By Malawi Freedom Network
August 25, 2026
The National Oil Company of Malawi Limited (Nocma) has lost US$403,605—equivalent to about K700 million—to cyber fraud after criminals allegedly impersonated a Mozambican company responsible for handling fuel shipments at the Port of Nacala.
Nocma has confirmed the incident, saying the Malawi Police Service and Bank of America have launched investigations aimed at tracing the funds and identifying those behind the fraudulent transaction.
According to Nocma, the fraudsters intercepted email communications involving Mozhandling Limited, a company contracted to provide port-handling services for fuel shipments passing through Nacala.
The criminals allegedly used the compromised communication to send Nocma forged banking information, claiming that Mozhandling had opened a new account with Bank of America.
Believing the instructions to be genuine, Nocma directed the National Bank of Malawi on April 29, 2026, to transfer US$403,605 to the account supplied by the fraudsters.
The deception was only discovered approximately two weeks later when a legitimate representative of Mozhandling contacted Nocma over an unpaid invoice.
The development immediately raised concerns within the company, prompting Nocma management to report the matter to the police and begin efforts to recover the diverted funds.
Nocma admits control weaknesses
Nocma has acknowledged that weaknesses in its internal controls contributed to the financial exposure.
The company says the vulnerabilities emerged during the introduction of the Government-to-Government (G2G) fuel procurement model, which was implemented before all necessary operational and cybersecurity procedures had been fully established.
The admission raises questions about the effectiveness of payment verification procedures used to authorise large international transactions involving fuel suppliers and service providers.
Nocma says it has since returned to the Open Tender System (OTS) and is conducting an audit of its payment verification and financial controls.
The company is also cooperating with law enforcement agencies as investigations into the incident continue.
Police and bank investigations underway
The Malawi Police Service is investigating the circumstances surrounding the transfer, while Bank of America is involved in efforts to trace the account that received the money.
It remains unclear whether the stolen funds can be fully recovered or whether any suspects have been identified or arrested.
The incident highlights the growing cybersecurity risks facing institutions handling large public-sector financial transactions, particularly where payments depend heavily on email communication and changes to banking details.
Nocma’s loss of approximately K700 million also places renewed focus on the need for stronger verification procedures before public institutions approve changes to supplier bank accounts.
Cybersecurity experts generally recommend independent verification of any new banking instructions through previously established communication channels rather than relying solely on email correspondence.
For Nocma, the immediate priority is now to trace the missing funds, establish exactly how the fraudulent communication entered its systems and close the control gaps that allowed the transaction to proceed.
The company says its ongoing review of payment verification procedures is intended to strengthen safeguards and prevent similar incidents from occurring in the future.
The investigation remains ongoing.
Read also: MUST Ranked Best University In Malawi
Read also: HRDC Accused of Hypocrisy Over Recent Statement on National Service Challenges


[…] Related stories: Nocma Loses K700 Million in Cyber Fraud After Hackers Impersonate Mozambican Firm […]