In 2021, Chinedu was short of cash and needed money urgently. With no other options, he turned to a loan app. It asked for his personal details and permission to access his contacts. He agreed, and the money landed in his account almost immediately.
He was supposed to repay the loan within a month. But only a week later, the lender began sending messages demanding payment.
Then the lender contacted his mother.
“Madam, Chinedu is owing us ₦36,000. Tell him to come and pay unless we will delist him. He is a fraudster,” the message read.
The lender also called her. The accusation made her angry. She had heard stories of loan apps contacting borrowers’ relatives and family members, but she had not expected to receive such a message about her own son.
Chinedu’s experience illustrates how a private financial problem can quickly become a public humiliation. The app did not just demand repayment from him. By gaining access to his contacts, it acquired a way to pressure the people around him, turning a ₦36,000 debt into an accusation of fraud delivered directly to his mother.
Across Nigeria, borrowers have described similar tactics where lenders contact parents, partners, friends, employers and religious leaders, accusing borrowers of theft or fraud, and threatening to expose them if they fail to pay. The harassment is not an accidental side effect of digital lending. It is enabled by the permissions and personal information many apps collect before disbursing a loan.
By January 2026, regulators had logged thousands of complaints like these. Between March and August 2025, the Federal Competition and Consumer Protection Commission (FCCPC) recorded 1,442 fintech-related and banking complaints combined. Those cases helped recover more than ₦10 billion for affected consumers. The Nigeria Data Protection Commission (NDPC) reported more than 400 active investigations tied to digital lenders in its 2023 annual report.
Behind these numbers are lost wages, broken relationships, and ruined reputations. These harms are enabled by an economy built around inexpensive phones, no-cost apps, and global data markets that turn people’s personal information into profit, especially those least able to protect themselves or recover from the damage.
How We Established the Chain
TechCity ran controlled technical audits, archived consent screens served to Lagos and New York IPs, reviewed independent research and technical documentation on low-cost smartphones, preinstalled software, and device data collection, installed and tested loan apps, reviewed regulatory files and court rulings, and interviewed users, moderators, regulators, and diaspora remitters. All sensitive captures and documents are catalogued and protected.
The reporting below explains our procedures and evidence in full.

Two Phones, Two Rules
Open Facebook on a phone bought in Lagos and on the same app in New York. The feed looks the same. The consent path does not.
Our side‑by‑side captures for identical app builds and accounts show the difference. On New York IPs, ad personalization and off‑platform tracking toggles appear early, with clear on/off controls and plain language. On Lagos IPs, those options are more likely to be buried behind extra taps, displayed in smaller type, and defaulted to “on.” The Lagos flows required more navigation to reach a real opt‑out.
That difference is not a technical limitation. Platforms implement opt‑in flows where regulators demand them. The Irish Data Protection Commission’s 2025 enforcement and the €530 million fine against TikTok prove platforms can change behavior. In Nigeria, the FCCPC and NDPC found in July 2024 that Meta’s WhatsApp update did not secure free, informed consent; a tribunal upheld $220 million in fines in April 2025. The fine constitutes the majority of $290 million in total fines levied by three Nigerian regulators, which include the FCCPC, the Advertising Regulatory Council of Nigeria (ARCON), and the NDPC.
When Meta threatened to withdraw from Nigeria rather than comply, the FCCPC responded in a public statement that the company had faced comparable penalties in India, South Korea, France and Australia without threatening to leave any of them. The Commission wrote: “They obeyed.”
The FCCPC has stated that EU users are presented with clear opt-in and opt-out tools delivered through in-app prompts, in contrast with what Nigerian users receive. Our own consent captures show the same thing. Putting the regulator’s finding next to our technical evidence makes the finding much harder to dismiss as a testing artefact.
A Google spokesperson pointed us to Privacy Checkup, My Ad Center, and Play Store rules banning sensitive permissions for loan apps and said the company had implemented flows consistent with the NDPA. Those policies exist. Our captures show, however, that many loan apps continued to obtain broad permissions or used technical workarounds to reconstruct contact data even after policy updates.

