Terrorist financiers are opening bank accounts in women’s names to conceal illicit funds, while male commanders and logistics managers secretly control the accounts, the Nigerian Financial Intelligence Unit (NFIU) has revealed.
The tactic is one of several increasingly sophisticated methods uncovered by the financial intelligence agency as terrorist networks exploit gaps in Nigeria’s banking, telecommunications and digital-finance systems to move money while keeping the real beneficiaries out of sight.
The disclosure is contained in the NFIU’s 2025 Annual Report, which identifies fraud, tax crimes, corruption, money laundering and terrorist financing as major drivers of illicit financial flows and warns that criminal networks are increasingly combining proxy accounts, fintech platforms, digital assets and layered cross-border transactions to obscure the origin of funds.
The report said the terrorists exploit cultural perceptions that women are less likely to attract official suspicion, using wives, sisters and female associates as fronts to distance illicit funds from the actual operatives.
“Terrorist financiers are opening bank accounts in women’s names while male commanders and logistics managers secretly control them,” the NFIU explained.
The agency described the practice as ‘identity laundering’, saying the men behind the accounts may hold the ATM cards, mobile-banking credentials and PINs, while the women whose names are attached to them may remain unaware of the transactions or the amounts involved.
Dead People’s SIMs Used to Break Money Trail but the deception does not stop with the account holder. The NFIU said terrorist facilitators also use telephone numbers that are not registered to the account holder or actual beneficiary, exploiting gaps between SIM registration and Bank Verification Numbers (BVNs).
Some of the numbers, it said, are pre-registered SIMs, SIMs registered to deceased persons or numbers linked to gender-based proxies.
“This severs the audit trail: when a transaction is flagged, investigators trace the phone to an unrelated person, letting the real facilitator stay anonymous and continue operations,” the agency warned
ISWAP Runs Finances like ‘Shadow States’
The report further identified sophisticated internal accounting practices among terrorist cells, particularly those linked to ISWAP, saying they sometimes use detailed transaction descriptions to track payments and account for expenditure.
According to the NFIU, the seemingly routine descriptions form part of an internal financial-control system within the cells.
“Operating like ‘shadow states’ with strict bureaucratic controls, they require detailed descriptions so field commanders can justify expenses to central financial controllers,” the agency disclosed.
Codes Replace ‘Jihad’, ‘Arms’, ‘Boko’ where detailed descriptions could expose the purpose of a transfer, facilitators resort to coded language, innocuous words, alphanumeric strings and multiple languages to evade automated banking filters.
The NFIU said the practice is designed to prevent suspicious keywords; including “Jihad”, “Arms” or “Boko” from triggering alerts and exposing the real purpose of transactions.
How Terrorists Turn ‘Humanitarian’ Appeals into Cash; The agency also uncovered a crowdfunding model through which terrorist networks can raise money from sympathisers abroad under seemingly legitimate humanitarian or educational appeals.
In its case study, the NFIU said a foreign-based facilitator can use social-media campaigns and encrypted platforms such as Telegram and Signal to direct donors to PayPal pages or conventional bank accounts.
Hundreds of sympathisers may contribute between $50 and $500 each; amounts small enough to escape most automated anti-money-laundering alerts.
The proceeds are then pooled in a master account controlled by a senior member of the network living legally abroad before being broken into smaller transfers and sent through international money-transfer operators and remittance applications to money mules in Nigeria.
The NFIU said students, small-business owners and relatives could be used as intermediaries, helping the network avoid reporting thresholds.
The money is subsequently converted to cash, used to purchase dual-use items such as motorcycles, fertilisers and satellite internet equipment, or transferred through mobile banking to logistics managers and field operatives.
Public Funds also Exposed to Diversion
Beyond terrorism financing, the NFIU identified serious vulnerabilities in public-sector financial management, saying state and local government money is being diverted through accounts belonging to finance officers and third parties.
It also identified procurement as a significant risk area and warned that cash transactions make it more difficult to establish audit trails and trace assets.
Ponzi, Crypto Scams, Hacking on the Rise
Fraud remains a major source of illicit financial flows, with the agency reporting growth in Ponzi schemes, fraudulent crowdfunding, cryptocurrency-enabled investment scams and hacking-related fraud.
The NFIU said criminals are exploiting weak fintech onboarding systems, including accounts with minimal identification requirements, to recruit victims and move money rapidly.
Farms, Construction Firms used as Possible Fronts;
The agency also flagged suspicious activity involving agricultural businesses and mechanised farms, some of which showed apparent links to unlicensed foreign-exchange operations and ownership patterns inconsistent with normal sector activity.
Construction companies also came under scrutiny, with the NFIU identifying multiple entities apparently linked to the same beneficial owner but registered under different names or jurisdictions, an arrangement it said could be used to conceal ownership.
Bakeries and restaurants were similarly identified in cash-placement and layering schemes, with large cash deposits moved into corporate accounts, including those of oil and gas companies, before portions were returned to hospitality businesses as purported investments.
Fintech, Digital Assets Open New Crime Channels; The financial intelligence unit further warned that weak know-your-customer controls among fintech firms are being exploited to receive proceeds from Ponzi schemes, while some virtual-asset service providers are accepting funds from designated high-risk jurisdictions.
Payment-service platforms, it said, are also facilitating large and unjustified transactions with suspicious classifications.
The NFIU identified the growing convergence of cybercrime and financial crime as another major risk, citing sextortion, online exploitation and hacking-related fraud.
Foreign Inflows Linked to Organised Crime, Trafficking Cross-border transactions were another area of concern, with the NFIU reporting suspicious foreign inflows that could be linked to organised crime and human-trafficking networks.
It also flagged high-risk remittance corridors and trade-related payment structures as channels that can be exploited to disguise the origin and destination of illicit funds.
NFIU Steps Up Intelligence, Issues Fresh Warnings; In response, the NFIU said it developed strategic analysis products and advisories targeting identified vulnerabilities, including the role of logistics networks and suppliers in terrorist financing.
The agency also issued an advisory on Ponzi and unregulated crowdfunding schemes, warning that such operations are increasingly using digital assets and purported “agricultural investments” to facilitate illicit financial flows.
According to the NFIU, some of these schemes recycle money from new investors to pay earlier participants instead of generating genuine profits, a structure that eventually collapses.
The Unit consequently urged financial institutions to tighten their scrutiny of suspicious transactions.
“The advisory mandates that financial institutions enhance their due diligence and report all suspicious transactions to mitigate the risk of widespread financial loss,” the NFIU said.
Advertisement