Inside the Panti Playbook: Fintech’s Arrest-First Habit

From Flutterwave’s 2023 detentions to the Bluebulb allegations making the rounds this month, Nigerian fintechs have repeatedly turned to the Panti police station as a first response to security incidents.
Fintech's Arrest Habit
Fintech’s Arrest Habit

The State Criminal Investigation and Intelligence Department in Yaba, Lagos, known to almost everyone in Nigerian tech simply as Panti, was not built for fintech. It has spent decades as the address people gave when they meant a place you did not want to end up. Lately, it has become something more specific: the default destination when a Nigerian payments company decides a security incident is, in fact, a crime committed by its own staff.

That is reportedly where a number of Bluebulb engineers were taken this month, according to an account that circulated widely on LinkedIn and which TechMoonshot has covered separately. A source at Bluebulb, speaking on condition of anonymity, told TechMoonshot that the police have since obtained a remand order and that the matter is now out of the company’s hands. Bluebulb has not issued a public statement addressing the claims. Whatever the outcome for the individuals involved, the broader shape of the story is not new. Look back three years and the same police station, the same instinct, and a strikingly similar sequence of events show up in the record of one of Nigeria’s most prominent fintechs.

Flutterwave Already Wrote This Playbook

In February 2023, Flutterwave’s legal counsel walked into the Panti station and reported an unauthorised transfer of ₦2.9 billion, roughly $6.3 million at the time, out of the company’s accounts. The company sought and won a court order to freeze 170 accounts across 27 banks tied to the funds. Weeks later, a fresh breach surfaced, and Nigerian police detained several more people connected to the case.

One of them, Damilola Williams, told reporters he had voluntarily gone to Panti on March 29, 2023, hoping to clear his name and get his frozen accounts released. Instead, he and four others were held until March 31, when they were released on bail. His account of the episode was blunt: the police and the Economic and Financial Crimes Commission had detained beneficiaries “on Flutterwave’s behalf.” By December 2024, the pattern had scaled considerably. Nigerian police had arrested customers linked to a separate ₦11 billion Flutterwave fraud case and were preparing to pursue 601 more people connected to earlier breaches, according to court documents reviewed by local outlets. Flutterwave has maintained throughout that customer funds were never at risk.

The Flutterwave cases mostly involved external beneficiaries rather than engineers on the payroll, which is a meaningful distinction. But the mechanism is identical to what Bluebulb is now accused of: a fintech reports an incident to Panti, the police move quickly and broadly, some of those detained are released without charge once the picture clarifies, and the company’s public position stays largely unchanged throughout. Flutterwave has since gone on to double its profit margins and continue expanding, a reminder that reputational fallout from these episodes rarely shows up on a balance sheet the way it shows up in an engineer’s LinkedIn post.

Kenya’s Courts Are Starting to Push Back

Zoom out from Lagos and a parallel story has been unfolding in Nairobi, with a different ending. A Safaricom manager named Wamatu was arrested and later dismissed after the telecom giant reported a data breach to investigators. Wamatu argued in court that the company had engineered his arrest to make him a scapegoat for losses that were not his doing, and that the internal disciplinary process had been decided before it even began. Safaricom denied any ulterior motive, saying it had simply reported suspected criminal conduct and that police made their own independent finding before proceeding. A Kenyan court ultimately upheld his sacking.

But the legal ground under that kind of defence has since shifted. In a separate case, Kenya’s High Court ruled in May 2026 that Safaricom must pay KES 9.9 million, about $76,000, over a data breach in which employees extracted subscriber data, including M-Pesa transaction records and geolocation history, and sold it to betting companies between 2018 and 2019. The breach touched more than 11.5 million subscribers. Justice Bahati Mwamuye’s judgment explicitly rejected the idea that a company could point to a “rogue employee” and treat that as the end of its own liability. Constitutional privacy obligations, the court found, cannot be outsourced to whichever staff member happened to have access when something went wrong.

That ruling matters well beyond Kenya’s borders. It reframes the entire logic that makes an arrest-first response tempting in the first place. If a company can no longer escape liability simply by identifying an individual to blame, the incentive to rush that identification, correctly or not, starts to weaken. Nigeria has no equivalent case law yet. The Nigeria Data Protection Act gives the regulator real enforcement teeth, evidenced by the ₦7.2 billion in penalties it has already collected, but that regime is built around corporate accountability to the regulator, not around protecting individual employees from being handed to the police before an investigation runs its course.

Why the Pattern Keeps Repeating

The uncomfortable truth is that the underlying anxiety driving this behaviour is not manufactured. Insider involvement in African financial fraud has been climbing for years, not shrinking. A 2023 PwC Nigeria survey found insider threats had become the top cybersecurity concern for 52 percent of Nigerian companies, up from 38 percent just two years earlier. Separate reporting citing Nigeria’s data protection authorities has put the share of breaches involving insiders at roughly 60 percent, triple the global average typically cited in international benchmarks. Nigeria’s banking sector has openly been described as being in the middle of a cybersecurity crisis, a framing that has followed the industry through a string of bank breaches serious enough to prompt talk of a national coordinating body.

Set against that backdrop, a management team’s instinct to move fast and involve police immediately is not irrational. It is a rational response to a genuinely elevated risk, filtered through weak internal forensic capacity. Nigeria’s federal infrastructure provider Galaxy Backbone has spent the past year pushing companies toward proactive incident-response planning precisely because so few organisations, fintech or otherwise, have the tooling to distinguish a compromised insider from an unlucky one within the first 48 hours. Without that tooling, the fastest available lever is often the police, and the police station with the most fintech experience in Lagos happens to be Panti.

What breaks down is not the impulse to investigate quickly. It is the substitution of an arrest for that investigation. An engineer at Deimos, speaking to TechMoonshot last year, argued that security itself is an innovation in fintech, not a defensive afterthought. That framing only holds up if the companies practising it treat their own engineers as part of the security function rather than its most convenient suspects.

The Flutterwave beneficiaries who spent two days in Panti in 2023 were eventually released without charge. The Bluebulb engineers, according to the anonymous source who spoke to TechMoonshot, are now under a remand order that has moved their fate out of the company’s hands entirely. Kenya’s courts have started closing the exit that let companies treat an arrest as a substitute for accountability. Whether that legal shift crosses into Nigeria, or whether Panti keeps functioning as the industry’s default incident-response tool, is the question the rest of this story is still being written to answer.

Leave a Reply

Your email address will not be published. Required fields are marked *

Prev
WIOCC Secures $300M From AFC, Vision Invest for Africa Digital Infrastructure
WIOCC Secures $300M From AFC, Vision Invest for Africa

WIOCC Secures $300M From AFC, Vision Invest for Africa Digital Infrastructure

WIOCC Group has secured $300 million from Africa Finance Corporation and Saudi

You May Also Like