The Corporate Affairs Commission Breach: Nigeria’s growing digital economy and rising cyber attacks.

Nigeria’s digital economy is growing rapidly, but the country’s cybersecurity systems are struggling to keep pace.

As more government services, financial systems, and public records move online, cybercriminals are increasingly targeting the infrastructure driving that transformation.

The recent breach at the Corporate Affairs Commission (CAC) is another example of how vulnerable some of the country’s most critical digital systems remain. Nigeria’s digital economy revenue is projected to reach $18.30 billion this year, according to asset managers; hence, the concerns become more significant.

The PUNCH reported in 2025 that the Managing Director and Chief Executive Officer of Arthur Stevens Asset Management Limited, Olatunde Amolegbe, who projected the digital revenue, justified this with the trajectory of the sector in recent years.

With the growth comes the risks. The Minister of Communications, Innovation and Digital Economy, Bosun Tijani, said the country is recording an average of 4,200 cyber-attacks every week.

The minister, while speaking at a summit in Abuja in April, expressed concerns that the digital space continues to draw increased attention from malicious actors. “The stronger your digital economy becomes, the more cyber-attacks you’re going to witness. We must therefore focus on building coordinated resilience rather than reacting in isolation,” Tijani said, according to a report by The Guardian.

Nigeria’s digital domain has grown significantly over the past two decades, with over 160 million internet users and about 157 million mobile lines, alongside expanding broadband and 4G coverage nationwide, the minister said.

However, experts warn that the country’s cyber defences have not evolved at the same pace.

Financial and corporate systems under pressure

The April cyberattack on the CAC, an important national infrastructure, is a high-stakes blow.

The CAC serves as the registry of Nigeria’s formal business economy. A compromise of its records raises concerns over identity theft, corporate fraud, manipulation of company information, and broader risks to investor confidence in digital public infrastructure. The data breach at the commission was reportedly orchestrated by the notorious ByteToBreach, an underground hacker group that has gradually become a household name in Nigeria and beyond.

Business Day reported that the hackers stole and leaked more than 15 million sensitive company documents from the CAC. They exported about 25 million files in total, around 750 gigabytes of data.

In a statement on April 15, 2026 on X, the CAC acknowledged what it described as a “cybersecurity incident involving unauthorised access to limited aspects of its information systems.” It said the incident promptly activated its response protocols and it was working with the National Information Technology Development Agency (NITDA) to assess the scope and impact.

The incident, deemed severe, led to the temporary suspension of company registrations by the CAC.

On April 20, the commission restored activities on the portal and introduced a Two-Factor Authentication security feature. But the attack on the CAC platform is not an isolated incident. Analysts say the significance of the attack extends beyond the commission itself.

They warn that a bigger concern is the possibility of other cyberattacks already underway, hidden from view and poised to strike another major organisation. This is not impossible given that the CAC breach is only the third large-scale strike by ByteToBreach in just a few weeks, according to reports.

In recent weeks, hackers have reportedly targeted Sterling Bank and Remita, raising concerns about the vulnerability of Nigeria’s financial and payment systems.

Sterling Bank was hit first, where the hackers claimed access to 900,000 customer accounts and 3,000 staff records, including Bank Verification Numbers (BVNs), National Identity Numbers (NINs), and passports.

Remita was struck next, with the hackers accessing three terabytes of data stored online, including 800 gigabytes of customer details, among others. The actor also claimed access to databases, logs, and source code, as well as the release of part of the data, including over 35,000 coded password versions.

Together, the incidents suggest a broader pattern, which is that cybercriminals are increasingly targeting institutions central to Nigeria’s digital economy, including payment systems, financial platforms, and business registries.

Experts warn that beyond immediate financial losses, repeated breaches could weaken public trust in digital systems at a time when the government and private sector actors are pushing deeper digital adoption across sectors.

Identity systems and threats to data sovereignty

Beyond financial infrastructure, concerns are also growing around Nigeria’s identity and data management systems. As more citizens rely on digital platforms for banking, identification, taxation, and government services, larger volumes of sensitive personal data are being stored online, increasing the possibility of potential breaches.

