October is National Cyber Security Awareness Month in Ghana. This year's theme, set by the Cyber Security Authority (CSA), is "Securing Ghana's Digital Finance Ecosystem: Building Trust Through Collaboration and Cyber Resilience", and the figures shared at the launch in Accra on 2 September 2026 explain why.

What the CSA reported

  • The national CERT (CERT-GH) recorded 3,876 cyber incidents from January to July 2026.
  • 1,818 of them, about 47%, were online fraud.
  • In the payment service provider sector, electronic fraud incidents rose 54%, and the value at risk rose 95%, from GH¢19 million to GH¢37 million.
  • Citing the Bank of Ghana's 2025 Fraud Report, the CSA said fraud cases across banks, specialised deposit-taking institutions and payment service providers rose 48%, from 16,733 in 2024 to 24,778 in 2025.

The CSA named the methods: online fraud, impersonation, payment diversion and business email compromise. None of them needs advanced hacking. They work by getting a real person to send money or hand over a login.

How these frauds usually reach a business

  • Payment diversion. A supplier's "new bank details" arrive by email, often from a lookalike address or from the supplier's own hacked mailbox. The next payment goes to the criminal.
  • Business email compromise. Someone signs in to a staff mailbox with a stolen password, reads ongoing conversations, then replies inside a real thread at the right moment.
  • Impersonation. A call or WhatsApp message from "the MD" or "the bank" asks for an urgent transfer, a code, or a PIN.

Controls that stop most of it

  1. Turn on multi-factor authentication (MFA) for email, banking and accounting. A peer-reviewed Microsoft study found MFA reduced the risk of account compromise by more than 99%. An authenticator app is stronger than SMS codes.
  2. Verify every change of bank details by phone, using a number you already have on file, never one given in the email that asked for the change.
  3. Split the job. The person who sets up a new payee should not be the person who approves the payment.
  4. Slow down on urgency. "Pay today, the MD is travelling" is a pattern, not a reason. A five-minute call back costs nothing.
  5. Give each person their own login. Shared accounts make it impossible to see who did what, and impossible to remove one person's access.
  6. Protect your email domain with SPF, DKIM and DMARC, so criminals cannot easily send mail that appears to come from you. Our guide to SPF, DKIM and DMARC explains the steps.

If it happens

Call your bank immediately; the sooner a transfer is reported, the better the chance of stopping it. Then report the incident to the CSA on 292 (call or text, 24 hours). Change the passwords of any account involved and check the mailbox for forwarding rules a criminal may have added.

Teknikal Ghana sets up MFA, email security and access controls for businesses in Sekondi-Takoradi and the Western Region. If you would like your setup checked, request a quote and tell us what you use today.