02 Oct Nigeria faces increasing cyber crimes, highlighted by Cyfirma Research
According to Cyfirma Research, Nigeria has seen a significant rise in data breaches and cybercrime from January to September 2025, affecting sectors such as banking, telecom, government, healthcare, and critical infrastructure.
A new report by the company, titled ‘Cyber Threat Assessment- Nigeria’, showed that the dark web revealed the sale of stolen banking databases and credentials, including a ransomware attack on Princeps Credit Systems Limited by the group Killsec, which impacted over 70,000 clients. It went on to reveal that illicit trade involved over 60 million records linked to Nigerian telecoms and 130,000 healthcare records, sparking major privacy concerns.
Among the notable incidents was an advertisement in March for Nigerian user data from a Russian forum, and in May, leaked credentials from Nigeria’s NASIMS portal. In June, a listing for access to the Institute of Bankers of Nigeria’s website was offered for USD$2,500, and by July, a partial database of the Chartered Institute of Bankers was leaked.
Allegations also surfaced regarding telecom data breaches, with one dark web user claiming to sell a database of 60 million Nigerian records. Additionally, government entities were targeted, with the Lower Niger River Basin Development Authority suffering a breach that led to significant data leaks. The pro-Yemeni hacker group Yemen Cyber Army also claimed responsibility for compromising several Nigerian government ministry domains.
In healthcare, a dark web user posted a dataset containing approximately 130,000 patient records from Nigerian healthcare facilities, raising alarms about the exposure of sensitive information. Overall, the incidents highlighted a troubling trend of cyber threats in Nigeria.
Cyfirma Research suggests that in light of these issues, it is crucial to strengthen regulatory oversight by enforcing stricter compliance for banks, telecoms, and government agencies regarding data protection.
It also recommends establishing cross-sector intelligence sharing to enable faster detection and response to leaks, ransomware, and credential sales.
Among the other suggestions, researchers say implementing multi-factor authentication (MFA) across financial and government portals can reduce account takeover risks and regular security audits through vulnerability assessments, as well as developing sector-specific Computer Emergency Response Teams (CERTs) to improve incident response capabilities.
Sorry, the comment form is closed at this time.