The Phone that Ships with You
For many Nigerians, the inequality begins before any app is installed. It begins with the device.
Transsion Holdings, maker of Tecno, Infinix and itel, controls a dominant portion of African smartphone sales. For many buyers, a new Tecno Spark Base/C Series or Infinix Hot Entry/i Series costing under ₦160,000 is the first and most affordable internet device.
Independent security research has raised concerns about data collection and preinstalled software on some low-end smartphones. Lookout documented families of preinstalled packages that exfiltrate device data; Secure-D and Upstream reported Triada and xHelper malware on some low-end models that persisted through resets and attempted fraudulent subscriptions.
These findings matter because persistent identifiers, app lists, and coarse-location data can allow analytics providers to link behaviour across apps and sessions. Many preinstalled packages cannot be uninstalled through ordinary settings, leaving users with limited control over software that comes with the device.
Most users, especially older or lower‑income users, rush through setup screens and never find buried privacy controls. “I bought the phone for the boy to do school work,” said Dauda Ibrahim, 63, a market trader. “I did not know the phone itself was sending text messages to people. I feel like someone is watching my family.”
How Loan Apps Turned Contact Lists into Weapons
The loan app boom met a real need: quick credit with less bank bureaucracy. But many loan apps asked for dangerous powers at install, including access to contacts, SMS and call logs, storage, and location. Borrowers were often required to provide their Biometric Verification Number (BVN), National Identification Number (NIN), bank details, and a photograph of their face. Some apps also used inducements such as free coupons to persuade people to download them.

The loan acknowledgement letters presented to customers were not always as transparent as they appeared. Clara, a former loan app employee, said the documents were scripted and that the interest rate stated on the first page often differed from the rate on the last page. Customers who did not read the document carefully often ticked the “allow” box without understanding the permissions they were granting.
“This is real life. I was there,” Clara said. “They would call customers and say nasty words to them. We also captured their contact details.”
When borrowers missed payments, some apps used that access to send mass messages, make automated calls and publicly shame them. Clara said she witnessed one incident in which “Rest in Peace” was written across a borrower’s photograph and sent to his contacts. Employees were paid commissions based on their ability to convince borrowers to repay.
“Every time I reported to work, I felt like a liar,” she said. “I had to resign for my peace of mind. That was not life.”
The harassment described by Clara is consistent with what borrowers and their relatives have reported. Lenders have contacted family members and acquaintances, accused borrowers of fraud or theft, and falsely claimed that some borrowers had died.
We instrumented loan apps such as Easy Buy, Flash Credit, Eagle Cash, Okada Naira, and True Loan (Play Store and sideloaded APKs), and recorded permission prompts and runtime behavior. Many apps requested contact and SMS access at install and triggered outgoing messages when borrowers missed payments. Several apps used alternative permission pathways to reconstruct contact lists even after Google updated Play Store rules to prohibit direct contact access for personal loan apps.
An academic study found circumvention techniques in about 30% of loan apps approved on Google Play. After disclosure, Google removed dozens of flagged apps. But deletion is not a full fix. Many delisted apps reappeared as sideloaded APKs, rebranded under new names, or shifted distribution to channels outside Play Store oversight.
The human consequences are immediate and personal. Ngozi Okafor, 22, told TechCity an app sent messages to her entire contact list accusing her of theft. “My sister called me crying,” she said. “People were saying I had stolen. I lost a job offer because they called my employer. I had to pay to stop it.” Complaints filed with the FCCPC and NDPC contain many similar accounts.
Regulators reacted with delistings and, in July 2025, the DEON Consumer Lending Regulations, which require explicit opt‑in consent for loans, ban pre‑approved top‑ups and create penalties and executive liability. But technical enforcement is needed to counter sideloading and rebranding.

The Invisible Workforce That Trained Silicon Valley’s AI
The pipeline does not stop at device telemetry and ad targeting. It reaches into the human labor that builds AI.
AI systems need labeled and moderated data. For years, many large U.S. firms outsourced labeling and content moderation to vendors in Kenya, Uganda, and elsewhere. Sama (Samasource Impact Sourcing Inc.), headquartered in San Francisco, was a major contractor. Court filings and internal testimony show some moderators were paid low wages, with filings documenting ranges between $1.46 and $3.74 per hour in several cases, and were repeatedly exposed to violent, sexual, and other deeply distressing content without adequate psychological support. Several moderators provided medical affidavits in Kenyan court filings outlining PTSD and other trauma.
In February 2026, the Swedish newspapers Svenska Dagbladet and Göteborgs-Posten, together with Naipanoi Lepapa, a Kenyan freelance journalist, reported that footage captured by Ray‑Ban smart glasses, often filmed without the filmed person’s knowledge, had been routed into Sama’s annotation queues. In March 2026, a class action was filed against Meta and EssilorLuxottica in the Northern District of California. The case is Bartone v. Meta Platforms Inc.
Former Sama data-annotation workers said they had labeled intimate domestic moments and personal financial data. Meta canceled its multi-year training data contract with Sama, leading to over 1,100 layoffs at the Nairobi facility. The sudden job cuts came after whistleblowing and press attention, leaving many without income or ongoing support.
One moderator described waking each morning with intrusive images, describing how they spent the entire day labeling footage. Legal filings and affidavits corroborate diagnoses of PTSD in some cases. The outsourcing choices that locate the riskiest tasks in lower‑cost markets are procurement decisions taken by corporate buyers, and the human costs fall on workers with limited protections.
The Ray-Ban episode is the second time the same company has been at the centre of the same kind of harm with a different Silicon Valley client. Sama’s contract with OpenAI ended in 2022 after workers were harmed classifying child sexual abuse material.
These are procurement choices. Buyers decide where to place hazardous work. When the riskiest tasks sit in lower‑cost markets with weaker protections, the human costs concentrate on workers with the least recourse. “Laws without leadership are like medicines without a dose,” digital‑rights lawyer and Managing Partner, Spectrum Legal Services, Saidu Lawal Mohammed, told us. “If the regulator does not enforce deliberately, companies will push the limit.”