On May 6, 2026, NITDA raised the alarm over a new artificial intelligence-powered malware known as DeepLoad, warning that the cyber threat is actively targeting Nigerian government agencies. The agency disclosed this in a critical advisory issued through its Computer Emergency Readiness and Response Team and shared via its official X account.

In 2024, there were reports that a website, ExpressVerify, was allegedly monetising the recovery of National Identification Numbers and personal information from the database of the National Identity Management Commission (NIMC).

The website reportedly had unrestricted access to the information. According to PUNCH, the incident prompted the Nigeria Data Protection Commission to heighten scrutiny of NIMC licensees after the website reportedly breached data protection protocols.

Although the NIMC denied allegations of a breach, the report sparked concerns. The NIMC emphasised that it had not authorised any website or entity to sell or misuse the National Identification Numbers or any other identity information. The commission specifically identified several websites, including idfinder.com.ng, verify.ng, championtech.com.ng, trustyonline.com, and anyverify.com, as unauthorised data harvesters.

While there are no recent reports of a possible attack on a critical institution such as the Federal Inland Revenue Service, experts warn that such an institution, which holds important revenue data, should not let its guard down.

Concerns over elections

As Nigeria approaches the 2027 general elections, cybersecurity concerns are also extending into the country’s democracy infrastructure. With growing public demand for electronic transmission of election results and wider reliance on digital election systems, experts warn that platforms linked to the electoral process may increasingly attract cyber threats, disinformation campaigns, and attempts at manipulation.

For instance, any loss of control of the INEC Result Viewing Portal to a foreign actor poses a devastating threat to Nigeria’s digital and democratic sovereignty. Recently, there have been reports of impersonation involving the Chairman of the Independent National Electoral Commission (INEC), Professor Joash Amupitan, on X (formerly Twitter). While INEC has dissociated itself and its chairman from the X account, the impersonator has since used the account to sway opinion on social media, making posts related to elections capable of misleading unsuspecting audiences.

That is only a fragment of how digital information can be manipulated during a period as sensitive as an election year. Deloitte stated in its 2026 outlook that as Nigeria approaches the 2027 elections, government digital systems are likely to attract increased attention from cyber attackers.

“Election periods tend to heighten political and social tension, making government and public services appealing targets for disruption or interference. With more public services now being delivered digitally, the attack surface has expanded significantly.

“This risk is compounded by the continued reliance on older technologies in parts of the public sector and uneven security controls across institutions,” it said. The organisation cautioned that attackers may focus on voter records, identity databases, or other critical government systems to push their political ideologies.

“In many cases, the objective may not be a complete shutdown, but confusion, delays, or doubt around official information during a sensitive period.” It therefore emphasised that protecting critical digital infrastructure would become a matter of national priority.

“Keeping essential services running, protecting the election process, and maintaining public trust will require better cooperation and stronger, more reliable systems across government,” the firm said, stressing that the period leading up to 2027 would be a crucial test of Nigeria’s ability to protect and manage its digital systems effectively.

A governance and state-capacity problem

Nigeria has a large population estimated at over 250 million, which means it possesses an expansive database, which also faces broader implications if that data is not properly protected. Nigeria recorded 281,500 leaked accounts in the first quarter of 2026, ranking as the 34th most breached country globally.

Nairametrics, which reported this on May 7, cited a new report by cybersecurity firm Surfshark. According to the report, Nigeria has recorded 24.1 million compromised user accounts since 2004, making it the third most affected country in Sub-Saharan Africa. Even with the country’s established regulatory framework, hackers have still found ways to hit major targets. Stakeholders argue that Nigeria’s deeper challenge may be institutional rather than just technological. They believe the recurring breaches point to weaknesses in state capacity, cybersecurity governance, enforcement, and coordination across agencies.

The National Data Protection Commission (NDPC) recently blamed the shortage of qualified data protection officers, describing it as a major challenge. According to the National Commissioner of the NDPC, Vincent Olatunji, this has left many organisations without adequate capacity to safeguard sensitive information.

While speaking in an interview with the News Agency of Nigeria in Lagos on May 1, 2026, he said the Nigeria Data Protection Act mandates organisations to engage data protection officers, but there is a growing gap in this area.

