Search
Africa edition

Explore Techsoma

Reporting on Africa’s technology economy.

Cybersecurity

How Breach Claims Can Strengthen Trust in Nigeria’s Digital Banking

In this story

A breach claim can affect customer trust long before investigators establish exactly what happened.

That creates a difficult problem for Nigeria’s digital banking industry. Customers do not see the security systems protecting their bank accounts or the controls operating behind their banking apps. They judge safety through their own experiences, what they hear about financial institutions and how banks respond when security concerns emerge.

This matters because trust is already becoming a major part of the digital banking experience. KPMG’s 2025 West Africa Banking Industry Customer Experience Survey found that only 33 percent of Nigerian banking customers felt very secure about how their digital transactions were handled, while 53 percent said they did not fully trust their bank’s digital platforms. The survey drew on responses from more than 35,000 retail customers, 5,000 SMEs and 600 corporate customers across Nigeria and Ghana.

The figures do not mean Nigerians have stopped using digital banking. In fact, digital payments continue to grow rapidly. They show that people can rely heavily on digital banking while still having concerns about how safe those services are.

That distinction is important when looking at the data breach claims involving Remita Payment Services, Sterling Bank and other entities that attracted regulatory attention earlier in 2026. The Nigeria Data Protection Commission said it opened an investigation to establish the nature and scope of the alleged incident, the categories of data involved and the risks to affected people. The investigation itself did not establish that every claim circulating about the incident was true.

Techsoma has already examined what those claims revealed about Nigeria’s cybersecurity coordination in its earlier analysis of the data breach claims. This article looks at a different part of the story.

The concern now is what breach claims do to customer confidence, how that confidence affects digital banking growth and what banks can do to protect trust when security concerns emerge.

Digital banking growth makes trust a business issue

Digital banking has moved well beyond being an alternative to visiting a physical branch. Nigerians now use banking apps and payment platforms to receive salaries, transfer money, pay bills, purchase goods, manage businesses and access other financial services. As more of these activities move online, customers have more personal and financial information tied to digital systems.

KPMG’s survey captured this change in Nigeria’s banking market. It reported that electronic payment transactions reached ₦1.07 quadrillion in 2024, representing almost 80 percent year-on-year growth. By the first quarter of 2025, transaction value had already reached ₦285 trillion.

That scale changes the meaning of a security incident. A customer does not need to experience a direct financial loss to become concerned about a bank’s security. A report that personal information may have been exposed can create fears about identity theft, phishing, account takeover and targeted scams. Those fears can influence how much information customers share, how much money they keep in an account and how willing they are to use a particular digital service.

The World Bank identifies trust as one of the key factors influencing adoption of digital financial services. It also points to consumer awareness, timely dispute resolution, effective consumer protection and strong regulatory supervision as factors that help build trust in digital finance.

This means banks should not treat trust as something separate from their technology strategy. A customer who does not trust the security of a digital service has less reason to use more of its features, even when those features offer greater convenience.

A breach claim can influence behaviour before the facts are settled

There is a clear difference between a confirmed data breach and an allegation that a breach occurred.

A confirmed breach requires evidence that an unauthorised person accessed, obtained, altered or exposed protected information. A claim still requires investigation. That distinction matters for responsible reporting because presenting an allegation as a fact can unfairly damage an institution and create unnecessary fear among customers.

Customers, however, do not always encounter these claims in a controlled environment.

A person may first see a screenshot on WhatsApp, a post on X or a message from a friend. Another customer may encounter the story through a news report before the bank has issued a detailed response. The customer then has to decide whether the information is credible, whether their own account is affected and whether they need to take action.

This uncertainty can produce several reactions.

  1. Customers may become more cautious with the affected institution: A customer who believes their information may have been exposed can reduce the amount of money they keep in an account or move some transactions elsewhere.
  2. Customers may become more vulnerable to follow-up scams: Criminals can use public concern about a breach to send fake security messages that ask people to click links, disclose passwords or provide one-time passwords.
  3. Customers may judge the bank by its response: A careful and informative response can reduce uncertainty, while silence or vague communication can leave customers relying on speculation.
  4. Customers may generalise the concern: People who hear repeated stories about financial data exposure may begin to question digital banking platforms beyond the institution named in a particular report.

