A story making the rounds on Nigerian tech LinkedIn this week has reopened an argument the industry keeps having and never quite resolving: what happens inside a fintech company after something goes badly wrong, and who pays for it.
According to an account that circulated widely online, a number of engineers at Bluebulb, the UK-regulated cross-border payments and treasury firm that has spent the past year expanding aggressively across Nigeria, were taken to the Panti Police Station in Lagos following unspecified security incidents. Some were reportedly released. Others were said to have been held without charge or bail, under a working assumption that the incidents were an inside job. Bluebulb has not issued a public statement addressing these claims.
A source at Bluebulb, speaking to TechMoonshot on condition of anonymity, said the police have since obtained a remand order covering the detained staff, and that the matter is now out of the company’s hands. If accurate, a remand order would move the case from an internal HR question into the formal court system, with a magistrate rather than Bluebulb’s management now controlling how long the engineers remain in custody before any charge is filed. TechMoonshot has not independently verified the remand order and could not immediately confirm its terms or the court that issued it. What the episode has done, whether or not every detail holds up, is force a public conversation about how fintechs treat their engineers when security fails.
Security Spending Is Cheap Compared to the Alternative
The most immediate lesson in the discourse is one every fintech founder claims to believe and few fully fund. Security operations centres, endpoint detection, mobile device management, web application firewalls, access controls and incident-response playbooks are unglamorous line items. They rarely show up in a pitch deck. They almost never win a founder an award for finance excellence.
But they are the difference between a contained incident and a company hunting for scapegoats. A well-instrumented environment produces evidence: logs, access trails, timestamps that either implicate someone or clear them within hours. An under-invested one produces suspicion instead, because suspicion is cheaper than forensics.
Nigeria’s fintech sector has quietly demonstrated it understands this at the policy level. The Central Bank’s GPS tracking mandate for PoS terminals exists precisely because unmonitored infrastructure is fraud-prone infrastructure. The same logic applies inside the engineering org, not just at the point-of-sale edge.
Due Process Is Not a Luxury for Fast-Growing Startups
The second and more uncomfortable question is what a company owes an employee before it hands them to the police. Nigerian labour law and basic due process both suggest the answer is: more than proximity to a system.
Being the engineer on call when an incident happens is not evidence of wrongdoing. It is evidence of being on call. Insider threats are real, and Nigeria’s financial sector has documented an unusually high rate of them, but real does not mean automatic. A 2023 PwC Nigeria survey found insider threats had climbed to the top cybersecurity concern for over half of local companies, up from roughly a third two years earlier, according to reporting on the survey. That trend explains why management teams are jumpy. It does not justify treating access as guilt.
TechMoonshot has covered the regulatory side of this tension before. Nigeria’s ₦7.2 billion in data privacy penalties collected under the NDPA has already built an entire compliance economy around handling breaches properly, with certified data protection officers and licensed audit firms now standard fixtures at serious fintechs. A company that can afford a compliance retainer can generally afford an investigation before an arrest.
The Case for Management’s Instinct to Act Fast
It would be unfair to write this without steelmanning the other side. Fintech leadership teams operate under genuine pressure that outsiders often underweight. When customer funds are involved, delay has a cost too. Regulators expect swift disclosure. Investors expect containment. And if an incident really is an inside job, every hour spent deliberating is an hour a bad actor has to cover their tracks or move funds further downstream.
Founders who have lived through a live breach will say, not unreasonably, that the instinct to lock down and interrogate immediately comes from having watched slower companies lose more money and more customer trust by waiting. Speed is not automatically the villain of this story.
Evidence, Not Proximity, Should Drive the Response
The rebuttal is that speed and due process are not actually in tension, because the fast response should be forensic, not accusatory. Pulling logs, freezing access, and isolating systems can happen within minutes without anyone being marched to a police station. Nigeria’s federal infrastructure providers have been urging exactly this posture, pushing companies toward proactive planning, simulation and tested incident-response protocols rather than reactive panic once something has already gone wrong.
The deeper cost of skipping that step is cultural, not just legal. One engineer at Deimos put it plainly in an earlier TechMoonshot interview: security itself is an innovation, not a tax on it. That framing only survives inside a company where engineers trust that a breach will trigger an investigation, not a manhunt. Once that trust breaks, in Nigeria’s tight-knit and rumour-fluent tech labour market, it does not come back with an apology. It comes back, if at all, after months of attrition and a noticeably harder time hiring.
Nigerian fintech has spent the last three years building genuine regulatory maturity, from IMTO licensing regimes like the one Fincra secured from the CBN to data protection frameworks with real enforcement teeth. Whatever ultimately turns out to be true about Bluebulb, the industry conversation it triggered is really about whether that same maturity extends to how companies treat the engineers who keep the systems running. Growth capital and regulatory licences are only half the infrastructure a fintech needs. The other half is a workplace where a security incident produces an investigation, not a scapegoat.