No firewall got breached. No malware got planted. According to Nigeria’s Economic and Financial Crimes Commission, a First City Monument Bank staff member with a company laptop and legitimate administrative credentials simply sold access to his own employer’s systems, in two separate transactions, for a combined $25,000. The case, now before the Federal High Court in Lagos, is a rare, fully documented example of exactly the kind of threat that no amount of technical security spending fully solves on its own: a person with real, authorised access deciding a payday beats their job.
What Aghogho Is Accused of Doing
The EFCC’s Lagos Zonal Directorate 1 arraigned Gideon Bakpa Aghogho, an FCMB staff member, alongside Oscar Ebere Chukwuebuka on August 19. According to the charge sheet, the alleged scheme played out in two distinct acts nearly fourteen months apart. Between April and May 2025, Aghogho is accused of knowingly disclosing FCMB’s internal server IP address and domain credentials without authorisation, allegedly receiving $15,000 for the information. Then, between July 24 and 26, 2026, prosecutors allege he supplied his own local Administrative Credential, tied to FCMB’s Virtual Center Platform, for a further $10,000. The two men, along with a third individual identified only as Scott, who remains at large, allegedly then attempted to use an HP Elite laptop FCMB had issued directly to Aghogho as the actual working tool to try accessing the bank’s database.
Where the Case Stands
The EFCC filed an eight-count charge covering conspiracy, unauthorised access to a computer system, illegal disclosure of access credentials, attempted interception of a network database, and retention of proceeds from unlawful activities, brought under Nigeria’s Cybercrimes Act. When the charges were read before Justice F.S.N. Ogazi, Aghogho pleaded not guilty, while Chukwuebuka pleaded guilty. That split plea matters for how this case should be read going forward: Chukwuebuka’s guilt is established by his own plea, while the allegations against Aghogho remain exactly that, allegations, until a trial concludes.
The Detail That Reframes the Whole Story
One line in the charge sheet is easy to miss and probably the most interesting part of the entire case. Of the $25,000 the scheme allegedly generated, prosecutors say Aghogho personally retained just $2,000, and Chukwuebuka kept only $400. That leaves more than $22,000 unaccounted for in what either man is accused of actually pocketing, a strong signal that whoever orchestrated this, quite possibly Scott, the still-at-large third party, walked away with the overwhelming majority of the payout while the insider who actually took on the legal risk kept a small fraction of it. If that reading holds up, the case looks less like an employee running his own lucrative side hustle and more like a low-level access holder being used, and underpaid, by whoever was actually positioned to exploit that access for real financial gain.
Why This Should Worry Anyone Building Financial Infrastructure
The technical details of this case are almost beside the point, and that’s exactly what makes it worth studying. The credentials were real. The laptop was real. The access was legitimate right up until the moment someone holding it decided to sell it. No amount of encryption or firewall investment defends against that specific failure mode, because the failure isn’t in the system, it’s in how access to the system is granted, monitored, and revoked once granted.
What Actually Reduces This Risk
A few concrete practices separate institutions that catch this kind of insider activity early from institutions that find out about it in an EFCC press release. Administrative access should be logged, scoped to what a role actually requires, and time-boxed, rather than existing as a standing credential someone can hand off to anyone whenever they choose. Sensitive infrastructure details like server IPs and domain credentials should never be something one person can disclose in full alone, splitting that knowledge across roles removes the single point of failure this case turned on entirely. Unusual credential activity, a login from a new device, an unfamiliar location, access at an odd hour, should trigger a review before any damage occurs, not surface only after the fact during an investigation. And offboarding plus regular access reviews need to be treated as genuine security controls rather than a compliance checkbox, since they’re often the actual difference between catching a problem in an internal log and catching it in a courtroom.
The Real Lesson
Every financial institution operating in Nigeria, or anywhere else, can build genuinely strong technical defences and still remain exposed to exactly this scenario, because the system ultimately runs on people, and people can be bought. The FCMB case is a concrete, court-documented reminder that access governance, not just access technology, is where a meaningful share of real-world financial infrastructure risk actually lives.