The World Bank warns that data theft can expose financial customers to identity theft and fraud while creating reputational damage for financial institutions. It also notes that protecting customer data helps maintain confidence in digital financial services.

That makes the public response to a breach claim important even when investigators have not completed their work.

Customers need useful information when security claims emerge

Banks cannot disclose every detail of an ongoing investigation. Sharing sensitive technical information can create additional security risks, and investigators often need time to establish the facts.

They can still communicate clearly. Customers need to know what the institution has confirmed, what remains under investigation and what they should do to protect themselves. A bank does not need to make an unsupported statement that everything is safe. It needs to explain what it knows and what it is doing to establish what it does not yet know.

A useful response should cover five areas.

  • The status of the claim: The institution should distinguish between confirmed facts, allegations and issues that remain under investigation.
  • The type of information involved: If an investigation confirms that customer data is affected, the institution should explain the relevant categories in simple language.
  • The steps already taken: Customers should know whether the institution has contained the incident, secured affected systems or engaged regulators and security specialists.
  • The action customers should take: Where customers face a specific risk, the bank should give clear instructions rather than leaving people to interpret technical statements.
  • The next update: If an investigation remains open, customers should know when and where they can expect further information.

Nigeria already has a regulatory basis for this type of response. The Nigeria Data Protection Act requires a data controller to notify the NDPC within 72 hours of becoming aware of a breach that is likely to create a risk to people’s rights and freedoms. Where the breach creates a high risk, the affected individuals should also receive notification.

The rule is important because it shifts data breach response away from a purely internal business decision. Serious incidents can create obligations to regulators and affected people.

That strengthens accountability and gives customers a better chance of receiving useful information when their data may be at risk.

Security controls should give customers confidence

Much of the security work inside a bank remains invisible to the customer.

A customer sees an authentication screen when logging into an app. The bank sees the systems checking the device, location, transaction history, account behaviour and other signals in the background.

That creates an important communication challenge. Banks need strong security controls, but customers also need enough understanding to recognise why those controls exist.

For example, additional verification when a customer uses a new device can feel inconvenient when the bank does not explain. The same control can feel protective when the bank clearly explains that it helps prevent criminals from accessing an account after obtaining someone’s login details.

The Central Bank of Nigeria’s 2024 Risk-Based Cybersecurity Framework recognises the importance of this approach. The framework requires supervised financial institutions to establish cybersecurity programmes covering governance, risk management, resilience, emerging technologies, monitoring, reporting and regulatory compliance. It also states that growing reliance on technology has increased financial institutions’ attack surface.

The CBN’s own 2024 Financial Stability Report also said its revised cybersecurity framework was intended to strengthen cybersecurity governance, risk management and overall resilience in banks.

The challenge for banks is to turn these internal controls into something customers can experience.

Customers may never see a bank’s security operations centre. They can see when a suspicious transaction triggers an alert, when a new device requires additional verification and when a fraud complaint receives a quick response. Those experiences shape trust.

Falling fraud losses show that stronger controls can work

Nigeria’s digital banking industry has evidence that security investments can produce better outcomes.

NIBSS reported that digital payment fraud losses fell to ₦25.85 billion in 2025, a 51 percent decline from ₦52.26 billion in 2024. It also reported that the number of fraud cases fell over the five years ending in 2025, although the value of losses remained a concern.

The decline does not mean the problem has disappeared. It does show why financial institutions should continue investing in controls that prevent and detect fraud.

Customers experience those controls in practical ways. They receive alerts when unusual activity occurs. They face additional checks when a transaction looks suspicious. They can report unauthorised activity through their bank’s support channels.

A strong digital banking security model should therefore protect the customer at several points.

