Evans Nandwa, a Kenyan information‑technology graduate employed by Ronford Digital Limited, was arrested in Nairobi and appeared before Magistrate Benmark Ekhubi at the Milimani Law Courts.

The Directorate of Criminal Investigations (DCI) Banking Fraud Investigations Unit says Nandwa was given legitimate access to NCBA Rwanda’s live backend during a scheduled maintenance on 6 June 2025 and, three minutes later, used his credentials to modify part of the bank’s core application code.

According to court documents, the code change was configured to recognise 70 specific accounts, causing withdrawal requests from those accounts to be marked as successful without the usual validation of funds or account legitimacy.

Investigators allege the 70 accounts were ghost profiles linked to cloned or fraudulently registered SIM cards created with stolen identification details, allowing transactions to bypass normal checks.

MTN Rwanda records show that 260 transactions involving those accounts were processed between 6 June and 14 June 2025, amounting to an estimated payout of KSh 57.5 million.

NCBA’s internal logs did not show corresponding legitimate debits for the disputed transactions, prompting the bank to revoke third‑party access credentials and launch a forensic review of the code changes.

The DCI has taken over the criminal investigation, tracing the suspicious modification to activity carried out using credentials assigned to Nandwa, and is seeking to determine the full extent of the alleged fraud, the creation of the ghost accounts, the destination of the funds and any possible accomplices.

The court has not yet ruled on the allegations; Nandwa’s appearance before the magistrate does not constitute a finding of guilt.