By Jennete Ugo Anya
More than N1 billion in fraudulent transactions went undetected by automated security systems across West Africa during the first half of 2026, according to esentry’s latest threat landscape report, ‘Eye of Horus’. The finding exposes a growing gap between cybersecurity monitoring speed and visibility into trusted identities, systems and workflows.
DEVELOPMENT:
esentry’s Digital Forensics and Incident Response team investigated three major incidents across Nigeria’s fintech, payments and core banking sectors where fraud reportedly ran its full course without triggering a system alert. The cases were discovered later through audits, support tickets or settlement warnings.
The company processed more than 3.5 million security alerts through six specialised teams during H1 2026, recording a median detection-to-escalation time of 11 minutes for confirmed threats.
Chief Business Officer at esentry, Gbolabo Awelewa, said that attackers are changing their methods.
“Attackers are increasingly exploiting trust rather than vulnerabilities. A legitimate credential, a trusted developer tool, a familiar SaaS platform, or an AI-enabled workflow can all become an entry point when the right controls and visibility are missing.”
He stated: “The priority now is continuous visibility, proactive threat hunting and the ability to identify malicious behaviour before it becomes business impact.”
DATA:
Nigerian organisations experienced an average of more than 4,700 attacks per week during H1 2026, while 281,500 Nigerian accounts were newly breached in Q1 alone.
esentry’s offensive security division conducted 175 engagements, including penetration tests, social engineering campaigns and cloud assessments. Every engagement gained unauthorised access, with none requiring a zero-day exploit.
In Ghana, the national Computer Emergency Response Team recorded more than 3,500 confirmed cybersecurity incidents in Q1, while 352 fraudulent online investment schemes caused losses of GHS 3,429,447 between January and June.
SIGNIFICANCE:
The findings suggest that cybersecurity risk is increasingly moving from obvious technical vulnerabilities towards identity, authorisation and trusted business infrastructure.
For banks, fintechs, telecoms and government platforms, simply detecting threats quickly is insufficient if critical activity is not being logged or monitored in the first place.
esentry’s collaboration with Darktrace also found that attackers exploited the React2Shell vulnerability within 30 hours of its disclosure, while a Darktrace decoy system was compromised within two minutes of going online.
NEXT MOVE:
esentry recommends mandatory egress logging, retention of authentication source-IP data and backend authorisation at every application endpoint.
The company also recommends stronger governance around agentic AI systems, including human sign-off for high-impact decisions.
OUR LENS:
The report points to a fundamental change in cybersecurity economics. The problem is no longer simply whether organisations can detect attacks quickly, but whether they can see activity occurring through systems they already trust.
As Awelewa put it, “organisations cannot assume something is safe simply because it is familiar.”
For financial institutions and other data-intensive businesses, identity controls, comprehensive logging and continuous threat hunting are increasingly becoming core operational infrastructure rather than optional cybersecurity upgrades.
Jennete Ugo Anya is a journalist and researcher with interests across Nigeria’s economy, public policy, business, development and strategic communications.
Discover more from StakeBridge Media
Subscribe to get the latest posts sent to your email.