More
    HomeGovernance, Policy & Regulations ForumCorporate Governance ForumLong Detection Lag: The Thread Running Through Senegal’s Fintech Heists

    Long Detection Lag: The Thread Running Through Senegal’s Fintech Heists

    Published on

    spot_img

    Dakar’s fintech corridor has, in the space of a year, produced a reliable licensing pipeline, a run of venture rounds cited approvingly at conferences, and — with almost the same regularity — a string of insider-fraud disclosures. Between August 2025 and July 2026, four companies operating in or through Senegal’s technology sector — Intech Group, Sénégal Numérique SA, CinetPay and Socium — have each had a trusted employee accused of quietly redirecting company funds, in one case for years, before anyone in a position to stop it noticed.

    The amounts differ by an order of magnitude. So does the method: a bearer cheque here, a re-run software transaction there, a saved corporate card number in a third case. Individually, each is a personnel problem with a police file attached. However, taken together, they describe something more structural — not that fraud occurs, which is unremarkable, but how long each scheme was permitted to run once it had started, and what that says about who, if anyone, was meant to be watching.

    The ledger

    CompanySectorAlleged LossApprox. Duration Before DiscoveryMechanismHow It Surfaced
    Intech GroupPayment aggregator~298m CFA (~€455,000)~4 yearsTreasurer allegedly re-triggered (“replayed”) already-completed transactions, rerouting funds to personal mobile-money walletsAn internal financial analyst flagged unusual transfers
    Sénégal Numérique SAState digital agency~46.4m CFA (~€70,000)~18 monthsSocial-media manager allegedly saved the corporate card and used it to fund personal e-commerce ventures
    SociumHR-tech startup~400m CFA (~$704,000), provisional~2 yearsFinance manager allegedly used bearer cheques, a ghost-employee payroll, mobile-money transfers and card withdrawalsA “routine review of financial operations,” per a person close to the company
    CinetPayLicensed payment institutionSettlement backlog exceeding $1.2m (over CFA 655m) owed to merchants and partnersThrough 2024, by investigators’ accountPlatform allegedly used by a merchant and an employee to process payments tied to loan-shark harassment and an unlicensed gambling operationCriminal investigation opened after victims filed harassment complaints

    What follows treats the underlying facts as alleged unless otherwise noted.

    A single point of failure, four times over

    Strip away the specifics and the mechanism repeats itself with almost mechanical fidelity: one employee, one system, and no second person required to approve what they did with it. At Intech Group, the treasurer did not need to hack anything — the “replay” function he is accused of exploiting was a legitimate feature of the company’s own payment API, designed to let staff re-send a transaction that had failed. Used correctly, it fixes technical hiccups. Used by someone who also controls where the money lands, it is a functioning ATM with no camera. At Sénégal Numérique SA, the control gap was smaller in ambition but identical in shape: one person authorised spending and the same person spent it, on a card nobody appears to have been reconciling against a budget line. At Socium, the finance manager is accused of running four separate channels — cheques, ghost payroll, a mobile wallet, a debit card — which is less a sign of criminal sophistication than of how much room a small finance team can offer someone nobody double-checks.

    This is the least glamorous explanation available, and probably the correct one: these were not, on the evidence reported so far, elaborate schemes defeating vigilant controls. They were unremarkable schemes running through the absence of controls that a dual-signature policy or a basic reconciliation habit would ordinarily catch within a pay cycle, not a presidential term.

    The maths of detection lag

    Duration is the more interesting variable than amount, and it is worth stating plainly: of the three cases with a reported timeframe, the average run before discovery works out to roughly two and a half years. That is not an industry benchmark drawn from an audit report — it is simply what results from averaging the figures, numbers that should probably not be this close together across unrelated companies in the same market

    None of the these was caught by an audit, a compliance function, or any of the risk-management infrastructure that seed-stage companies tend to list confidently in their pitch decks. Intech Group’s case surfaced because an analyst happened to notice the pattern in transaction logs. Socium’s surfaced during what its own source described, with commendable understatement, as a “routine review.” CinetPay’s surfaced because people being harassed over invented micro-loans filed complaints with a cybersecurity unit — a discovery mechanism that depended entirely on the fraud spilling outward into the lives of people who had never used the platform. In no case reported here did an internal control designed to catch this sort of thing actually catch it. The controls, as far as the public record shows, did not exist to fail.

    What the money bought, and what that reveals

    The forensic detail in these cases tends to be treated as colour — the BMW X5 allegedly bought with Socium funds for a rental-car side business, the Kia Sportage and Renault Arkana that Intech Group’s treasurer handed back as partial restitution. It is worth resisting that impulse, because the detail is informative rather than decorative. None of the accused, on the reporting available, laundered the proceeds through anything more sophisticated than a car dealership and a mobile-money wallet. That is not what fraud looks like when someone has anticipated getting caught; it is what fraud looks like when someone has correctly calculated that nobody is checking. 

