It might just take a while…..
Jesse had seven of his sons pass before samuel, but Samuel said to him
“the lord has not chosen these.”
So he asked Jesse, “Are these all the sons you have?”
“There is still the youngest,” Jesse answered “but he’s tending to the sheep.”
Good first step, but too vague. What data was accessed? How many entities affected? No named official, no legal breach reference. Stakeholders left guessing. Next update needs specifics: data type, root cause, and regulatory filings. #GRC#CyberIncident#CAC
The more we get, the higher the fences we build, abundance often breeds isolation.
Yet true richness lies not in what we keep, but in what we give freely, without fear.
#solemnthoughts
A simple and highly effective measure is mandatory dual authorization , preferably a lower level staff initiates the reversal or credit adjustment, and a supervisor authorizes it for any amount above a predefined threshold set by the bank's risk committee.
A First Bank employee named Tijani Muiz Adeyinka worked on the electronic products team.
His job gave him legitimate access to process reversals for customers.
He used that access to credit merchant accounts with money that was not theirs.
The fraudulent postings went to his wife's Zenith Bank account first.
From there to 34 other accounts.
Which then spread to 1,190 secondary accounts across multiple banks.
By the time First Bank noticed and reported it to the Nigeria Police Force on March 25, 2024...the figure had grown from ₦12 billion to ₦40 billion.
He was already on the run.
Three court orders across Lagos and Jalingo were obtained to freeze accounts.
Some of the money had already been converted to USDT through crypto traders.
This is what insider fraud actually looks like in Nigerian banking.
Not a dramatic hack.
A staff member. A privileged function. No second authorization required.
If your system allows any single person to trigger financial transactions without a second approval layer that is your vulnerability.
Segregation of duties is not bureaucracy.
It is what stands between your system and ₦40 billion walking out the door.
When Privacy Goes Wrong
Imagine this: One morning, a fast-growing Lagos fintech woke up to a nightmare. A researcher found 500,000 users' data exposed online. BVN numbers, bank balances, everything.
#cyberseccurity#dataprivacy#informationsecurity
· Financial: 30% of users fled in one week. Their Series B funding? Gone.
· Operations: Engineers dropped everything. Customer service drowned. Bank partnerships froze.
One breach didn't cause one problem. It triggered a cascade across the entire company.
More importantly, I practiced identifying bad permissions and fixing them correctly by reassigning proper access control and ownership, also understanding not just what to change, but why it matters.
#InfoSecJourney#Linux#100DaysOfCyberSecurity
Today I focused on the logic behind Linux filesystem security.
I learned how Linux controls access using ownership and permissions, why sensitive files like "/etc/shadow" are protected, and how misconfigured permissions can become real security vulnerabilities.
#Cybersecurity