank accounts, mobile banking services and telephone numbers registered to people other than the actual account beneficiaries.
The findings were contained in the NFIU’s 2025 Annual Report, which highlighted emerging links between terrorism financing, financial technology and cross-border money transfers.
According to the report, foreign-based facilitators were using social media to solicit donations under the cover of humanitarian assistance or educational programmes before transferring the proceeds through several channels to terrorist operatives.
The NFIU said the facilitators often encouraged large numbers of sympathisers to make small payments, with individual donations ranging from $50 to $500. The amounts, it said, were deliberately kept below levels that could trigger automated anti-money laundering alerts.
“The following is a case study on Crowdfunding Network identified during the year: A foreign-based facilitator runs social-media campaigns claiming humanitarian relief or educational support and uses encrypted apps (Telegram, Signal) to share links to convincing PayPal pages or standard bank accounts.
“Hundreds of sympathiser donors contribute $50–$500 each, amounts small enough to avoid most automated AML alerts,” the report read.
The agency said the money was later consolidated in a master account controlled by a senior member of the network who resides legally outside Nigeria.
“When the pool reaches a threshold, that account becomes the hub for onward movement,” the report stated.
From the master account, the funds were divided into smaller transactions and sent through International Money Transfer Operators and remittance applications to individuals in Nigeria who served as money mules.
The NFIU listed students, small-business operators and relatives among those allegedly used for the transfers. It said the arrangement helped the financiers avoid reporting requirements and make it difficult to establish the source and destination of the funds.
“Rather than sending one large transfer, the senior member fractures the funds and sends dozens of sub-threshold payments through IMTOs and remittance apps to a network of money mules in Nigeria; students, small-business owners, or relatives, avoiding reporting triggers.
“Upon receipt, the money was either converted to cash, used to purchase dual-use items such as motorcycles, fertilisers and satellite internet equipment, or transferred through mobile banking channels to logistics managers and field operatives,” it added.
The report described the final movement of the money into terrorist activities as the “integration” stage.
The NFIU also raised concerns about what it described as gender-based proxy accounts. It said terrorist financiers were opening accounts in women’s names while male commanders or logistics officials controlled the accounts.
“Terrorist financiers are opening bank accounts in women’s names while male commanders and logistics managers secretly control them.
“They exploit cultural norms that make women less likely to be suspected by authorities, using wives, sisters, or female associates as fronts to distance illicit funds from the true operatives.
“This tactic functions as identity laundering: women’s accounts are managed by men who hold ATM cards, mobile-banking credentials, and PINs, while the women often remain unaware of the transactions and volumes,” the report stated.
The agency further said some terrorist facilitators used telephone numbers that were not registered to the actual account holders or beneficiaries for mobile banking and transaction alerts.
According to the report, pre-registered SIM cards, numbers linked to deceased persons and SIM cards associated with gender-based proxies were used to weaken the connection between bank accounts, SIM cards and Bank Verification Numbers.
“Terrorist facilitators use phone numbers for mobile banking or account alerts that are not registered to the account holder or the true beneficiary.
“They bypass the security link between SIM cards and BVNs by using pre-registered SIMs, SIMs registered to deceased people, or SIMs tied to gender-based proxies. This severs the audit trail: when a transaction is flagged, investigators trace the phone to an unrelated person, letting the real facilitator stay anonymous and continue operations,” it stated.
The NFIU also identified coded and detailed transaction descriptions as another method used to conceal terrorist financing.
It said some terrorist cells, particularly those associated with the Islamic State West Africa Province, used professional-looking descriptions for transactions as part of an internal financial management system.
“Terrorist cells, particularly those linked to ISWAP, routinely use precise, professional-sounding transaction narrations to maintain internal accounting. Operating like “shadow states” with strict bureaucratic controls, they require detailed descriptions so field commanders can justify expenses to central financial controllers. Although truthful narrations appear counterintuitive, they create an internal audit trail; analysts repeatedly observe high-frequency, logistics-related payments with accurate narrations sent from a single source to multiple recipients,” the report said.
However, the Unit said other facilitators relied on ordinary expressions, secret codes and combinations of letters and figures to conceal the purpose of transactions. Some also switched between languages to avoid automated banking filters.
“Transaction descriptions employ innocuous words, secret codes, or alphanumeric strings to conceal intent. Facilitators use this coded language, often switching languages to evade banks’ automated keyword filters that flag terms like ‘Jihad,’ ‘Arms,’ or ‘Boko.’
“This practice obscures the true purpose of transfers, preventing detection and enabling continued financing,” it said.
Beyond terrorism financing, the NFIU said its analysis showed an increasingly connected threat involving financial crimes, technology and international transactions.
The Unit identified fraud as a major underlying offence, with Ponzi schemes, fraudulent crowdfunding, cryptocurrency investment scams and hacking-related fraud among the growing threats.
It said criminals were also exploiting weaknesses in fintech account registration, including account categories with limited identification requirements, to recruit victims and move funds quickly.
The report also pointed to continued risks in public financial management, including the diversion of government funds through accounts belonging to finance officials and third parties.
It identified procurement and cash transactions as major areas of concern because large cash movements can make it difficult to establish audit trails and trace assets.
The NFIU said its findings had informed advisories, alerts and intelligence reports provided to relevant authorities, financial institutions and policymakers.
“Financial Fraud and Investment Scams: Fraud remains a dominant predicate offence, with notable growth in Ponzi schemes, fraudulent crowdfunding arrangements, cryptocurrency-enabled investment scams, and hacking-related fraud (including compromised social media and messaging accounts).
“Analytical reviews during the period examined these trends and informed internal advisories and alerts, some of which remained restricted for operational purposes.
“These schemes increasingly exploit fintech onboarding gaps, including tiered accounts with minimal identification requirements, and leverage digital platforms to rapidly scale victim recruitment and fund movement.
“Corruption and Misappropriation of Public Funds Analysis highlighted persistent vulnerabilities in public sector financial management, including the diversion of state and local government funds through accounts of finance officers and associated third parties.
“Procurement processes remain a significant risk area, while utilisation of cash transactions complicates audit trails and asset tracing efforts,” the report said.
A security expert, Chidi Omeje, urged Nigeria’s security and financial intelligence agencies to strengthen their methods as criminal networks develop more sophisticated ways of evading existing controls.
Omeje said criminal groups were constantly seeking weaknesses within the country’s security and financial systems.
He called on the Nigeria Police Force, Department of State Services and financial regulatory bodies to improve monitoring of financial transactions and intensify efforts to trace illicit funds.
“Every single day, these guys grow in sophistication and desperation, and we must also devise means to bring them to their knees.
“The state must ultimately deal with them. They must follow the money trail to monitor these movements and effectively tackle the situation,” he said.
Omeje said intelligence-led investigations and financial tracking were essential to preventing criminal groups from gaining an advantage over the state.
Another security analyst, Lawrence Alobi, called for stronger cooperation between security agencies and financial institutions.
Alobi said better intelligence gathering would help authorities identify fraudulent accounts and other methods used by criminal networks to avoid detection.
“It behoves us now, the security agencies, to intensify their intelligence sharing and information gathering, because it is through information that we can get some of these things.
“Security agencies need to work with the banks and also warn them. Any bank found to have connived or aided this act should be sanctioned,” he said.
He also urged banks to strengthen their identity verification systems and ensure that account holders were genuine beneficiaries rather than proxies.
“The banks themselves must sit up and ensure they properly verify every individual’s identity so that there is a real, verifiable person behind every account, not just someone acting by proxy. Intelligence agencies must go the extra mile to hold banks accountable for any loopholes exploited within their system,” he added.
