
by MAVHUTO BANDA
LILONGWE, (CAJ News) – THE Human Rights Defenders Coalition (HRDC) is demanding that heads must roll at the National Oil Company of Malawi (NOCMA) following the reported loss of K700 million (US$403 605) through cyber-enabled fraud.
This is one of the most prominent digital heists involving a public sector institution in the Southern African country.
The attackers utilised sophisticated Business Email Compromise (BEC), intercepting and spoofing communications from a legitimate international logistics partner, Mozhandling Limited, to redirect a massive payment straight into a fraudulent Bank of America account.
HRDC has branded this a national scandal.
“This is not merely a story about cybercriminals,” it stated.
“It is a serious failure of governance and financial controls that has resulted in the loss of a huge amount of public money.”
HRDC said while the sophistication of the alleged fraudsters must be investigated and those responsible brought to justice, this incident could not be dismissed as simply a case of cybercriminals deceiving NOCMA. “The critical issue is how fraudulent payment instructions were accepted, verified and acted upon without adequate safeguards to protect such a substantial amount of public money. The loss raises serious questions about NOCMA’s internal controls, oversight mechanisms and the responsibility of officials entrusted with safeguarding public resources.”
The rights body said the investigation must establish whether there were failures, negligence or breaches of procedure within NOCMA that contributed to the loss.
“Those entrusted with authorising, verifying and processing the payment must account for their actions and decisions. Where responsibility or culpability is established, there must be consequences.”
While retail or mobile money scams happen frequently on a smaller scale, high-profile corporate and state-level cyber-enabled fraud of this magnitude involving critical infrastructure and state fuel importers is rare in Malawi.
The case has drawn public scrutiny because it highlights major institutional vulnerabilities.
It has exposed loopholes tied to the rapid rollout of government-to-government procurement models before proper cybersecurity safeguards were fully implemented.
– CAJ News