The NFIU says terrorist financiers are using accounts belonging to deceased persons, crowdfunding platforms, women’s bank accounts and third-party phone numbers to conceal and transfer illicit funds.
The Nigerian Financial Intelligence Unit (NFIU) has uncovered an emerging crowdfunding network being used to raise and move money for terrorist activities in Nigeria.
The financial intelligence agency also identified the use of bank accounts registered in women’s names and phone numbers linked to third parties as methods employed by terrorist financiers to conceal the movement of illicit funds.
The findings were contained in the NFIU’s 2025 Annual Report, which examined emerging trends in terrorist financing, financial fraud and other financial crimes during the year.
How Foreign-Based Facilitators Raise Funds
According to the report, the crowdfunding network is operated through foreign-based facilitators who use social media to solicit donations disguised as humanitarian relief or educational assistance.
The facilitators reportedly use encrypted messaging platforms such as Telegram and Signal to circulate links to payment pages and conventional bank accounts.
The NFIU said hundreds of sympathisers could be encouraged to make relatively small donations, typically between $50 and $500, with the amounts structured to reduce the likelihood of triggering automated anti-money laundering alerts.
“The following is a case study on Crowdfunding Network identified during the year: A foreign-based facilitator runs social-media campaigns claiming humanitarian relief or educational support and uses encrypted apps (Telegram, Signal) to share links to convincing PayPal pages or standard bank accounts.
“Hundreds of sympathiser donors contribute $50–$500 each, amounts small enough to avoid most automated AML alerts,” the report stated.
The funds are subsequently consolidated in a “master account” controlled by a senior member of the network who is legally resident abroad.
“When the pool reaches a threshold, that account becomes the hub for onward movement,” the NFIU stated.
Money Mules Used To Move Funds
The agency said the accumulated funds are then divided into numerous smaller payments and sent through International Money Transfer Operators (IMTOs) and remittance applications to a network of money mules in Nigeria.
Students, small-business owners and relatives are among those identified as potential recipients in the network.
The NFIU said the fragmentation of the funds is intended to avoid reporting thresholds while making it more difficult to establish the source and final destination of the money.
“Rather than sending one large transfer, the senior member fractures the funds and sends dozens of sub-threshold payments through IMTOs and remittance apps to a network of money mules in Nigeria; students, small-business owners, or relatives, avoiding reporting triggers,” the report said.
It added that the recipients could convert the funds into cash, use them to acquire dual-use items such as motorcycles, fertilisers and satellite internet equipment, or transfer the money through mobile banking channels to logistics managers and field operatives.
The NFIU described this stage as the “integration” of the funds into terrorist operational financing.
Women’s Accounts Used As Proxies
The report also identified gender-based proxy accounts as an emerging terrorist financing technique.
According to the NFIU, terrorist financiers open bank accounts in the names of women while male commanders or logistics managers secretly control the accounts.
“Terrorist financiers are opening bank accounts in women’s names while male commanders and logistics managers secretly control them.
“They exploit cultural norms that make women less likely to be suspected by authorities, using wives, sisters, or female associates as fronts to distance illicit funds from the true operatives.
“This tactic functions as identity laundering: women’s accounts are managed by men who hold ATM cards, mobile-banking credentials, and PINs, while the women often remain unaware of the transactions and volumes,” the report stated.
Third-Party SIMs Used To Break Audit Trails
The NFIU further identified the use of telephone numbers that are not registered to the actual account holders or beneficiaries for mobile banking and transaction alerts.
It said facilitators could use pre-registered SIM cards, numbers registered to deceased persons or SIMs linked to gender-based proxies to break the connection between bank accounts, SIM cards and Bank Verification Numbers (BVNs).
“Terrorist facilitators use phone numbers for mobile banking or account alerts that are not registered to the account holder or the true beneficiary.
“They bypass the security link between SIM cards and BVNs by using pre-registered SIMs, SIMs registered to deceased people, or SIMs tied to gender-based proxies. This severs the audit trail: when a transaction is flagged, investigators trace the phone to an unrelated person, letting the real facilitator stay anonymous and continue operations,” it stated.
ISWAP Uses Transaction Narrations To Track Funds
The financial intelligence agency also uncovered methods used by terrorist cells, particularly those linked to the Islamic State West Africa Province (ISWAP), to disguise or organise financial transactions.
According to the report, some cells use detailed and professional-sounding transaction descriptions as an internal accounting mechanism.
The NFIU said frequent logistics-related payments with detailed narrations were sometimes sent from a single source to multiple recipients, suggesting a structured financial management system within the terrorist network.
“Terrorist cells, particularly those linked to ISWAP, routinely use precise, professional-sounding transaction narrations to maintain internal accounting. Operating like “shadow states” with strict bureaucratic controls, they require detailed descriptions so field commanders can justify expenses to central financial controllers. Although truthful narrations appear counterintuitive, they create an internal audit trail; analysts repeatedly observe high-frequency, logistics-related payments with accurate narrations sent from a single source to multiple recipients,” the report said.
However, the NFIU said other facilitators resort to coded descriptions to conceal the purpose of transactions and evade automated monitoring systems.
It said innocuous words, secret codes and alphanumeric combinations could be used in transaction descriptions, with facilitators sometimes switching between languages to avoid bank filters designed to identify suspicious terms.
“Transaction descriptions employ innocuous words, secret codes, or alphanumeric strings to conceal intent. Facilitators use this coded language, often switching languages to evade banks’ automated keyword filters that flag terms like ‘Jihad,’ ‘Arms,’ or ‘Boko.’
“This practice obscures the true purpose of transfers, preventing detection and enabling continued financing,” the agency said.
Fraud, Public Funds Also Raise Concerns
Beyond terrorist financing, the NFIU said its risk and crime analysis for 2025 revealed an increasingly interconnected threat environment involving financial crime, technology and cross-border activity.
The agency identified fraud as a dominant predicate offence, with notable increases in Ponzi schemes, fraudulent crowdfunding arrangements, cryptocurrency-related investment scams and hacking-related fraud, including the compromise of social media and messaging accounts.
It said criminals were increasingly exploiting weaknesses in fintech onboarding processes, including tiered accounts with minimal identification requirements, while digital platforms enabled them to recruit victims and move funds rapidly.
The report also identified persistent vulnerabilities in the management of public funds, including the diversion of state and local government resources through accounts belonging to finance officers and associated third parties.
Procurement processes were identified as another major risk area, while extensive use of cash was said to complicate audit trails and efforts to trace illicit assets.
The NFIU said its findings had been converted into targeted advisories, executive alerts and strategic intelligence products to assist competent authorities, reporting entities and policymakers in responding to the identified threats.
“Financial Fraud and Investment Scams: Fraud remains a dominant predicate offence, with notable growth in Ponzi schemes, fraudulent crowdfunding arrangements, cryptocurrency-enabled investment scams, and hacking-related fraud (including compromised social media and messaging accounts).
“Analytical reviews during the period examined these trends and informed internal advisories and alerts, some of which remained restricted for operational purposes.
“These schemes increasingly exploit fintech onboarding gaps, including tiered accounts with minimal identification requirements, and leverage digital platforms to rapidly scale victim recruitment and fund movement.
“Corruption and Misappropriation of Public Funds Analysis highlighted persistent vulnerabilities in public sector financial management, including the diversion of state and local government funds through accounts of finance officers and associated third parties.
“Procurement processes remain a significant risk area, while utilisation of cash transactions complicates audit trails and asset tracing efforts,” the report said.
