  1. Account opening should include reliable identity checks: Strong verification reduces the opportunity for criminals to create fraudulent accounts or impersonate legitimate customers.
  2. New devices should receive additional scrutiny: Device changes can become an entry point for account takeover, so banks need controls that detect unusual access.
  3. Transactions should receive real-time monitoring: Systems need to identify unusual behaviour quickly enough for banks to intervene before losses become larger.
  4. Customers should receive useful alerts: An alert that arrives quickly and clearly can help a customer identify suspicious activity before more transactions occur.
  5. Fraud complaints should receive prompt attention: Customers judge the bank by what happens after they report a problem, not just by the technology that failed before the problem occurred.
  6. Recovery should form part of security planning: A customer needs to know what the bank will do after an account becomes compromised and what support the customer can expect.

These measures also fit the World Bank’s view that effective consumer protection and robust security measures can make digital financial services safer and encourage greater trust and usage.

Security therefore has a direct connection with customer experience.

Banks also carry responsibility for their technology partners

A digital banking service rarely depends on one organisation.

Banks work with payment processors, fintech companies, cloud providers, identity verification companies, telecommunications providers and other technology vendors. These relationships allow banks to offer more services and process more transactions, but they also create additional points where data and systems can interact.

For organisations handling personal data in Nigeria, understanding registration requirements for data controllers and processors is also part of meeting data protection obligations.

The customer usually does not know which company handles a particular part of a transaction. They know the bank they chose.

That means a bank’s responsibility for customer trust does not end at its own technical infrastructure. A security weakness at a third-party provider can still create questions about the bank’s ability to protect its customers.

The CBN’s cybersecurity framework recognises third-party and outsourcing risks as part of financial institutions’ wider cybersecurity responsibilities.

The World Bank similarly notes that cyber threats can enter financial market infrastructure through participants, connected systems, service providers and vendors. It describes the resilience of payment systems as important to continued trust in digital financial services.

This is why financial institutions need stronger vendor oversight. They should assess the security practices of critical technology partners, define clear incident reporting obligations and know how quickly a third party can notify them when a security problem occurs.

Customers may never know that these checks happen. That is exactly why banks need to do them well.

Regulation can support growth by giving customers stronger protection

Regulation is sometimes discussed as a burden on financial institutions, particularly when banks and fintech companies want to launch new digital products quickly.

For customers, however, effective regulation provides something they cannot create themselves. It establishes minimum expectations for how financial institutions should protect their money, data and rights.

A customer cannot inspect a bank’s cybersecurity programme before opening an account. They cannot audit the payment processor handling a transaction. They cannot assess whether a bank has tested its incident response plan.

Regulators can perform part of that oversight.

The World Bank describes financial consumer protection as important not only for protecting customers but also for the healthy development of the financial sector, financial inclusion and broader economic growth. It also says effective complaint handling and dispute resolution can improve trust and adoption of digital financial services.

Nigeria’s regulatory framework therefore has a role beyond enforcement.

Clear requirements help responsible financial institutions understand what they need to build. Effective enforcement gives customers greater confidence that financial institutions must take their responsibilities seriously. That creates a stronger foundation for digital banking growth.

Banks should measure trust alongside transaction growth

Banks already monitor transaction volumes, active users, customer complaints, failed payments and other operational measures.

Customer trust deserves the same attention.

The KPMG finding that 53 percent of surveyed customers did not fully trust their bank’s digital platforms should encourage banks to investigate why customers feel that way. The industry cannot assume that high transaction volumes automatically mean high confidence.

A bank can measure trust through several areas.

  • Security confidence: Do customers feel safe when they use mobile and internet banking?
  • Privacy confidence: Do customers understand how their personal and financial information is handled?
  • Incident confidence: Do customers believe their bank will communicate clearly when a security incident occurs?
  • Complaint confidence: Do customers believe the bank will take their concerns seriously when fraud happens?
  • Recovery confidence: Do customers believe the bank will help them recover when an account becomes compromised?

These questions reveal a part of customer behaviour that transaction numbers cannot show.

