Between 2023 and 2026, Nigeria has witnessed a surge in high‑profile data breaches affecting fintechs, banks, government agencies, and digital lenders. These incidents highlight systemic weaknesses in security controls, insider access, and regulatory compliance under the Nigeria Data Protection Act (NDPA).
Flutterwave experienced unauthorized transactions amounting to billions of naira. Investigations revealed weak segregation of duties and poor transaction monitoring, with insider exploitation playing a major role.
Insider misuse of privileged accounts led to exposure of customer data. This case underscored the importance of monitoring internal access and implementing zero‑trust security frameworks.
Sterling Bank faced two major breaches: one through vendor risk in 2025, and another ransomware attack in 2026 that compromised nearly 900,000 customer records and 3,000 employee files. Attackers demanded a ransom of €250,000.
The National Identity Management Commission suffered exposure of National Identity Numbers (NINs) due to unsecured API authentication, raising national security concerns.
A digital lending platform collected excessive borrower data beyond lawful purposes, violating NDPA principles of data minimisation and purpose limitation.
A coordinated breach across government agencies and payment platforms exposed over 3 terabytes of national payment data. The incident highlighted systemic supply‑chain vulnerabilities and the urgent need for stronger inter‑agency security protocols.
Data breaches in Nigeria are no longer isolated events — they are systemic, frequent, and costly. The NDPA 2023 has made compliance mandatory, and organizations that fail to secure data face financial penalties, reputational damage, and legal consequences. For Nigerian businesses, data protection is now a core operational requirement, not optional.
