The Nigeria Financial Intelligence Unit (NFIU) has exposed a series of sophisticated crowdfunding networks and novel financing tactics currently employed by terrorist organizations to raise, transfer, and manage funds for their illicit operations.
These revelations were formally outlined in the NFIU’s 2025 Annual Report, which was obtained by The PUNCH.
According to findings released by the NFIU, individuals financing terrorist activities are opening bank accounts in women’s names. In addition, these financing networks routinely utilize mobile phone numbers for banking services and account alerts that are not registered to the actual account holder or the genuine beneficiary of the funds.
Multi-Layered Crowdfunding and Foreign Remittance Networks
The operational mechanism of the crowdfunding scheme involves foreign-based facilitators who leverage social media platforms to solicit monetary donations under the guise of funding humanitarian relief projects or educational support.
Also Read : Documents Unveil How Fake Federal Office Solicited Funds and Land From State Governors
Once collected, these funds are systematically transferred through multiple complex layers before reaching operational terrorist cells situated across Nigeria.
The intelligence agency highlighted that terrorist sympathizers are generally urged to make relatively small individual contributions, usually between $50 and $500, utilizing specialized PayPal links or standard banking accounts.
These transaction amounts are intentionally kept low to prevent triggering automated anti-money laundering (AML) alerts within financial institutions.
In detailing this funding method, the NFIU report documented a specific operational case study:
“The following is a case study on Crowdfunding Network identified during the year: A foreign-based facilitator runs social-media campaigns claiming humanitarian relief or educational support and uses encrypted apps (Telegram, Signal) to share links to convincing PayPal pages or standard bank accounts.”
“Hundreds of sympathiser donors contribute $50–$500 each, amounts small enough to avoid most automated AML alerts.”
Following the initial collection phase, the donated funds are pooled into a central “master account” under the administrative control of a senior operative of the group who resides legally in a foreign nation.
The NFIU further disclosed that the accumulated funds are subsequently broken down into dozens of smaller, sub-threshold payments. These fragmented sums are moved through International Money Transfer Operators (IMTOs) and mobile remittance applications to a decentralized network of financial mules operating within Nigeria.
The report identified students, small-business owners, and relatives of operatives among those utilized as money mules, pointing out that this structured fragmentation strategy is engineered to avoid mandatory transaction reporting limits and obscure the original origin and ultimate destination of the money.
Regarding this distribution process, the report stated:
“Rather than sending one large transfer, the senior member fractures the funds and sends dozens of sub-threshold payments through IMTOs and remittance apps to a network of money mules in Nigeria; students, small-business owners, or relatives, avoiding reporting triggers.”
“Upon receipt, the money was either converted to cash, used to purchase dual-use items such as motorcycles, fertilisers and satellite internet equipment, or transferred through mobile banking channels to logistics managers and field operatives,”
The agency described this final operational phase as the full “integration” of illicit financial assets into active terrorist operational financing.
Gender-Based Proxy Accounts and Identity Laundering
Alongside international remittance systems, the NFIU highlighted the utilization of gender-based proxy accounts as another emerging operational method in terrorist financing networks. Through this technique, terrorist organizations establish bank accounts registered under women’s names while male commanders and logistics coordinators secretly maintain complete physical and operational control over the funds.
Explaining this identity manipulation method, the agency stated in its report:
“Terrorist financiers are opening bank accounts in women’s names while male commanders and logistics managers secretly control them.”
“They exploit cultural norms that make women less likely to be suspected by authorities, using wives, sisters, or female associates as fronts to distance illicit funds from the true operatives.”
“This tactic functions as identity laundering: women’s accounts are managed by men who hold ATM cards, mobile-banking credentials, and PINs, while the women often remain unaware of the transactions and volumes.”
Bypassing Security Links via Unregistered SIM Cards
The report additionally revealed that terrorist facilitators regularly use mobile telephone numbers for banking operations and automated transaction alerts that are completely disconnected from the actual account holders or true beneficiaries.
Also Read: Dollar to Naira Exchange Rate Today: Official and Parallel Market Rates for August 25, 2026
By deploying pre-registered SIM cards, phone numbers tied to deceased persons, and SIM cards linked to female proxy accounts, these networks effectively sever the regulatory link between bank accounts, SIM cards, and Bank Verification Numbers (BVNs).
Addressing this security evasion method, the NFIU noted:
“Terrorist facilitators use phone numbers for mobile banking or account alerts that are not registered to the account holder or the true beneficiary.”
“They bypass the security link between SIM cards and BVNs by using pre-registered SIMs, SIMs registered to deceased people, or SIMs tied to gender-based proxies. This severs the audit trail: when a transaction is flagged, investigators trace the phone to an unrelated person, letting the real facilitator stay anonymous and continue operations,”
Transaction Narrations, ISWAP Accounting, and Coded Language
In detailing how terrorist cells conceal their financial transfers, the NFIU revealed that it uncovered sophisticated methods of disguising transactions using either explicit professional descriptions or coded narrations. Cells linked to the Islamic State West Africa Province (ISWAP) routinely utilize precise, detailed transaction descriptions to maintain what financial analysts categorize as an internal accounting and bureaucratic control mechanism.
The report provided detailed insights into ISWAP’s financial administration:
“Terrorist cells, particularly those linked to ISWAP, routinely use precise, professional-sounding transaction narrations to maintain internal accounting. Operating like “shadow states” with strict bureaucratic controls, they require detailed descriptions so field commanders can justify expenses to central financial controllers. Although truthful narrations appear counterintuitive, they create an internal audit trail; analysts repeatedly observe high-frequency, logistics-related payments with accurate narrations sent from a single source to multiple recipients.”
Conversely, the NFIU pointed out that other facilitators employ benign words, secret codes, and alphanumeric strings within transaction descriptions to avoid detection.
The report explained that these facilitators frequently switch between different languages to bypass automated banking keyword filters and conceal the purpose of their financial transfers.
The NFIU concluded its findings on transaction concealment noting:
“Transaction descriptions employ innocuous words, secret codes, or alphanumeric strings to conceal intent. Facilitators use this coded language, often switching languages to evade banks’ automated keyword filters that flag terms like ‘Jihad,’ ‘Arms,’ or ‘Boko.’”
“This practice obscures the true purpose of transfers, preventing detection and enabling continued financing,”