“There is a significant gap between demand and supply of skilled personnel. This training is designed to prepare participants, not just for certification, but to fill that gap effectively,” he said during a data protection training session.

A cybersecurity expert familiar with the operations of the Federal Government, who preferred anonymity, identified human error in some of the breaches. He told the Guardian that the Remita breach, for instance, allegedly involved a misconfigured online storage system, which exposed roughly three terabytes of data. He said cloud misconfiguration is often the result of human error rather than sophisticated hacking.

For Allen Aliogwo, who is also a cybersecurity expert, governance failure cannot be overemphasised. He said the spate of attacks put the NDPC in the spotlight. According to him, some arms of government are showing signs of digital decay, insisting that the NDPC and other security operatives must work to close Nigeria’s porous online space. The expert worries that while the NDPC announced the launch of investigations in some cases, it could not prevent further attacks.

Aliogwo said if the think tank responsible for strategic planning cannot secure its digital correspondence, there is little hope for a commission like the CAC, for instance, which registers millions of businesses. “The CAC breach is not just about lost files; it is about digital sovereignty. A foreign (or hostile) actor now potentially possesses the blueprint of Nigeria’s formal economy,” he told the Guardian.

The expert said the “GOV_BETRAYAL” screenshot in the purported proof package of the hacking suggested that the actor felt they had exposed a state that failed to protect its citizens.

The persistence of major breaches despite existing regulations has also raised questions about enforcement and preparedness, suggesting that expanding digital services has not kept pace with security coordination.

How is the government responding?

Following the breach at the CAC, the NITDA instructed all ministries, departments, and agencies (MDAs) to adopt proactive cybersecurity measures in compliance with the National Cybersecurity Policy and Strategy (NCPS) 2021.

NITDA’s Director of Corporate Communications and Media Relations Department, Hadiza Umar, directed all MDAs to immediately review and reinforce their cybersecurity architecture to address emerging threats targeting government systems and sensitive data.

“In addition, there is a need for functional incident response frameworks, including prompt reporting of cybersecurity breaches for coordinated intervention.

“Detailed cybersecurity guidelines have already been issued to MDAs for implementation as part of ongoing efforts to strengthen resilience across public sector digital infrastructure,” the NITDA stated.

The current administration has been acknowledged by some stakeholders for its interest in securing Nigeria’s cyberspace, including developing a protection plan for Critical National Assets and Infrastructure (CNAI). They cite the Designation and Protection of Critical National Information Infrastructure (CNII) Order, 2024, signed by President Bola Tinubu, as evidence of the government’s commitment to addressing cyber threats. According to a report by The Nigerian Observer, Nigeria is also among 114 countries that have adopted national cybersecurity strategies and 118 that have established Computer Security Incident Response Teams (CSIRTs).

Experts say protecting CNII is central to national security, noting that a robust digital economy depends heavily on effective cybersecurity.

The establishment of the Nigerian Computer Emergency Response Team (ngCERT) and the National Digital Forensic Laboratory has also been commended as part of efforts to combat cybercrime. However, they still argue that stronger synergy and international collaboration are required to address the growing challenge, given the cross-border nature of cyber threats.

A cybersecurity expert, Jude Olabori, said unlocking Nigeria’s digital economic potential depends largely on cybersecurity, which itself relies on cooperation and sustained support.“Section 41(2)(b) provides for the conformity of Nigerian cybercrime and cybersecurity laws with regional and international standards. “The objective is to support and participate in international cooperation to address the menace of cybercrime,” he said.

Some stakeholders also note that the five pillars of the Ministry of Communications, Innovation, and Digital Economy’s Strategic Agenda (2023–2027) can only drive economic growth if anchored on strong cybersecurity. The pillars include knowledge, policy, infrastructure, innovation, capital, and trade. “None of these pillars can thrive in the absence of a strong and continuously evolving national cybersecurity framework,” Charles Oluma, a cybersecurity expert, said.

The challenge is no longer whether Nigeria will face more cyberattacks, but whether its institutions can build the capacity, coordination, and resilience needed to protect an economy that is becoming increasingly digital.

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *

Latest comments

    fr_FRFrench