The Pipeline That Links Devices, Apps, and Brokers
These harms stack into a pipeline. Device telemetry becomes identifiers. Apps collect contact and message data. Platforms stitch behavior across sessions. Outsourced workers label sensitive footage. Data brokers buy and merge financial, social, and device signals to sell commercial segments.
Our review of independent security research and available technical documentation identified concerns about preinstalled software and data collection on some low-end devices. Consent-screen archives show weaker ad controls in Lagos. Whistleblower emails and intermediary contracts we reviewed show analytics vendors aggregating and selling derived signals to broker networks.
Using ingestion timestamps, field‑name matches, intermediary invoices and broker catalog examples, we identified ingestion patterns consistent with remittance‑derived packages reaching U.S. broker endpoints. Those matched patterns, combined with whistleblower invoices and intermediary logs, provide strong technical and circumstantial evidence that remittance‑adjacent signals were prepared and delivered in forms ingestible by broker catalogs, though the full contractual chains remain partially redacted.
In plain terms, our data show that packages with remittance and device fields were prepared and transmitted in ways brokers accept. Whether specific commercial contracts authorized each transfer can be established only by production of internal contracts or audit logs we could not obtain.
Remittances channel large, steady flows of money and data. Nigeria received more than $20 billion in remittances in 2024; 2026 projections put the figure closer to $26 billion. Every transfer produces records such as sender identity, recipient, amount, device, and frequency. Remittance apps commonly ask for identity verification, anchoring transactions to real people.
In the United States, financial data benefits from some protections, but these do not uniformly block remittance platforms from sharing derived or aggregated behavioral signals with partners. Data brokers can license or buy commercial signals, including behavioral indicators tied to purchasing and remittance patterns. When those signals are combined with social and location data, they produce profiles of diaspora households living in Atlanta, Houston, and New York. These profiles can be sold to advertisers, lenders, or political campaigns.
Diaspora remitters described the same sense of violation. “I send $200 every month for my mother’s healthcare. Then I started getting ads about funeral plans and high‑interest loans aimed at migrants. It felt like someone sold my pattern,” said Michael Ayodeji, a remitter in Atlanta. “I never signed up for my life to be used as a marketing list,” Elizabeth Nnaji in New York said.

Jurisdictional Patchwork and Regulatory Limits
Regulation matters, and it changes behaviour where it is enforced. The Nigeria Data Protection Act, 2023 (NDPA) established the NDPC and set data‑protection rights. The FCCPC used its consumer authority to push the removal of abusive apps and later implemented DEON in 2025 to regulate digital lenders. The tribunal ruling that upheld the FCCPC’s fine against Meta in April 2025 showed that national regulators can wield power.
But enforcement is fragmented. The UK ICO told us its remit covers UK data subjects and that searching global complaints for cross‑border differential treatment would often exceed FOIA cost limits and involve third‑party personal data. NITDA told us the NDPA governs processing but does not automatically give journalists access to internal records. We asked Meta, TikTok, Sama, Transsion, and loan apps for comment by email and certified letter between July 9 and July 22, 2026. Google replied by providing background materials, outlining global privacy tools and Play Store rules. Most others did not answer by our deadline.
The U.S. Federal Trade Commission has told us it cannot meet the 20‑business‑day FOIA deadline because the request requires searches of field offices. The FTC says it is still processing the request and will contact us if narrowing the scope becomes necessary.
Non‑response is itself informative. Corporations point to policies and public resources; regulators point to remit and resourcing limits. But the audit trails, including consent logs, remediation records, contract redactions and ingestion receipts, that would bridge technical captures to corporate decisions remained largely unavailable without regulatory compulsion or legal process.
In September 2025, Kenya’s Court of Appeal ruled that Meta can be sued in Kenyan courts, rejecting the argument that claims belonged in US courts. This ruling is a counterexample of a national court in an African jurisdiction asserting authority over a US platform and winning.

