Over three weeks this spring, a single hacking group worked its way through three of Nigeria’s most sensitive digital systems: a major commercial bank, the payment platform millions of Nigerians rely on for salaries and government transfers, and the national registry that holds records for every company in the country. The Nigeria Data Protection Commission (NDPC) is now investigating all three. The episode has become an unusually direct test of what Nigeria’s five-year-old data protection regime can actually do when the breach isn’t hypothetical.
Three Weeks, Three Breaches
The campaign, attributed to a ransomware group calling itself ByteToBreach, started with Sterling Bank on March 27, when attackers reportedly exploited an unpatched, internet-facing server to expose roughly 900,000 customer accounts and internal records — a lapse that sits squarely inside what the Central Bank of Nigeria’s own cybersecurity framework requires banks to prevent. Four days later, the same group claimed to have pulled close to 3TB of data from Remita, the payments platform that processes salaries and remittances for a large share of Nigeria’s public and private workforce, including roughly 800GB of KYC documentation.
The most damaging hit came next. On April 15, the Corporate Affairs Commission (CAC) confirmed unauthorised access to parts of its information systems and shut down its company registration portal to contain the damage. ByteToBreach claimed to have exfiltrated around 25 million files — roughly 750GB of data, including more than 15 million company documents — and published proof online: a sequence of screenshots walking through the entire intrusion, one of them captioned “GOV_BETRAYAL.” Reports at the time put the group’s ransom demand at €250,000.
Why This Touches Nearly Everyone
The three targets weren’t random. CAC is the primary agency through which every company, business name, and NGO in Nigeria gets registered — its database is effectively a record of the country’s formal economy. Remita sits underneath government payroll and a large share of private-sector salary processing. Sterling Bank is a top-tier retail lender with millions of ordinary customers. Between the three, it’s difficult to find a working Nigerian adult who hasn’t had some piece of personal or business data pass through at least one of these systems in the past few years.
What NDPC Is Actually Doing
The NDPC opened formal investigations into all three incidents under Section 46(3) of the Nigeria Data Protection Act, 2023, starting with Sterling Bank and Remita in early April and extending to CAC once its breach was confirmed. The CAC probe alone was scoped to examine access-control mechanisms, data privacy impact assessments, vulnerability and penetration testing, and due diligence over CAC’s third-party data processors — in other words, not just what went wrong technically, but whether the institution had done the basic governance work it was legally required to do beforehand. The Commission has publicly maintained that Nigeria’s broader data protection framework remains fundamentally sound, even as it investigates three of the year’s most serious breaches at once.
The Bigger Number Behind the Headlines
This breach wave landed in the middle of what the NDPC itself describes as a shift into “full enforcement mode.” By early 2026, the Commission had collected an estimated ₦7.2 billion from company registrations, compliance fees, and fines, closed more than 240 breach investigations, and taken 11 major enforcement actions since the law came into force. Fines for non-compliance can now reach ₦10 million or 2% of a company’s annual gross revenue, whichever is higher. Notably, the NDPC has generally avoided publicly naming the organisations behind those 11 enforcement actions — a deliberate choice, by most accounts, meant to encourage voluntary compliance rather than shame violators into silence.
The Uncomfortable Question
That last point cuts both ways. An investigation is not the same thing as accountability, and Nigeria has been here before — a near-identical pattern of breach, investigation, and quiet resolution played out with the National Identity Management Commission’s own data exposure before enforcement action was ever seriously considered. Sterling Bank’s alleged failure to patch a public-facing server is also a reminder that some of these gaps predate NDPC’s involvement entirely; that specific obligation sits with the Central Bank’s own cybersecurity rules, which apparently went unmet long before any data regulator got involved. Nigeria’s data protection law is, on paper, comprehensive. Whether the institutions actually bound by it have the technical capacity and internal discipline to comply is a separate question — and this spring suggested the answer, at three very different types of organisations, was no.
Why It Matters Beyond This Wave
The CAC breach didn’t happen in isolation. Nigerian organisations face an estimated 4,700 cyberattacks a week, and Deloitte’s most recent Nigeria Cyber Security Outlook put cumulative losses to cybercrime at more than $3 billion between 2019 and 2025. ByteToBreach itself isn’t a Nigeria-specific problem either — the same group has claimed attacks on government systems as far away as Sweden. What makes the CAC incident particularly uncomfortable is timing: Nigeria is heading into general elections in 2027, and security researchers have already started asking whether systems like INEC’s IReV result-viewing portal or its BVAS voter-accreditation devices could be the next target in a similar campaign. A breach of election infrastructure would raise the stakes from inconvenient to existential for public trust in the vote itself.
What to Watch
None of this means Nigeria’s data protection regime is failing outright — a functioning regulator investigating breaches at a bank, a payments platform, and a government agency within days of each disclosure is, in itself, more institutional response than many peer markets manage. But the real test isn’t the investigation opening; it’s what comes out the other end; whether CAC, Remita, and Sterling Bank face consequences proportionate to what was lost, and whether the next unpatched server gets fixed before someone finds it instead of after.