By Joseph Dumbula
The National Oil Company of Malawi Limited (NOCMA) has lost US$403,605, approximately K700 million, after hackers allegedly infiltrated business communications and tricked the state-owned company into transferring money to a fraudulent bank account.
According to NOCMA, the fraudsters impersonated Mozhandling Limited, a Mozambican company involved in handling fuel shipments through the Port of Nacala, one of Malawi’s strategic fuel import corridors.
The hackers allegedly gained access to email exchanges between NOCMA and Mozhandling and used information from the correspondence to make their communications appear legitimate. They subsequently supplied fraudulent banking details, claiming that Mozhandling had opened a new account with Bank of America.
Believing the instructions to be authentic, NOCMA directed the National Bank of Malawi on April 29, 2026, to transfer US$403,605 to the account provided by the fraudsters.
The deception went undetected for approximately two weeks and only came to light when a legitimate representative of Mozhandling contacted NOCMA to inquire about the outstanding payment. By then, the money had already been transferred to the fraudulent account.
NOCMA reported the matter to the Malawi Police Service, while Bank of America has also launched an investigation aimed at tracing the funds and helping identify those behind the scheme.
The incident has raised serious questions about cybersecurity, payment verification and financial controls at one of Malawi’s most strategically important state-owned companies. NOCMA plays a central role in securing fuel supplies for the country, making the breach particularly significant at a time when reliable energy imports remain critical to Malawi’s economy.
NOCMA management has acknowledged that weaknesses in its systems and procedures contributed to the loss. The company said some vulnerabilities emerged following the government’s introduction of the Government-to-Government fuel procurement arrangement without sufficiently developed operational and cybersecurity safeguards.
The revelation is likely to intensify scrutiny over how major payments are authenticated, particularly when suppliers communicate changes to banking information. The apparent ability of fraudsters to manipulate an established correspondence chain also highlights the growing threat posed by business email compromise, in which criminals impersonate trusted suppliers or executives to redirect legitimate payments.
NOCMA has since reverted to the Open Tender System and is reviewing its payment verification procedures and internal controls in an effort to prevent similar incidents.
The company has pledged to continue cooperating with the Malawi Police Service and Bank of America as investigations seek to establish how the communications were compromised, identify those responsible and determine whether any of the US$403,605 can be recovered.
For NOCMA, the investigation will not only be about recovering the missing millions but also about addressing the cybersecurity and financial-control weaknesses that allowed a routine fuel-related transaction to become an expensive fraud.