{"id":7159,"date":"2026-06-01T11:56:12","date_gmt":"2026-06-01T10:56:12","guid":{"rendered":"https:\/\/openafricantribune.com\/?p=7159"},"modified":"2026-06-01T11:56:36","modified_gmt":"2026-06-01T10:56:36","slug":"the-corporate-affairs-commission-breach-nigerias-growing-digital-economy-and-rising-cyber-attacks","status":"publish","type":"post","link":"https:\/\/openafricantribune.com\/fr\/2026\/06\/01\/the-corporate-affairs-commission-breach-nigerias-growing-digital-economy-and-rising-cyber-attacks\/","title":{"rendered":"The Corporate Affairs Commission Breach: Nigeria\u2019s growing digital economy and rising cyber attacks."},"content":{"rendered":"<p class=\"wp-block-paragraph\">Nigeria\u2019s digital economy is growing rapidly, but the country\u2019s cybersecurity systems are struggling to keep pace.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As more government services, financial systems, and public records move online, cybercriminals are increasingly targeting the infrastructure driving that transformation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The recent breach at the Corporate Affairs Commission (CAC) is another example of how vulnerable some of the country\u2019s most critical digital systems remain. Nigeria\u2019s digital economy revenue is projected to reach $18.30 billion this year, according to asset managers; hence, the concerns become more significant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The PUNCH reported in 2025 that the Managing Director and Chief Executive Officer of Arthur Stevens Asset Management Limited, Olatunde Amolegbe, who projected the digital revenue, justified this with the trajectory of the sector in recent years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the growth comes the risks. The Minister of Communications, Innovation and Digital Economy, Bosun Tijani, said the country is recording an average of 4,200 cyber-attacks every week.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The minister, while speaking at a summit in Abuja in April, expressed concerns that the digital space continues to draw increased attention from malicious actors. \u201cThe stronger your digital economy becomes, the more cyber-attacks you\u2019re going to witness. We must therefore focus on building coordinated resilience rather than reacting in isolation,\u201d Tijani said, according to a report by The Guardian.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nigeria\u2019s digital domain has grown significantly over the past two decades, with over 160 million internet users and about 157 million mobile lines, alongside expanding broadband and 4G coverage nationwide, the minister said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, experts warn that the country\u2019s cyber defences have not evolved at the same pace.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Financial and corporate systems under pressure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The April cyberattack on the CAC, an important national infrastructure, is a high-stakes blow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CAC serves as the registry of Nigeria\u2019s formal business economy. A compromise of its records raises concerns over identity theft, corporate fraud, manipulation of company information, and broader risks to investor confidence in digital public infrastructure. The data breach at the commission was reportedly orchestrated by the notorious ByteToBreach, an underground hacker group that has gradually become a household name in Nigeria and beyond.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Business Day reported that the hackers stole and leaked more than 15 million sensitive company documents from the CAC. They exported about 25 million files in total, around 750 gigabytes of data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a statement on April 15, 2026 on X, the CAC acknowledged what it described as a \u201ccybersecurity incident involving unauthorised access to limited aspects of its information systems.\u201d It said the incident promptly activated its response protocols and it was working with the National Information Technology Development Agency (NITDA) to assess the scope and impact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The incident, deemed severe, led to the temporary suspension of company registrations by the CAC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On April 20, the commission restored activities on the portal and introduced a Two-Factor Authentication security feature. But the attack on the CAC platform is not an isolated incident. Analysts say the significance of the attack extends beyond the commission itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They warn that a bigger concern is the possibility of other cyberattacks already underway, hidden from view and poised to strike another major organisation. This is not impossible given that the CAC breach is only the third large-scale strike by ByteToBreach in just a few weeks, according to reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In recent weeks, hackers have reportedly targeted Sterling Bank and Remita, raising concerns about the vulnerability of Nigeria\u2019s financial and payment systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sterling Bank was hit first, where the hackers claimed access to 900,000 customer accounts and 3,000 staff records, including Bank Verification Numbers (BVNs), National Identity Numbers (NINs), and passports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remita was struck next, with the hackers accessing three terabytes of data stored online, including 800 gigabytes of customer details, among others. The actor also claimed access to databases, logs, and source code, as well as the release of part of the data, including over 35,000 coded password versions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together, the incidents suggest a broader pattern, which is that cybercriminals are increasingly targeting institutions central to Nigeria\u2019s digital economy, including payment systems, financial platforms, and business registries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Experts warn that beyond immediate financial losses, repeated breaches could weaken public trust in digital systems at a time when the government and private sector actors are pushing deeper digital adoption across sectors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Identity systems and threats to data sovereignty<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond financial infrastructure, concerns are also growing around Nigeria\u2019s identity and data management systems. As more citizens rely on digital platforms for banking, identification, taxation, and government services, larger volumes of sensitive personal data are being stored online, increasing the possibility of potential breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On May 6, 2026, NITDA raised the alarm over a new artificial intelligence-powered malware known as DeepLoad, warning that the cyber threat is actively targeting Nigerian government agencies. The agency disclosed this in a critical advisory issued through its Computer Emergency Readiness and Response Team and shared via its official X account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2024, there were reports that a website, ExpressVerify, was allegedly monetising the recovery of National Identification Numbers and personal information from the database of the National Identity Management Commission (NIMC).