… says terrorists use women, dead persons’ SIMs to hide illicit funds
The Nigeria Financial Intelligence Unit has uncovered an emerging crowdfunding network being exploited by terrorist financiers to raise, move and channel funds to operatives in Nigeria.
The Unit also identified the use of women as proxies in opening bank accounts, as well as the deployment of telephone numbers not registered to account holders or actual beneficiaries for mobile banking and transaction alerts.
According to the NFIU’s 2025 annual report, the emerging crowdfunding model involves foreign-based facilitators using social media platforms to solicit donations under the guise of humanitarian relief, educational assistance or other legitimate causes before moving the proceeds through several layers to terrorist operatives in Nigeria.
The NFIU said the facilitators typically encouraged hundreds of sympathisers to make relatively small contributions, ranging from $50 to $500, through PayPal pages and conventional bank accounts.
The strategy, it noted, was designed to keep individual transactions below thresholds likely to trigger automated anti-money laundering alerts.
The report stated, “A foreign-based facilitator runs social-media campaigns claiming humanitarian relief or educational support and uses encrypted apps (Telegram, Signal) to share links to convincing PayPal pages or standard bank accounts.
“Hundreds of sympathiser donors contribute $50–$500 each, amounts small enough to avoid most automated AML alerts.”
The NFIU said the proceeds were subsequently consolidated into a “master account” controlled by a senior member of the network who was legally resident abroad.
It explained that once the funds accumulated to a certain threshold, the account became a central hub for moving the money to recipients in Nigeria.
Rather than transferring the entire amount in a single transaction, the facilitator allegedly fragmented the funds into dozens of smaller payments and routed them through International Money Transfer Operators and remittance applications.
The payments were then sent to a network of money mules in Nigeria, including students, small-business owners and relatives.
The Unit said the arrangement was intended to remain below reporting thresholds while making it difficult for investigators to establish the original source and ultimate destination of the funds.
“Rather than sending one large transfer, the senior member fractures the funds and sends dozens of sub-threshold payments through IMTOs and remittance apps to a network of money mules in Nigeria; students, small-business owners, or relatives, avoiding reporting triggers,” the report stated.
Upon receipt, the funds were either converted into cash or used to acquire items that could serve both civilian and operational purposes.
The NFIU listed motorcycles, fertilisers and satellite internet equipment among the items that could be purchased with the funds.
It added that some proceeds were transferred through mobile banking channels to logistics managers and field operatives.
According to the report, this represented the final stage of the process, where apparently legitimate donations were transformed into operational resources for terrorist groups.
Beyond crowdfunding, the NFIU identified what it described as an emerging gender-based proxy account system, in which bank accounts are opened in women’s names but are secretly controlled by male terrorist commanders or logistics managers.
The Unit said the technique was being used to create distance between illicit funds and the actual individuals controlling them.
“Terrorist financiers are opening bank accounts in women’s names while male commanders and logistics managers secretly control them,” the report stated.
It said wives, sisters and female associates were being used as fronts, exploiting social and cultural assumptions that women were less likely to attract suspicion during financial investigations.
The NFIU described the practice as “identity laundering”, explaining that male operatives could retain control of the accounts by possessing ATM cards, mobile banking credentials and personal identification numbers.
In some cases, it said, the women whose names appeared on the accounts were allegedly unaware of the nature, volume or frequency of the transactions taking place.
The financial intelligence agency also raised concerns over the use of telephone numbers that do not belong to the registered bank account holders or actual beneficiaries.
It said terrorist facilitators were using such numbers for mobile banking services and transaction alerts in an attempt to sever the link between bank accounts, SIM cards and Bank Verification Numbers.
According to the report, the techniques included the use of pre-registered SIM cards, telephone numbers registered to deceased persons and SIM cards linked to gender-based proxy account holders.
The NFIU said the practice could make investigations more difficult because a financial trail could lead investigators to an unrelated individual whose telephone number was attached to an account.
“Terrorist facilitators use phone numbers for mobile banking or account alerts that are not registered to the account holder or the true beneficiary,” the report stated.
It added that the practice “severs the audit trail” and could allow the actual facilitator to remain anonymous while continuing to operate.
The NFIU further uncovered sophisticated methods being used to conceal the purpose of terrorist-related financial transactions through transaction narrations.
It said some terrorist cells, particularly those linked to the Islamic State West Africa Province (ISWAP), used detailed and professional-sounding descriptions to maintain what analysts considered an internal accounting system.
According to the report, the pattern involved frequent logistics-related payments from a single source to several recipients, with detailed descriptions attached to the transfers.
The Unit said such transactions could appear legitimate to conventional monitoring systems because the narrations were often accurate descriptions of the expenditure.
It explained that terrorist cells could operate with highly structured financial controls, requiring field commanders to account for expenditures to central financial controllers.
The report stated that the apparently legitimate transaction descriptions effectively created an internal audit trail within the terrorist network.
However, the NFIU said other facilitators deliberately used innocuous words, secret codes and alphanumeric combinations to conceal the purpose of transactions.
Some also switched between languages in their descriptions in an attempt to circumvent automated banking filters that could flag terms associated with terrorism.
The report noted that terms such as “Jihad,” “Arms” and “Boko” could trigger alerts, prompting facilitators to adopt coded alternatives.
The practice, it said, made it more difficult for automated systems to identify suspicious transfers based solely on transaction narratives.
The NFIU said its risk and crime analysis for the year revealed an increasingly interconnected threat environment involving financial crime, technology and cross-border activities.
It identified fraud as a dominant predicate offence and reported growing cases of Ponzi schemes, fraudulent crowdfunding arrangements, cryptocurrency-enabled investment scams and hacking-related fraud.
The Unit said criminals were increasingly exploiting weaknesses in fintech onboarding processes, particularly tiered accounts with minimal identification requirements.
Digital platforms, it added, had also made it easier for criminal networks to recruit victims rapidly and move funds across jurisdictions.
The report also identified vulnerabilities in public-sector financial management.
According to the NFIU, state and local government funds were at risk of diversion through accounts belonging to finance officers and associated third parties.
Procurement processes were identified as another significant risk area, while extensive use of cash transactions was said to complicate audit trails and make the tracing of illicit assets more difficult.
The Unit said its findings had been converted into targeted advisories, executive alerts and strategic intelligence products for relevant authorities, reporting entities and policymakers.


Comments
Start the conversation about this story.