What Must Change
This is not an argument to shut down global technology or to block cross‑border commerce. It is an argument for consistent standards and enforceable accountability.
Platforms must deploy the same default consent standards globally. App stores must hold developers to consistent rules and actively block apps that facilitate harassment. Device makers must disclose pre‑installed telemetry and provide easy, meaningful opt‑out or removal for non‑essential packages. Companies outsourcing AI work must provide fair pay and psychological support equivalent to what on‑site staff receive. Remittance platforms must treat transaction histories as sensitive and require clear, informed consent for secondary uses. And countries with market power should set baseline privacy laws that limit regulatory arbitrage.
Responses, Non‑Responses, and Accountability
Google supplied background materials about Play Store rules and account controls. The ICO and NITDA explained remit and FOI limits. Meta, TikTok, Sama, Transsion, and loan apps did not provide on‑record responses by our deadline.
Those responses are part of the story. Where companies supply detailed audit trails and remediation logs, claims can be tested. Where firms decline to provide records, independent audits and regulator action become more important.
The Evidence and How We Found It
We followed this story from the moment someone taps “allow” to the places that profit from that tap, using tests, captures, documents, and interviews so each claim rests on linked evidence.
We began by recreating signup and ad‑consent flows for identical app builds from two places: Lagos and New York. Using controlled accounts and local IP addresses, we stepped through every screen, took time‑stamped screenshots, and saved the interaction sequences. Those side‑by‑side captures are the primary record of how the same app offers different choices depending on where a user sits.
We then examined publicly available research and technical documentation concerning low-cost smartphones, preinstalled software, and device-data collection. These materials provided the basis for our discussion of device telemetry and the privacy risks associated with software that users may be unable to remove or easily control.
Next, we ran the apps themselves. We installed multiple loan apps from Google Play and as sideloaded APKs, logged every permission dialog, traced API calls, and recorded runtime events. When apps rebuilt contact relationships without an explicit contact permission, we documented the exact file‑access and API methods used, such as call‑log parsing, SMS‑thread reconstruction, or other techniques, and captured outgoing message events that matched harassment patterns in complaints.
Finally, we looked beyond the phone. Whistleblower invoices, intermediary delivery logs and broker catalog excerpts showed how remittance‑adjacent signals are packaged and offered to buyers. By matching ingestion timestamps, field names and delivery patterns in those broker samples to our own captures and intermediary logs, we found consistent evidence that transaction and device signals were assembled into broker‑ready packages.
We paired that machine work with human testimony. In total, we conducted 31 interviews, consisting of 22 Nigerian users (ages 22–65, including six elders), eight diaspora households, and one former moderator. We corroborated their accounts against the technical traces and regulator filings we reviewed.
A note of caution must sit beside these results. The matched technical and documentary evidence is strong and consistent, but it does not by itself prove that every observed transfer was authorized by a specific contractual clause. Some internal contracts, audit logs, and ingestion receipts remain redacted or unavailable; establishing contractual authorization for particular transfers would require their production.
We have filed a FOIA request with the U.S. Federal Trade Commission seeking related records; the agency has informed us it needs additional time to search field records and is processing the request. We also asked Mercy Mutemi, counsel for former Sama moderators in Nairobi, to comment on the Sama case and to provide documentary material. She did not respond before publication, and her absence is noted as a limitation in obtaining additional contextual documents.
A Human Ledger
Consent records, network captures, complaint files, and tribunal decisions all provide important evidence. But so do the personal accounts: a son humiliated in public, a market trader whose family’s privacy was exposed, a moderator haunted by the work, and a diaspora sender who feels betrayed. Taken together, they show that the system turning inexpensive phones, “free” apps, and outsourced labor into tools for extracting value from vulnerable people is not unavoidable. It is the result of corporate, regulatory, and political choices, and those choices can be changed.
If you were publicly shamed by a loan app, worked as an AI labeler or moderator, or have documents showing how remittance or device telemetry reaches brokers, contact TechCity at info@techcityng.com. We will protect your confidentiality.
Reporting for this story was supported by the Fund for Investigative Journalism.