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The website reportedly had unrestricted access to the information. According to PUNCH, the incident prompted the Nigeria Data Protection Commission to heighten scrutiny of NIMC licensees after the website reportedly breached data protection protocols.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although the NIMC denied allegations of a breach, the report sparked concerns. The NIMC emphasised that it had not authorised any website or entity to sell or misuse the National Identification Numbers or any other identity information. The commission specifically identified several websites, including idfinder.com.ng, verify.ng, championtech.com.ng, trustyonline.com, and anyverify.com, as unauthorised data harvesters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While there are no recent reports of a possible attack on a critical institution such as the Federal Inland Revenue Service, experts warn that such an institution, which holds important revenue data, should not let its guard down.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/openafricantribune.com\/wp-content\/uploads\/2026\/05\/The-Guardian-Nigeria-1-1024x576.webp\" alt=\"\" class=\"wp-image-7182\" srcset=\"https:\/\/openafricantribune.com\/wp-content\/uploads\/2026\/05\/The-Guardian-Nigeria-1-1024x576.webp 1024w, https:\/\/openafricantribune.com\/wp-content\/uploads\/2026\/05\/The-Guardian-Nigeria-1-300x169.webp 300w, https:\/\/openafricantribune.com\/wp-content\/uploads\/2026\/05\/The-Guardian-Nigeria-1-768x432.webp 768w, https:\/\/openafricantribune.com\/wp-content\/uploads\/2026\/05\/The-Guardian-Nigeria-1-18x10.webp 18w, https:\/\/openafricantribune.com\/wp-content\/uploads\/2026\/05\/The-Guardian-Nigeria-1.webp 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Concerns over elections<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As Nigeria approaches the 2027 general elections, cybersecurity concerns are also extending into the country\u2019s democracy infrastructure. With growing public demand for electronic transmission of election results and wider reliance on digital election systems, experts warn that platforms linked to the electoral process may increasingly attract cyber threats, disinformation campaigns, and attempts at manipulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For instance, any loss of control of the INEC Result Viewing Portal to a foreign actor poses a devastating threat to Nigeria\u2019s digital and democratic sovereignty. Recently, there have been reports of impersonation involving the Chairman of the Independent National Electoral Commission (INEC), Professor Joash Amupitan, on X (formerly Twitter). While INEC has dissociated itself and its chairman from the X account, the impersonator has since used the account to sway opinion on social media, making posts related to elections capable of misleading unsuspecting audiences.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is only a fragment of how digital information can be manipulated during a period as sensitive as an election year. Deloitte stated in its 2026 outlook that as Nigeria approaches the 2027 elections, government digital systems are likely to attract increased attention from cyber attackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cElection periods tend to heighten political and social tension, making government and public services appealing targets for disruption or interference. With more public services now being delivered digitally, the attack surface has expanded significantly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis risk is compounded by the continued reliance on older technologies in parts of the public sector and uneven security controls across institutions,\u201d it said. The organisation cautioned that attackers may focus on voter records, identity databases, or other critical government systems to push their political ideologies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIn many cases, the objective may not be a complete shutdown, but confusion, delays, or doubt around official information during a sensitive period.\u201d It therefore emphasised that protecting critical digital infrastructure would become a matter of national priority.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cKeeping essential services running, protecting the election process, and maintaining public trust will require better cooperation and stronger, more reliable systems across government,\u201d the firm said, stressing that the period leading up to 2027 would be a crucial test of Nigeria\u2019s ability to protect and manage its digital systems effectively.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A governance and state-capacity problem<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Nigeria has a large population estimated at over 250 million, which means it possesses an expansive database, which also faces broader implications if that data is not properly protected. Nigeria recorded 281,500 leaked accounts in the first quarter of 2026, ranking as the 34th most breached country globally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nairametrics, which reported this on May 7, cited a new report by cybersecurity firm Surfshark. According to the report, Nigeria has recorded 24.1 million compromised user accounts since 2004, making it the third most affected country in Sub-Saharan Africa. Even with the country\u2019s established regulatory framework, hackers have still found ways to hit major targets. Stakeholders argue that Nigeria\u2019s deeper challenge may be institutional rather than just technological. They believe the recurring breaches point to weaknesses in state capacity, cybersecurity governance, enforcement, and coordination across agencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The National Data Protection Commission (NDPC) recently blamed the shortage of qualified data protection officers, describing it as a major challenge. According to the National Commissioner of the NDPC, Vincent Olatunji, this has left many organisations without adequate capacity to safeguard sensitive information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While speaking in an interview with the News Agency of Nigeria in Lagos on May 1, 2026, he said the Nigeria Data Protection Act mandates organisations to engage data protection officers, but there is a growing gap in this area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThere is a significant gap between demand and supply of skilled personnel. This training is designed to prepare participants, not just for certification, but to fill that gap effectively,\u201d he said during a data protection training session.