While economists debated and regulators scrambled over the sudden implosion of banks, a small, unheralded community of IT audit pioneers performed a service indispensable to the survival of Nigeria’s financial system—and its economic sovereignty.

On 16 January 1998—the “Mass Burial” day—the Central Bank of Nigeria simultaneously revoked the licences of twenty-six banks. Thirty-four institutions were technically insolvent; depositors ruined; the sector convulsed. Yet the deepest breach was invisible to the public eye: it was unchecked cybercrime.

Racing to computerise through the late 1980s and 1990s, Nigerian banks unwittingly created an unguarded attack surface. Internal control and audit departments possessed no methodology for penetrating the interiority of computerised systems, auditing merely around the computer. This opacity proved catastrophic. IT personnel lacked strong system security hygiene. Our team detected default passwords on central servers hosting billions in customer deposits.

This systemic blindness was pervasive. The Chief Inspector of one of Nigeria’s top 3 banks candidly confided that his auditors were completely blind inside the computer, a complaint echoed by the Committee of Chief Inspectors industry-wide at the time. Without technical illumination, governance was operatively blind, labouring in the obscurity of systems whose interiority it could neither enter nor interrogate. What society observed as sudden bank implosions was actually the eruption of computer frauds accumulating unseen as capital funds and customer deposits evanesced without accountability.