Nigeria is strengthening its cybersecurity posture as cybercrime becomes more profitable even while reported fraud cases decline. Authorities are preparing a new national cybersecurity framework expected to mandate incident reporting, set minimum cybersecurity investment requirements, and expand public-private collaboration. The push comes as organizations in Nigeria faced an average of 4,361 attempted cyberattacks per week in June 2026, making the country one of Africa’s most targeted environments and often exposing victims to threat levels roughly double the global average.
Financial losses have risen sharply, with digital-payment fraud reaching ₦25.85 billion in 2025, driven in part by insider-enabled schemes including SIM swap fraud, account compromise, and phishing. Nigeria already requires breach notification within 72 hours under its 2023 Data Protection Act, but enforcement and compliance remain uneven, especially among smaller organizations with limited training and security resources. Officials and industry observers say stronger enforcement, better reporting, and improved defenses against credential theft are critical to reducing cybercriminal profits in the country’s expanding digital economy.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Nigerian authorities are developing a new cybersecurity framework intended to mandate incident reporting, set minimum cybersecurity investment levels, and expand public-private collaboration. The move is presented as part of a broader effort to strengthen the country's cybersecurity posture as cybercrime losses rise.
Organizations in Nigeria experienced an average of 4,361 attempted cyberattacks per week in June 2026, according to Check Point Software. The references say this made Nigeria the second most targeted country in Africa, with threat levels often about twice the global average.
Nigeria recorded ₦25.85 billion in digital-payment fraud losses in 2025, despite a decline in the total number of reported fraud incidents. The reporting attributes much of the impact to insider involvement, SIM swap fraud, account compromise, and phishing.
Nigeria's 2023 Data Protection Act established a requirement for breach notification within 72 hours. The references note that enforcement capacity and business compliance have remained weak.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.