Bank of Uganda (2024): when fraudulent transfers reach a central bank

Central banks sit at the top of the financial trust chain, which is exactly why the reports that emerged from Kampala in late 2024 drew worldwide attention. The episode is still best described through what was publicly reported — and what officials confirmed — rather than as a settled story.

What happened

In late November 2024, Uganda's state-owned newspaper New Vision reported that accounts at the Bank of Uganda had been breached and that approximately 62 billion Ugandan shillings — around 16 to 17 million US dollars at the time — had been fraudulently transferred out. The report attributed the intrusion to actors described as a group calling itself "Waste", said to be based in Southeast Asia; Ugandan coverage also referred to the affected central-bank accounts in similar terms. Reuters subsequently reported that two officials had confirmed an incident had occurred, and that Uganda's finance ministry acknowledged the matter.

According to the reporting, portions of the money were transferred to accounts abroad — destinations reported included Japan and the United Kingdom — while other portions moved through domestic channels. Ugandan authorities stated that part of the funds had been blocked or recovered, though the precise amounts recovered varied between reports.

Investigations were opened on multiple tracks: the Criminal Investigations Department of the Ugandan police, and a special audit by the Auditor General ordered at the direction of the presidency. Subsequent Ugandan reporting and court proceedings in 2025 indicated that investigators were examining possible insider involvement alongside the external-intrusion narrative, and several individuals — reported to include bank and ministry personnel — faced charges. The definitive official account of how the fraud was executed has not been published in full, so competing explanations should be treated as unresolved.

How the attack worked

Because the forensic findings were not fully public, the mechanics must be stated cautiously. The publicly reported picture — fraudulent payment instructions executed from within legitimate central-bank payment processes, funds routed to foreign and domestic beneficiaries, partial recovery after detection — is consistent with the way large payment-system frauds generally work: either compromised credentials and access to payment infrastructure, insider abuse of legitimate access, or a combination of the two. Ugandan investigators themselves publicly pursued both possibilities. What is clear is that the controls that matter in such cases are identity, authorization and verification controls around payment initiation — human-layer controls as much as technical ones.

The impact

The reported loss was material even after partial recovery. Beyond the money, the incident triggered a special audit of the central bank, parliamentary scrutiny, criminal proceedings, and uncomfortable regional questions: if fraudulent instructions can be executed against a central bank, every commercial bank and treasury in the region has to re-examine its own payment controls. Trust, once questioned at the top of the chain, is expensive to rebuild.

Lessons for African organisations

  • Payment initiation is the crown-jewel process. Multi-person authorization, hard limits and out-of-band confirmation must apply to every high-value instruction — no exceptions for seniority or urgency.
  • Insider risk and external intrusion are not alternatives. Real frauds often blend both; controls and monitoring must assume either.
  • Credential and session security for payment operators — phishing-resistant MFA, privileged-access management, immediate revocation — decide how far an intruder can go.
  • Detection speed determines recovery. The funds that were saved were the funds that were frozen fast.
  • Prepare for public scrutiny. Financial institutions should assume incidents become public and plan communications accordingly.

Sources

  • New Vision reporting on the breach and reported amounts (2024)
  • Reuters coverage confirming an incident via Ugandan officials (2024)
  • Daily Monitor and subsequent Ugandan reporting on investigations and court proceedings (2024–2025)

Whether the first domino is a phished operator or a colluding insider, the human layer decides the outcome — measure yours with our free Human Risk Maturity Assessment.