Connect with us

Banking

EXPLAINER: Understanding CBN’s 0.5% Cybersecurity Levy

Published

on

CBN Ways and Means

By Adedapo Adesanya

On Monday, May 6, 2024, the Central Bank of Nigeria (CBN) directed all financial institutions, including commercial banks and others to deduct a 0.5 per cent cybersecurity levy on electronic transfers as stipulated in the Cybercrime (Prohibition, Prevention, etc) (Amendment) Act 2024.

The directive has since created an uproar among Nigerians as they interpreted it to be that the 0.5 per cent fee would be charged on the value of the funds transferred electronically. For instance, a sum of N1,000 will attract N5, N2,000 to attract N10, N5,000 to attract N50, and so on.

But from the explanation given by the CBN in 2018 when this policy was first implemented, the cybersecurity fee is levied on the service charge by the financial institutions from the originator of the transaction.

For example, if the service charge on the transfer of N10,000 is N50, the 0.5 per cent cybersecurity levy will be charged on the N50, not N10,000, which means apart from paying N50 for Electronic Money Transfer Levy (EMTL), 7.5 per cent Value-Added Tax (VAT), and other fees, the customer will likely pay 25 Kobo as an additional fee for the transaction.

This development is not new. The Cybersecurity Act was first passed in 2015 and introduced a 0.005 per cent levy on electronic transfers. In June 2018, the CBN implemented the policy and directed banks to collect the levy on “electronic transactions occurring in a bank or on a mobile money scheme or any other payment platform that have an accompanying service charge.”

It was explained in 2018 through Mr Dipo Fatokun, who was then the Director Banking and Payments System Department, that “Electronic transactions shall be all financial transactions occurring in the bank or on a Mobile Money Scheme or any other payment platform that have an accompanying service charge; the levy shall be 0.005 per cent of the service charge (exclusive of all tax effects) from all electronic financial transactions occurring in a bank, a Mobile Money Scheme and other Payment Platforms.

“All electronic transactions (both inter and intra) that have an accompanying service charge shall qualify as eligible transactions; the effective date of collection shall be with effect from July 1, 2018.”

Now, the levy has been increased by 900 per cent and covers fintechs, payment service providers, and other financial institutions. These institutions have been mandated to remit the monies to the National Cybersecurity Fund (NCF), which would be administered by the Office of the National Security Adviser (ONSA).

In the latest circular signed by the Director of the Payments System Management Department of the CBN, Mr Chibuzo Efobi; and the Director of the Financial Policy and Regulation Department, Mr Haruna Mustafa, the apex bank emphasised that failure to remit the fees is an offence as stated in Section 44 (8) of the Act and will attract a conviction of not less than 2 per cent of the annual turnover of the defaulting business, amongst others.

“Following the enactment of the Cybercrime (Prohibition, Prevention, etc) (Amendment) Act 2024 and pursuant to the provision of Section 44 (2)(a) of the Act, ‘a levy of 0.5% (0.005) equivalent to a half per cent of all electronic transactions value by the business specified in the Second Schedule of the Act,’ is to be remitted to the National Cybersecurity Fund, which shall be administered by the Office of the National Security Adviser,” a part of the notice said.

While the outbursts have continued, many have also justified the need for the charge, especially with fraud prevalent in the Nigerian financial ecosystem.

Available data released by the Financial Institutions Training Centre (FITC) showed that Nigerian banks lost N2.09 billion to frauds in the fourth quarter of 2023, with mobile emerging as the top channel through which the largest amount was lost. 

According to the report, the N2.09 billion loss recorded in Q4 was a 77.58 per cent increase from the N1.18 billion recorded by the banks in Q3 2024.  

There are also indicators that the number might be higher this year, with the CBN forcing the hands of neobanks like Opay, MoniePoint, PalmPay, and Kuda not to open new accounts.

Despite this new fund, it is not all gloomy as 16 banking transactions are exempted from the CBN’s new cybersecurity levy.

These are Loan disbursements and repayments; Salary payments; Intra-account transfers within the same bank or between different banks for the same customer; Intra-bank transfers between customers of the same bank, Other Financial Institutions’ instructions to their correspondent banks; Interbank placements; Banks’ transfers to CBN and vice-versa; Inter-branch transfers within a bank; and Cheque clearing and settlements.