    Two audiences, two sets of caveats

    To the companies’ credit, three of the four responded to discovery by going to the authorities rather than quietly settling the matter internally, which is more than can be said for plenty of larger, older institutions facing the same choice. CinetPay, for its part, issued a right of reply insisting it had “immediately terminated the contract with the merchant” and filed its own complaint once it learned of the misuse — a statement that reads, depending on one’s mood, as either a genuinely swift response or a well-rehearsed one; the two are not mutually exclusive, and nothing in the public record settles which.

    To the accused individuals’ credit, at least they were consistent: none of the four alleged schemes required unusual technical skill, elaborate cover stories, or accomplices beyond a courier and, in one case, a sibling. If there is a lesson in criminal minimalism here, it is that Senegal’s fintech sector did not need to be defeated by a sophisticated adversary. It needed, and in each case failed to provide, one colleague willing to ask a second question before a transaction cleared.

    Why this is a sector problem, not four unlucky companies

    It would be convenient to treat each case as an isolated personnel failure — a bad hire, caught eventually, case closed. The clustering argues against that reading. Several of the scandals emerged around the same period as major funding rounds or other significant transaction milestones. In Socium’s case, the coincidence is particularly striking: the company raised its $5m seed in 2024, led by Breega with Partech, Orange Ventures and Sonatel participating, while reports suggest the alleged fraudster’s footprint at the company stretches back roughly two years. The overlap does not establish a connection between the funding and the alleged misconduct, but it does raise a more uncomfortable question: how much can investors actually see when they conduct due diligence on a fast-growing company?

    Funding rounds and major transactions are, among other things, signals that outside parties have examined a company and found its governance adequate. What these cases suggest is that the signal and the substance are not always the same thing — that a lead investor’s due diligence can miss operational and internal-control failures that may already be taking place inside the business.

    A Dakar-based venture adviser, speaking to this publication on condition of anonymity after the Socium arrest, put the underlying risk plainly: with a small finance team, one person is often given “the keys to everything,” and without dual-authorisation payments or independent oversight, a company is one disgruntled employee away from a crisis. The four cases above are not simply four bad employees. They point to what can happen when that structural gap is left open long enough for different people, entirely unconnected to one another, to exploit it.

    The regional context

    None of this happens in a regulatory vacuum. The BCEAO has spent the past year moving aggressively to bring West Africa’s fast-growing payments industry under formal oversight. In 2025, it processed 79 applications for payment-institution status and approved 30, while 12 new electronic-money issuers brought the number of licensed issuers across the eight-country union to 81. Senegal, with 11, and Côte d’Ivoire, with nine, had the largest concentrations. The surge came as the central bank tightened its grip on a sector that had spent years operating ahead of formal regulation, extending a crackdown that made direct licensing a prerequisite for remaining in the formal payments system.

    The push is not merely about licences. Compliance also opens the door to PI-SPI, BCEAO’s interoperable instant-payment system connecting banks, mobile-money operators and microfinance institutions. The platform was officially launched in September 2025, with the central bank positioning it as the infrastructure for faster, interoperable payments across the union.

    That is, on its own terms, a reasonable and overdue push toward interoperability and formalisation. But it also creates a distinction the industry has yet to resolve: a licence can establish that a company is authorised to operate without establishing that its internal controls are strong enough to prevent a single employee from quietly emptying the till.

    That is not an argument against the licensing drive. It is an argument that a licence answers the question “Is this company authorised to operate?”, not “Can someone inside it steal for two years before anyone notices?” Investors, regulators and the companies themselves appear, for now, to be much better at answering the first question than the second.

    Latest articles

    Africa to LatAm: Busy Mobility Fintech Route Gets a Yango Mafia Boost

    Fuelled by informal workforces and bank credit gaps, vehicle-financing platforms are building cross-continental empires.

    Inside dLocal’s $23.7M AZA Finance Deal: $22.8M of Customers, IP and Goodwill

    The Nasdaq-listed payments group settled its restructured Africa transaction without paying cash.

    Telegram Ads, Money Mules and $16bn: The Shadow Corridors Linking China to Africa

    Chinese-language money laundering networks (CMLNs) have begun openly marketing their financial services to operators in five sub-Saharan African countries, according to latest reports.

    Egypt’s Licence Freeze Spawns $95m Tamweely Deal

    Egyptian digital payments and fintech group e-Finance for Digital and Financial Investments has agreed...

    More like this

    Africa to LatAm: Busy Mobility Fintech Route Gets a Yango Mafia Boost

    Fuelled by informal workforces and bank credit gaps, vehicle-financing platforms are building cross-continental empires.

    Inside dLocal’s $23.7M AZA Finance Deal: $22.8M of Customers, IP and Goodwill

    The Nasdaq-listed payments group settled its restructured Africa transaction without paying cash.

    Telegram Ads, Money Mules and $16bn: The Shadow Corridors Linking China to Africa

    Chinese-language money laundering networks (CMLNs) have begun openly marketing their financial services to operators in five sub-Saharan African countries, according to latest reports.