A person can use a banking app every day because it is convenient while still believing that the platform is not completely safe.

That gap matters because trust becomes more important as banks introduce new digital products and ask customers to conduct more of their financial lives online.

Better incident response can turn concern into confidence

Banks cannot guarantee that criminals will never target their systems.

The more realistic standard is whether an institution can detect an incident, contain it, protect customers and communicate accurately while investigators establish the facts.

That requires preparation before an incident occurs.

A strong incident response plan should establish who makes decisions, how technical teams escalate a problem, how regulators receive information and how customer communication works. Banks also need to test those plans instead of leaving them as documents that staff rarely use.

The reason is simple. A security incident creates pressure across several departments at once. Security teams need to investigate the technical problem. Legal and compliance teams need to assess regulatory obligations. Customer service teams need to respond to worried customers. Communications teams need to explain the situation without compromising the investigation.

Without preparation, these teams can give customers conflicting information.

The World Bank’s digital finance guidance places strong emphasis on cybersecurity resilience and effective responses to threats because financial systems need to remain trustworthy even when attacks occur.

Nigeria’s data protection rules also give organisations a clear framework for responding to serious personal data breaches. The NDPC’s guidance requires prompt notification when the relevant risk threshold is met.

Good incident response therefore protects more than systems. It protects the relationship between the institution and its customers.

Trust will shape the next stage of Nigeria’s digital banking growth

Nigeria’s digital payment system has already reached a scale that makes customer trust an industry-wide concern.

KPMG reported that electronic payment transactions reached ₦1.07 quadrillion in 2024, while NIBSS has reported significant growth in instant payment activity. The more Nigerians depend on digital channels for everyday financial activity, the more important it becomes for those channels to feel secure and dependable.

Breach claims should therefore not be treated only as reputational problems for individual companies.

They should prompt the industry to examine whether customers understand how their data is protected, whether banks respond properly when security concerns emerge and whether customers have effective ways to report and recover from fraud.

The strongest response is not to tell customers that nothing can go wrong. No financial institution can make that promise honestly.

The stronger approach is to show customers that the institution has systems in place to reduce risk, detect suspicious activity, contain incidents and support customers when problems occur.

That is where regulation can help the industry grow.

The CBN’s cybersecurity requirements establish minimum controls for supervised financial institutions. The NDPC’s data protection rules create obligations around the handling and protection of personal information. NIBSS data shows that fraud losses can fall when the financial ecosystem improves its defences. The World Bank’s work on digital finance reinforces the link between security, consumer protection and trust.

For Nigerian banks, the opportunity is to turn these requirements into something customers can feel in everyday use.

That means clearer communication when security concerns arise, stronger protection across third-party relationships, faster responses to fraud complaints and security controls that protect customers without making digital banking unnecessarily difficult.

Digital banking has already won customers through speed and convenience.

The next stage of growth will depend heavily on whether customers believe the systems handling their money and personal information deserve their confidence.

Breach claims can weaken that confidence, but they can also expose where the industry needs to improve.

If banks, payment companies and regulators respond with stronger safeguards, clearer communication and better customer protection, those improvements can make digital banking more trusted and more resilient.

That is good for customers, and it is also good for the long-term stability and growth of Nigeria’s digital financial sector.

Share this storyLinkedIn X

Our reporting follows our editorial standards. To report an error, see our corrections policy.

Welcome Back!

Login to your account below

Retrieve your password

Please enter your username or email address to reset your password.

From the newsroomAfrica, in focus.

The Techsoma Briefing.

The companies, ideas and people shaping African tech.
A considered read, straight to your inbox.

The Techsoma Briefing

One last step

Check your inbox.

Open the email from Techsoma and confirm your subscription to start receiving the briefing.

Can’t find it? Check your spam or promotions folder.

The Techsoma Briefing

For curious minds

Africa’s tech story.
In your inbox.

The companies, ideas and people worth following. Get the Techsoma Briefing for free.

By signing up, you agree to receive Techsoma emails. Unsubscribe anytime. Privacy policy