Others are Letters of Credit; Banks’ recapitalisation-related funding – only bulk funds movement from collection accounts; Savings and deposits, including transactions involving long-term investments such as Treasury Bills, Bonds, and Commercial Papers; Government Social Welfare Programmes transactions e.g. Pension payments; Non-profit and charitable transactions, including donations to registered non-profit organisations or charities; Educational institutions’ transactions, including tuition payments and other transactions involving schools, universities, or other educational institutions; as well as transactions involving the bank’s internal accounts such as suspense accounts, clearing accounts, profit and loss accounts, inter-branch accounts, reserve accounts, nostro and vostro accounts, and escrow accounts.

Adedapo Adesanya is a journalist, polymath, and connoisseur of everything art. When he is not writing, he has his nose buried in one of the many books or articles he has bookmarked or simply listening to good music with a bottle of beer or wine. He supports the greatest club in the world, Manchester United F.C.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Banking

NDIC Reimburses 700,000 Heritage Bank Depositors, Moves to Pay Customers of 46 Failed MFBs

Published

on

Heritage Bank headquarters

By Adedapo Adesanya

The Nigeria Deposit Insurance Corporation (NDIC) says it has paid the insured deposits of about 700,000 customers of the defunct Heritage Bank and has commenced the reimbursement of depositors of 46 microfinance banks (MFBs) whose operating licences were recently revoked by the Central Bank of Nigeria (CBN).

The chief executive of NDIC, Mr Oludare Sunday, made this known on Wednesday during a retreat for members of the House of Representatives Committee on Insurance and Actuarial Matters in Lagos.

He said the corporation immediately began settling the insured deposits of customers after the CBN revoked the licences of the 46 microfinance banks and appointed the NDIC as their provisional liquidator.

“We are working on those. The CBN revoked the licences, and we were appointed as the provisional liquidator. We have started paying depositors of those banks, and gradually we intend to cover all the insured depositors,” he said.

Mr Sunday explained that the NDIC’s responsibility extends beyond paying insured deposits to recovering outstanding loans owed to the failed institutions and disposing of their assets to generate funds for the settlement of uninsured depositors.

“Our function as liquidator involves the payment of guaranteed sums. Thereafter, we go after those who owe the institutions and have not paid. We also ensure that we sell the available assets and realise their investments towards paying the uninsured portion of the deposits. So, we have started paying the guaranteed deposits. What we are doing now is also realising the assets of those institutions,” he stated.

Although he declined to disclose the exact number of depositors of the failed microfinance banks who had been reimbursed, Sunday said the Corporation was working with the Nigerian Interbank Settlement System (NIBSS) to identify depositors through their Bank Verification Numbers (BVN) to ensure seamless payments.

“So, the more accounts we discover, the more payments we make,” he added.

Providing an update on the liquidation of Heritage Bank, the NDIC chief said about 700,000 depositors had already received their insured deposits, while efforts were ongoing to trace other customers whose identities could not be verified from available records.

He attributed the challenge to legacy accounts created before the introduction of the BVN system, as well as incomplete customer records inherited from banks that were later merged into Heritage Bank.

“If you know Heritage Bank, you know it is an amalgamation of several banks, including the acquisition of Enterprise Bank in 2014. So, if you think of banks like Guardian Express and Spring Bank, they are all part of Heritage Bank.

“There are depositors we have not been able to trace, and this is an opportunity for them to come forward. I am sure many of us did the National Youth Service Corps (NYSC) and may have left some money in an account, but there was no BVN then.

“Even the addresses we had were sometimes things like ‘opposite filling station.’ How do you trace such a person? Once they come forward, and for those we have been able to identify from the institution’s database, we have been paying them,” he explained.

Mr Sunday added that the Corporation would continue to recover outstanding loans and dispose of Heritage Bank’s assets to generate funds for the payment of liquidation dividends to depositors whose balances exceeded the insured limit.

Earlier in his remarks, he described the NDIC as a critical pillar of Nigeria’s financial safety net, stressing the need for stronger collaboration between regulators and the National Assembly as the banking sector responds to recapitalisation efforts and rapid financial technology developments.

According to him, while the ongoing banking recapitalisation programme has strengthened the resilience of financial institutions, it must be complemented by sound corporate governance, effective risk management, strict regulatory compliance and robust supervision to safeguard long-term financial system stability.

He also disclosed that more than 98 per cent of depositors, representing over 281 million accounts across insured financial institutions, are fully protected under the NDIC’s deposit insurance scheme.

