In March 2026, a major Rwandan bank detected irregular transactions worth roughly Rwf 4.7 billion (about USD 3.4 million) moving out through its mobile money channel. The bank's monitoring systems triggered quickly: most of the suspicious transactions were reversed within 24 hours, and the bank confirmed that customer deposits remained secure. By mid-March, at least 35 suspects were in custody in the investigation led by the Rwanda Investigation Bureau, and six people believed to be connected to the fraud had been arrested in Uganda.
No customer funds were lost, and the institution deserves credit for how quickly it responded.
The incident also exposed attack patterns and weaknesses that are not specific to one bank. The routes reportedly exploited in this case (a third-party vendor platform, the mobile money float system and gaps in transaction monitoring) exist across the East African financial sector. This article sets out what every bank, microfinance institution and fintech in the region should now review.
The attack pattern
Based on the details reported by Taarifa, Techweez and ITWeb Africa, the fraud followed a pattern that should concern every financial institution in East Africa:
- Third-party entry point: The suspected initial access came through a vendor-supplied internet-banking platform used under licence rather than through systems the bank built itself. Investigators were still examining exactly how the platform was exploited, but the vendor layer was the suspected weak link.
- Mobile money float exploitation: Funds were moved through bulk mobile money float purchases, using SIM cards with no prior transaction history. A bank official told Taarifa that single SIM cards bought float worth up to Rwf 100 million (about USD 72,000), and that "some of those SIM cards had never previously received even Rwf 1,000".
- Routing around transfer limits: Normal daily bank-to-wallet transfers were capped at roughly Rwf 2 million, so moving Rwf 4.7 billion through standard channels would have required thousands of individual transactions. Bulk float purchases bypassed those per-transaction caps entirely.
- Possible insider involvement: Two bank IT staff with data centre roles were among those detained, although investigators stressed that detention does not establish involvement. Either way, the case raises questions about access controls and the monitoring of privileged users.
Each of these attack vectors exists at other institutions in the region, so the useful question is whether your own defences would hold.
Five things to review
1. Your third-party vendor attack surface
Most banks in East Africa depend on external vendors for core banking, internet banking, mobile banking and payment switching. These platforms often have direct access to customer data and transaction processing, yet they rarely receive the same security scrutiny as internally developed systems.
If your vendor-supplied platforms have never been penetration tested, or were last tested before deployment, that is a gap.
Action: Include all third-party vendor platforms in your next penetration testing scope. Test them with the same rigour you apply to your own applications. Review vendor access credentials and ensure they follow the principle of least privilege. We cover how to structure this work in our guide to third-party vendor security assessments.
2. Mobile money integration security
The bank-to-mobile-money channel is one of the most actively exploited attack surfaces in East African banking. Business logic flaws in this layer, such as inadequate velocity checks, weak SIM validation or exploitable float purchase mechanisms, are difficult to find with automated scanning tools. Finding them takes manual testing by people who understand how mobile money works in this market.
Action: Commission a focused API penetration test of your mobile money integrations. Test specifically for business logic flaws: transfer limit bypasses, velocity check evasion, SIM registration validation and float manipulation.
3. Transaction monitoring rules
In this case the monitoring systems did fire, and quickly. But the reported pattern (bulk float purchases from SIM cards with no transaction history, single SIMs buying float worth tens of millions of francs, rapid cross-channel movement) is the kind of signal that well-tuned rules can catch at the first transaction rather than the hundredth.
Most transaction monitoring systems are configured to catch known fraud patterns. They often miss novel ones, especially patterns that exploit the specific mechanics of East African mobile money.
Action: Review your transaction monitoring rules against this specific attack pattern. Add rules for transactions from SIMs with no prior history, unusual float purchase volumes, rapid bank-to-wallet transfers from a single source and cross-channel velocity that exceeds normal customer behaviour.
4. Privileged access controls
The detention of two data centre staff in this investigation, whatever the eventual findings about their involvement, highlights a risk that many institutions under-manage: insider access. In many banks, IT staff have broad, persistent access to production databases, payment switches and admin interfaces without adequate logging, alerting or time-based access restrictions.
Action: Audit who has standing access to production systems. Implement just-in-time privileged access where possible. Log and alert on all administrative access to critical banking infrastructure. Ensure separation of duties between those who administer systems and those who can initiate transactions.
5. Incident response readiness
This institution detected the fraud and reversed most of the suspicious transactions within 24 hours. That is a strong response, and a useful benchmark for your own team.
Many banks in the region have incident response plans on paper that have never been tested. When a real incident hits, untested plans fall apart at the first decision point.
Action: Run a tabletop exercise simulating a similar scenario: vendor platform compromise, mobile money channel exploitation and a high volume of transactions in progress. Measure your team's time to detect, contain and communicate. If you have never done this, start with our guide to incident response planning for East African institutions.
The regulatory context
In Rwanda, most of the reviews above also map directly to a regulatory obligation. Regulation N° 50/2022 of the National Bank of Rwanda (BNR) requires BNR-regulated financial institutions to run a penetration test at least annually and vulnerability assessments at least twice a year, with an executive summary of findings filed with BNR within 15 days of the test and an annual statement of self-assessment due by 15 January. The regulation also names six qualifying credentials for testers, OSCP among them. Institutions outside BNR's licence perimeter are not bound by the regulation, but its requirements are a sensible baseline for any financial institution in the region.
An incident of this profile is likely to sharpen supervisory attention on vendor security practices and mobile money channel controls across the sector. Institutions that cannot demonstrate recent, thorough security assessments of their full technology stack, including vendor platforms and mobile money integrations, should expect difficult conversations with their regulators. We break down the filing mechanics and tester requirements on our BNR-compliant penetration testing page.
What an incident like this costs
Even when customer deposits are protected, the institution carries the bill. In this case, Taarifa reported that roughly Rwf 1.2 billion of the Rwf 4.7 billion had been recovered at the time of writing, with the remainder still under recovery. Add the forensic investigation, the regulatory engagement, legal proceedings in two countries and the reputational exposure, and the true cost runs far beyond the headline figure. We examine the full cost picture in what a data breach costs an East African bank.
The vendor-platform, mobile-money and insider-access vectors exposed here are not specific to Rwanda; they recur wherever digital banking grows faster than security maturity. A targeted security assessment costs a small fraction of any single line item above.
How we can help
IMIZI Cyber is a Kigali-based firm providing manual penetration testing for banks, fintechs, telecoms, government and healthcare institutions across Africa. We focus on the areas this incident exposed (mobile money integration security, vendor platform assessment and business logic testing for financial applications) and report in a form a board and a regulator can both act on.
If this incident has prompted you to review your own security posture, we can move quickly to scope a targeted assessment that gives you a clear view of where your institution stands and what needs attention first.
For details on what a full security assessment covers, see our security assessments service page. For penetration testing of specific applications and infrastructure, see our penetration testing service page. When you are ready to talk, Book a Free Call.