Fact-check | July 30, 2026: The claim that Nigerian fintechs must now refund every scam transfer is misleading without context. A CBN instant-payment security circular is in force, but the reimbursement language being shared online comes from a document the CBN still lists as an exposure draft.
A sweeping claim moved through Nigerian fintech discussions this week: a bank or fintech can be made to refund an authorised transfer even when the customer pressed the send button.
There is a real policy story behind it. There is also an important gap between the headline and the documents.
The Central Bank of Nigeria introduced new controls for instant payments from July 1, 2026. They cover device binding, transaction limits, stronger identity checks and fraud monitoring. A separate CBN draft sets out circumstances in which a victim of authorised push payment fraud could qualify for reimbursement. The second document is conditional, and its public status matters.
What readers should keep straight
- Already in force: minimum security and customer-control requirements for instant-payment services.
- Still labelled a draft: the APP fraud document containing the detailed reimbursement test.
- Not the same loss: sending a gift card code after seeing a fake credit alert is different from being tricked into making an outgoing bank transfer.
The claim travelled farther than its source
A July 29 post about Nigerian fintech liability said financial institutions can now be liable for authorised push payment, or APP, fraud even when a user initiated the transaction. That wording removes nearly all the conditions attached to the underlying proposal.
APP fraud is not simply any transfer a customer later regrets. It describes a situation in which someone is manipulated into authorising a payment to a fraudster. The CBN exposure draft says eligibility would depend on the facts, including whether the payment was made under false pretence, whether the customer reported it within 72 hours and cooperated, whether the customer was negligent, and whether the financial institution failed to use appropriate controls.
That is a case-by-case test. It is not an automatic refund switch.
There is a second reason for caution. On July 30, the CBN public circular feed still identifies the reimbursement document as the Exposure Draft of the Guidelines for Handling Authorised Push Payment Fraud. We found no final version in that feed replacing the draft.
Four dates explain the confusion
| Date | What happened | Why it matters |
|---|---|---|
| December 1, 2025 | CBN listed its APP fraud guidelines as an exposure draft. | The proposed reimbursement rules were opened for comment, not presented as a blanket guarantee. |
| March 12, 2026 | CBN issued the Additional Functionalities for Instant Payment circular. | This is the source for opt-out controls, fraud monitoring, identity checks and device rules. |
| July 1, 2026 | The instant-payment requirements took effect. | Banks, other financial institutions and payment service providers had to implement the minimum controls. |
| July 29, 2026 | Online posts revived the reimbursement claim in much broader language. | The live security circular and the draft reimbursement framework were presented as one settled rule. |
This does not make the policy unimportant. It means readers should name the document they are relying on before making a legal or financial claim.
What changed inside instant-payment services
The live July 1 requirements are practical. According to the CBN’s reforms and initiatives summary, customers must be able to disable instant transfers voluntarily and later change that preference through a process protected by multi-factor authentication. In-person transfers at a bank remain available when the online instant-payment option is disabled.
Financial institutions must also let customers choose lower personal transaction limits, subject to verification and risk assessment. They are required to use enterprise-level fraud monitoring and stronger identity checks for online account opening and reactivation.
The device rule is especially relevant to people who change phones frequently. A mobile financial-services app can be enabled on only one device at a time. Moving it to another device triggers reactivation and authentication.
For the first 24 hours after a new mobile-app activation, the circular sets a maximum NGN 20,000 limit. For a new account, that limit applies to inflows and outflows. For an existing account moved to a new device, it applies to outflows.
That temporary limit does not change the value of a gift card. It can affect how money is received or moved through a newly activated app, but it is not a gift card rate, a payout promise or proof that a card transaction is safe.
Gift card sellers can face three different problems
1. A fake credit alert, followed by a lost code
A buyer sends a screenshot or an SMS that appears to show payment. The seller reveals the card code, then discovers that no money settled in the bank account.
In that situation, there may be no incoming bank transfer to reverse. The loss is the disclosed gift card code. The new instant-payment controls do not turn a fake alert into a completed payment, and the APP reimbursement draft should not be advertised as a guaranteed remedy.
Check the settled balance and transaction reference inside the official banking app. A buyer’s screenshot is not confirmation.
2. A request to pay a “release” or “verification” fee
A supposed buyer or platform says the payout is waiting, but the seller must first transfer money to unlock it. This involves an outgoing payment and is closer to the type of manipulation described as APP fraud.
Stop before sending the fee. If money has already gone out, contact the financial institution through its official fraud channel immediately. The draft mentions a 72-hour reporting test, but waiting makes recovery harder and can allow funds to move through more accounts.
3. A genuine payout that is later disputed
A real credit can still become part of an investigation if the sending account was compromised or used without authority. A seller should be able to show what the payment was for without exposing the full gift card code in a public email or chat.
Keep the platform account record, quote, payout reference, timestamp and proof of the card’s source. Cooperate with the bank’s questions. Do not move disputed funds in an attempt to hide their origin.
An offer far above the current gift card rate estimate deserves more checking, not a faster handover. GiftCardsRate provides market references; it does not process trades or guarantee a buyer’s payment.
A clean case file beats a long complaint
If a transfer or payout goes wrong, the order of the evidence matters. Build the record while the details are still visible:
- Save the transaction identity. Record the amount, date, time, account names, bank or fintech, and the in-app transaction reference.
- Preserve the trade context. Keep the quote, platform profile, support conversation, stated fees and payout terms. Save the gift card receipt if one exists.
- Protect the code. Redact the full gift card number and PIN from ordinary complaint emails. Share sensitive details only through a verified support process when they are genuinely required.
- Report through the official channel. Ask for a case reference and keep every response. Do not continue a conversation through a phone number supplied by the suspected scammer.
The CBN’s consumer complaint guide says a customer must first complain to the bank or regulated financial institution. If the institution does not resolve the complaint within the stated period, the customer can escalate it to the CBN Consumer Protection Department with the transaction history and proof that the institution was contacted first.
That escalation timetable is not a reason to delay an initial fraud report. Report suspected fraud as soon as it is discovered, then preserve the case reference for any later escalation.
Our verdict
The CBN has raised the minimum security standard for Nigerian instant payments. That part is current and took effect on July 1.
The broader claim that every bank or fintech must refund a scam transfer goes beyond the public record we checked. The detailed reimbursement test is still labelled an exposure draft, and even that draft makes eligibility conditional on the investigation, the customer’s conduct and the institution’s controls.
For gift card sellers, the distinction is more than legal wording. A fake payment alert, an outgoing “release fee” and a disputed genuine payout are three different events. Record them differently and report them accurately.
Editorial note: GiftCardsRate is an independent gift card rate information website. It is not a bank, payment service provider or gift card buyer. This report is informational and is not legal advice. We will update it if the CBN publishes a final APP fraud guideline that changes the position described above.
