Job hunting...
Next Year, I'll create a guide to help all those who want to start earning in Tech, Marketing and Technical Writting. I haven't landed any serious writting role hence that section will be brief. It'll e beat realistic piece ever_ for 🆓. Check this for inspiration
I was hitting 9 months learning JavaScript and a newbie at marketing and writting. Fast forward days⏩ it's still December but this time, I have new pairs of shoes and clothes for Christmas.
This is a motivation to anyone struggling in tech. Keep pushing, your time is near.🤝
In banking and fintech cybersecurity, tech vendors and developers are routinely scheduled to push code updates, run migrations, and test integrations between 12:00 AM and 6:00 AM when customer traffic is at its absolute lowest.
Because banks process millions of commercial transactions during standard working hours (8:00 AM to 5:00 PM), making structural changes to a mobile money banking pipeline during the day risks freezing the system, dropping active user calls, and halting transactions.
On June 6, 2025, at around 5:30 A.M, NCBA Bank officially activated the vendor contract and granted a consultancy firm, Ronford Digital Limited's employee, Evans Nandwa, a live backend privileges to begin system maintenance and upgrades for its NCBA Rwanda subsidiary.
According to DCI Banking Fraud Investigation Unit (BFIU) court filings, at 5:33 AM, just three minutes after receiving live backend access, Nandwa altered the core application codebase.
He specifically manipulated the mobile integration logic governing the MTN mobile money network in Rwanda. Under his modified logic, whenever a withdrawal request hit the network, the system was forced to bypass validation checks entirely and automatically return a fake "Success" status code. This script was pre-programmed with 70 ghost account profiles.
The code was hardcoded with a highly specific filter that applied only to those exact 70 ghost accounts. If a withdrawal request came from any of the specific 70 ghost account numbers on Nandwa's list, the system would skip the balance check entirely, never looked at how much money they had, not to check if the account is fake, and instantly send a "Success" signal to MTN Rwanda.
By restricting the loophole to just those 70 accounts, the fraudsters achieved two critical goals: It ensured that only their pre-programmed script and automated wallets could siphon the money.
Two, random members of the public wouldn't accidentally discover the glitch and start withdrawing funds, which would have triggered immediate chaos and alerts.
For almost a week, the architectural flaw remained invisible. From June 6 until June 14, 2025, everything looked perfectly normal on the surface to NCBA Bank, as core systems reported standard operational metrics while the exploit quietly ran in the background.
Because the exploit was hidden deep inside the database queries, it was completely invisible to the daily operational dashboards. The bank only realized they had been shortchanged when the physical cash balances were tallied during the standard end-of-week settlement on June 14.
On June 14, NCBA's technical risk team performed a routine end-of-week settlement and reconciliation audit, and discovered a massive cash deficit of 57.5 million shillings that came from 70 ghost accounts, matching 260 transactions that were pushed through the Rwandan MTN mobile network.
In banking sector, an end-of-week reconciliation is a standard administrative process. The bank's systems automatically cross-reference two primary data sets; What the bank's internal database says customers withdrew, and What the telecom partner (MTN Rwanda) actually paid out in cash.
Normally, these two figures match down to the exact cent. However, on June 14, 2025, the automated script flagged a massive, irreconcilable deficit.
While the external telecom ledger showed that MTN Rwanda had successfully paid out Ksh 57.5 million to mobile money users, NCBA's internal deposit accounts showed no corresponding debit entries, fees, or even valid account holders for those transactions. The money had simply vanished into the mobile ecosystem through "ghost" approvals.
The exploit was designed to bypass system validation across the board. It cleared transactions for 70 ghost accounts that the system forced into a "success" state.
POV:
Safaricom: We are building and revolutionizing AI in East Africa and beyond.🚀🚀
Meanwhile, Safaricom's Developers AI Assistant when you're stuck on important issues: 👇😂Premium Pain
Kwani @KenyaPower_Care wamepata competitor ju they've started marketing campaigns kuliko @pakakumi ? The only way I'm installing that app is if I can check my token balance there. Otherwise wacha paybill ya 888880 ifanye kazi iliundiwa😂