Fourteen Days Later, Door Two: Remita On April 1, 2026, a post appeared on a cybercrime forum: roughly 3 terabytes of data from Remita, the platform that processes salaries, taxes, and payments for a large share of the Nigerian government. Remita was never actually the target of a direct attack. According to the threat actor's own account, the access came entirely through Sterling Bank — production credentials that should have lived in a secured vault were instead sitting in plaintext inside a code repository the actor had already reached through the bank's compromised network. Remita, in other words, was collateral damage from a decision Sterling Bank made about how it stored secrets.
Two Weeks After That, Door Three: The Corporate Affairs Commission On or around April 10, 2026, the same actor moved into the CAC — Nigeria's central company registry, the authoritative record of ownership, directorship, and beneficial-ownership data for every registered business in the country. This was a different kind of target. Not a bank account. Not a payment rail. The legal identity layer of Nigerian commerce itself. Around 25 million files, roughly 750 gigabytes, were allegedly exfiltrated, and the CAC had to temporarily shut down its registration portal. Three institutions. One actor. Three weeks. And a fourth data point that puts it in context: in late April, a separate actor linked to a group called Nullsec Nigeria claimed a breach of the EFCC itself — Nigeria's financial-crimes enforcement agency — allegedly exposing agent names, phone numbers, operational code names, and password hashes.
The Pattern Nobody Wants to Name Here is what should stop every technology and compliance leader in Nigeria cold: Sterling Bank said nothing to its customers. Remita said nothing to its customers. The CAC eventually issued a public statement, but in language so understated it barely described what had actually happened — despite the Nigeria Data Protection Act 2023 requiring disclosure. None of the three institutions apologised to the people whose data had been taken. This is not a story about a sophisticated adversary using zero-day exploits. It is a story about a known, patchable vulnerability that sat open for months, a set of production credentials stored where anyone with repository access could read them, and organisations that discovered they'd been breached — and chose silence over disclosure. The Nigeria Data Protection Commission opened formal investigations into all three institutions. Regulators are now examining whether the organisations had "appropriate technical and organisational measures" in place — the exact language of the 2023 Act.
Then The Wave Kept Coming This wasn't a one-off. In August, Zenith Bank confirmed that hackers had accessed customer email addresses and phone numbers, describing it as part of a broader global campaign and stressing that core banking systems remained untouched. The bank said it activated incident response immediately — a contrast worth noting against the silence of the March–April cases. The numbers around all of this are not comforting. By mid-2026, cybersecurity researchers were tracking Nigeria as the second most attacked nation in Africa, with the average organisation facing over 4,000 attempted attacks per week. The Nigeria Data Protection Commission now estimates a cyberattack occurs somewhere in the country roughly every 39 seconds. AI-driven attacks on the financial sector alone rose 150% in a single year, according to fintech compliance firm Prembly. Just two weeks ago, at the CIBN's annual banking conference in Abuja, the CBN's Director of Payments System Supervision, Dr. Rakiya Yusuf, told the room plainly that a cyber breach in a single bank, fintech, or technology vendor could now destabilise the entire interconnected financial system — and called for real-time Security Operations Centres and mandatory, faster incident disclosure across the sector.
What This Means If You Run A Business In Nigeria Your vendor's vulnerability is your vulnerability. Remita was breached without ever being directly attacked. If a partner, vendor, or upstream platform you depend on gets compromised, and your credentials or integration points touch theirs, you inherit their exposure the moment they're compromised — whether or not your own perimeter was ever tested. A disclosed CVE with a maximum severity score is not a future problem, it is an active one. The Sterling Bank breach didn't start with something exotic. It started with a publicly known flaw that had already been assigned the highest possible severity rating and simply wasn't patched. Your patch backlog is not an administrative task — it is your attack surface, dated. Secrets management is not optional infrastructure. Production credentials sitting in plaintext inside a code repository is one of the most common — and most preventable — causes of lateral breach expansion anywhere in the world. If your organisation does not have a secrets vault with access logging, that is a gap with a name. Silence is now a regulatory liability, not a PR strategy. The Nigeria Data Protection Act 2023 requires disclosure. Choosing not to notify affected customers doesn't just risk trust — under the current wave of NDPC investigations, it is itself becoming the story regulators focus on.
What Every Nigerian Should Know If you bank with, or have ever registered a business through, an institution swept up in this wave, treat your BVN, NIN, and any KYC documents you've submitted as potentially exposed, even if you haven't received a direct notification. Watch for unusual account activity, and where possible enable transaction alerts at zero threshold — the same advice that applies after any large-scale breach. If a company you've dealt with goes quiet after a reported breach, that silence is not evidence nothing happened; it is, at minimum, evidence they haven't told you yet.
What Every Compliance And Security Product Builder Must Take Away This is the part that should shape engineering decisions directly, not just policy documents. Authentication and access-control failures are the common thread, not the exception. Every institution in this chain was compromised through an access or credentials failure, not an exotic zero-day. A pilot server without proper segmentation. A production secret in a repo instead of a vault. This is precisely the layer that authentication-and-compliance tooling exists to close — and it is precisely where most Nigerian institutions are still relying on manual process rather than enforced infrastructure. Design for the possibility that your customer is also someone else's compromised vendor. If your product ingests BVNs, NINs, or KYC data from a partner institution, build for the scenario where that partner has already been breached upstream and doesn't know it yet. Continuous credential rotation and anomaly detection on inbound integration traffic should be default, not premium. Compliance frameworks and technical controls are not the same thing, and the gap between them is where breaches live. Institutions in this wave had compliance obligations under the NDPA. They did not have the technical controls to meet them. A framework document that isn't backed by enforced, monitored infrastructure is a liability disguised as a safeguard.
The Bigger Picture: Nigeria's Cybersecurity Reckoning It would be easy to read this as three unlucky institutions and move on. That would be the same mistake people made after the NIBSS glitch. Nigeria's digital economy has scaled faster than its security discipline has matured. A quadrillion-naira payment ecosystem, a national KYC infrastructure, and a company registry that underpins anti-money-laundering due diligence for the entire country are now sitting on the same foundation of unpatched servers, plaintext secrets, and delayed disclosure that a single motivated actor exploited in under a month. The government has begun responding — a new national cybercrime coordination effort has been stood up in the wake of this wave, and the CBN is now explicitly framing cybersecurity as a financial-stability issue rather than an internal IT matter. The organisations that treat authentication, access control, and continuous compliance monitoring as core infrastructure — not an annual audit exercise — are the ones that will still have customer trust the next time an actor like this finds an open door.
Three Things You Should Do This Week One: Audit your patch backlog for anything with a critical CVE score, especially on internet-facing or pilot/staging servers. If it's been open more than 30 days, that is your highest-priority ticket this week, not next sprint's. Two: Find out where your production credentials actually live. If any secret, API key, or database credential exists in plaintext inside a code repository, a config file, or a chat thread, move it to a proper secrets vault with access logging today. Three: Write down your breach disclosure trigger and timeline before you need it. Who decides when a suspected breach becomes a customer notification? How many hours does that decision take? If that process doesn't exist as a document your team can execute under pressure, it doesn't exist. If your organisation needs a real assessment of where your authentication, access control, and compliance posture actually stand — not just where your documentation says they stand — Mandleva works with Nigerian businesses at every stage. Reach us through our contact page. We would rather find the open door before someone else does.
This article discusses matters that are the subject of ongoing regulatory investigation by the Nigeria Data Protection Commission. It is analytical and educational in nature and does not seek to establish fault or prejudge any investigation's findings. All facts referenced are drawn from publicly available reporting and statements already in the public domain. This does not constitute legal advice.