Continue Reading

Banking

Zenith Bank Probes Customer Data Breach, Says Funds Remain Safe

Published

on

zenith bank logo

By Adedapo Adesanya

Zenith Bank Plc is investigating an incident involving unauthorised access to customers’ data, noting that the breach does not involve financial information and has not compromised its banking services or digital channels.

In an email sent to customers on Wednesday, the bank stated that the incident was part of a broader global cyberattack affecting multiple international organisations across various sectors.

The lender stated that it immediately activated its incident response protocols and intensified its cybersecurity and remediation efforts upon discovering the incident.

“This incident is part of a broader, global cyber-attack targeting multiple international organisations across various sectors. Upon discovery, we promptly activated our incident response protocols, cybersecurity actions and remediation efforts,” the bank said.

The bank reassured customers that its banking services and digital channels remain secure and fully operational.

As a precautionary measure, Zenith Bank advised customers to remain alert to potential phishing attempts and other forms of social engineering.

“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and never to disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone,” the bank said.

The incident is the latest in a series of cybersecurity challenges facing Nigerian financial institutions, with banks in recent months suspending their social media operations over impersonation and other fraudulent activities.

Earlier in April, the Nigeria Data Protection Commission (NDPC) said it was investigating alleged data breaches involving Sterling Bank, Remita and the Corporate Affairs Commission (CAC).

Nigerian banks have long been prime targets for cybercriminals because of the vast amounts of customer data and financial transactions they handle every day.

While many attacks have traditionally sought to steal funds, cybercriminals are increasingly targeting personal information, which can be used for identity theft, phishing schemes, account takeovers and other forms of financial fraud.

Cybersecurity threats have increasingly targeted Nigerian banks in recent years. In 2025, Union Bank of Nigeria warned customers about fraudulent websites and phishing campaigns designed to steal login credentials and personal information by impersonating the bank.

In August 2024, Guaranty Trust Bank experienced a domain-related security incident that temporarily disrupted access to its official website, although the lender assured customers that their deposits and banking services remained secure while it resolved the issue.

Continue Reading

Banking

Otedola Reveals Ambition to Take Majority Control of First HoldCo

Published

on

First Bank Otedola

By Adedapo Adesanya

The chairman of First HoldCo Plc, Mr Femi Otedola, has affirmed plans to increase his 26 per cent holding in the organisation to 51 per cent, confirming a planned takeover of Nigeria’s oldest banking institution.

Mr Otedola spoke in an exclusive interview with Nairametrics published on Monday, giving a rare direction following recent speculations about the financial institution.

The milestone followed a series of share acquisitions, as Mr Otedola sought to tighten his grip as the company’s largest shareholder following the recent acquisition of additional shares worth N222.21 billion.

In the interview, the mogul said he has invested more than N600 billion of his personal wealth in First HoldCo, describing the move as a “long-term generational commitment” rather than another turnaround investment he would eventually exit.

Responding to speculation that he intends to consolidate his position in the group, Mr Otedola hinted that his investment journey is far from over.

“My investment threshold is always over and above 51 per cent,” he said. “One of my key investment principles is that firm shareholder control, with due regard for minority interest, is a key ingredient to executing reforms and restructuring to deliver value to all stakeholders.”

The businessman said the same strategy had guided his investments in African Petroleum Plc, later renamed Forte Oil Plc, where he gradually increased his shareholding from 28 per cent to 75 per cent before exiting the company in 2019.

He said he also increased his stake in Geregu Power Plc from 51 per cent to 95 per cent before reducing it to 77 per cent after the company’s public listing.

“I am on the same trajectory with First HoldCo Plc,” Mr Otedola said.

“To date, I have invested over N600 billion of my personal wealth in First HoldCo Plc — a figure that speaks not to speculation, but to unflinching confidence in the institution’s future, fundamentals and an unwavering personal commitment to its success.”

Mr Otedola said his decision to invest in First HoldCo came at a time when the institution was facing one of the most challenging periods in its history.

The billionaire steadily increased his investment in the group, accelerating his share purchases in 2026. His stake grew from 6.68 billion shares (15.95 per cent) in June 2025 to 8.06 billion shares by March 2026, then to 9.28 billion shares by June after acquiring about 1.22 billion shares in one quarter. A further purchase through Calvados Global Services last month lifted his holdings above 10 billion shares for the first time.

Continue Reading