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A cybersecurity expert familiar with the operations of the Federal Government, who preferred anonymity, identified human error in some of the breaches. He told the Guardian that the Remita breach, for instance, allegedly involved a misconfigured online storage system, which exposed roughly three terabytes of data. He said cloud misconfiguration is often the result of human error rather than sophisticated hacking.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Allen Aliogwo, who is also a cybersecurity expert, governance failure cannot be overemphasised. He said the spate of attacks put the NDPC in the spotlight. According to him, some arms of government are showing signs of digital decay, insisting that the NDPC and other security operatives must work to close Nigeria\u2019s porous online space. The expert worries that while the NDPC announced the launch of investigations in some cases, it could not prevent further attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Aliogwo said if the think tank responsible for strategic planning cannot secure its digital correspondence, there is little hope for a commission like the CAC, for instance, which registers millions of businesses. \u201cThe CAC breach is not just about lost files; it is about digital sovereignty. A foreign (or hostile) actor now potentially possesses the blueprint of Nigeria\u2019s formal economy,\u201d he told the Guardian.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The expert said the \u201cGOV_BETRAYAL\u201d screenshot in the purported proof package of the hacking suggested that the actor felt they had exposed a state that failed to protect its citizens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The persistence of major breaches despite existing regulations has also raised questions about enforcement and preparedness, suggesting that expanding digital services has not kept pace with security coordination.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How is the government responding?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Following the breach at the CAC, the NITDA instructed all ministries, departments, and agencies (MDAs) to adopt proactive cybersecurity measures in compliance with the National Cybersecurity Policy and Strategy (NCPS) 2021.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NITDA\u2019s Director of Corporate Communications and Media Relations Department, Hadiza Umar, directed all MDAs to immediately review and reinforce their cybersecurity architecture to address emerging threats targeting government systems and sensitive data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIn addition, there is a need for functional incident response frameworks, including prompt reporting of cybersecurity breaches for coordinated intervention.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cDetailed cybersecurity guidelines have already been issued to MDAs for implementation as part of ongoing efforts to strengthen resilience across public sector digital infrastructure,\u201d the NITDA stated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The current administration has been acknowledged by some stakeholders for its interest in securing Nigeria\u2019s cyberspace, including developing a protection plan for Critical National Assets and Infrastructure (CNAI). They cite the Designation and Protection of Critical National Information Infrastructure (CNII) Order, 2024, signed by President Bola Tinubu, as evidence of the government\u2019s commitment to addressing cyber threats. According to a report by The Nigerian Observer, Nigeria is also among 114 countries that have adopted national cybersecurity strategies and 118 that have established Computer Security Incident Response Teams (CSIRTs).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Experts say protecting CNII is central to national security, noting that a robust digital economy depends heavily on effective cybersecurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The establishment of the Nigerian Computer Emergency Response Team (ngCERT) and the National Digital Forensic Laboratory has also been commended as part of efforts to combat cybercrime. However, they still argue that stronger synergy and international collaboration are required to address the growing challenge, given the cross-border nature of cyber threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A cybersecurity expert, Jude Olabori, said unlocking Nigeria\u2019s digital economic potential depends largely on cybersecurity, which itself relies on cooperation and sustained support.\u201cSection 41(2)(b) provides for the conformity of Nigerian cybercrime and cybersecurity laws with regional and international standards. \u201cThe objective is to support and participate in international cooperation to address the menace of cybercrime,\u201d he said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some stakeholders also note that the five pillars of the Ministry of Communications, Innovation, and Digital Economy\u2019s Strategic Agenda (2023\u20132027) can only drive economic growth if anchored on strong cybersecurity. The pillars include knowledge, policy, infrastructure, innovation, capital, and trade. \u201cNone of these pillars can thrive in the absence of a strong and continuously evolving national cybersecurity framework,\u201d Charles Oluma, a cybersecurity expert, said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The challenge is no longer whether Nigeria will face more cyberattacks, but whether its institutions can build the capacity, coordination, and resilience needed to protect an economy that is becoming increasingly digital.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Nigeria\u2019s digital economy is growing rapidly, but the country\u2019s cybersecurity systems are struggling to keep pace. As more government services, financial systems, and public records move online, cybercriminals are increasingly targeting the infrastructure driving that transformation. The recent breach at the Corporate Affairs Commission (CAC) is another example of how vulnerable some of the country\u2019s [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":7183,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"saved_in_kubio":false,"footnotes":""},"categories":[19,30,27,25],"tags":[],"class_list":["post-7159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-economy","category-governance","category-infrastructure","category-security"],"_links":{"self":[{"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/posts\/7159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/comments?post=7159"}],"version-history":[{"count":2,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/posts\/7159\/revisions"}],"predecessor-version":[{"id":7185,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/posts\/7159\/revisions\/7185"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/media\/7183"}],"wp:attachment":[{"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/media?parent=7159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/categories?post=7159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/openafricantribune.com\/fr\/wp-json\/wp\/v2\/tags?post=7159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}