Two stories landed almost on top of each other this week and together they poke a hole in something the entire fintech industry has been quietly assuming for years.
First one: Nigeria's central bank opened a new track in its regulatory sandbox specifically for companies building on "permission-based data sharing," the technical term for open banking, where you as a customer authorize some third-party app to look at your financial data so it can offer you better credit, or smarter budgeting, or whatever the product is. The pitch, and it's a good one, is that this unlocks financial products for people who don't have a traditional credit history, using data they already generate every day. CBN wants to see what people are building, applications closed today.
Second one: South African telecom companies, MTN, Vodacom, Telkom, Cell C, all of them, lost about R199 million to what's called subscription fraud over the past year. Reported cases jumped 307%. And here's the part that stopped me: this isn't fraudsters using fake documents or exploiting some technical loophole. They're using real identity documents and real bank statements, stolen from somewhere else, to pass the exact verification checks these companies rely on. The system worked exactly as it was designed to work. It just verified the wrong person.
Sit with that for a second, because I think it matters more than either headline on its own. Open banking, permission-based data sharing, all of this next wave of African fintech innovation, it all runs on one foundational assumption: that when someone presents a real ID and real supporting documents, that person actually is who the documents say they are, and actually is consenting to whatever's happening. That assumption has always been a little shaky. What South Africa's telcos just showed us, at scale, with real numbers, is that it's now actively being exploited, and not by amateurs. A 307% jump in a single year isn't opportunists getting lucky, that's organized syndicates who've figured out that stealing a real identity is more profitable than faking one, because real identities sail through verification that's specifically built to catch fakes.
So here's my actual worry. Nigeria is about to onboard a fresh batch of startups building products that live and die on exactly this kind of identity trust, permission-based data sharing where a third party gets access because someone "consented." If the underlying assumption, that the person consenting is actually the person whose data it is, is already breaking down in South Africa's telecom sector at R199 million a year and rising fast, there's no reason to think fintech is somehow immune. If anything, fintech is a richer target, because the data being shared is directly about money, not just a phone contract.
I don't think this means open banking is a bad idea, I actually think it's one of the more genuinely useful things happening in African fintech right now, because it can bring real financial products to people the traditional banking system has always ignored. But I think everyone building in this space, and every regulator approving sandbox applicants, needs to treat identity verification as the actual hard problem here, not a solved box to tick before the interesting product work starts. The lesson from South Africa isn't "add more security questions." It's that a real document in a criminal's hands passes every check we've built, and that's not a bug you patch, it's a structural weakness in how the whole system decides who to trust. Whoever solves that properly, not whoever ships the flashiest permission-based app, is going to be the one who actually makes this next wave of African fintech work the way it's supposed to.

