Connect with us

News

NDPC probes cybersecurity breach of Nigeria’s corporate database at CAC – Technology Times

info

Published

on

1776508670 admin ajax.png

Nigeria’s data protection regulator says it has launched an investigation into a suspected compromise of the country’s corporate registry systems, raising fresh concerns about the resilience of critical digital infrastructure underpinning business operations.

The Nigeria Data Protection Commission says it is probing an alleged data breach at the Corporate Affairs Commission, signalling what could be one of the most consequential cybersecurity incidents affecting Nigeria’s corporate database ecosystem.

In a statement issued on April 17, 2026, Babatunde Bamigboye, Head, Legal, Enforcement & Regulations at NDPC confirms that the agency has “initiated an investigation into the reported data breach at the Corporate Affairs Commission (CAC)” pursuant to Section 46(3) of the Nigeria Data Protection Act, 2023.

The data protection regulator says the probe is part of broader efforts to maintain confidence in Nigeria’s digital economy, stating that the investigation “underscores the importance of fostering trust in Nigeria’s economic environment.”

ndpc-probes-cybersecurity-breach-at-cacndpc-probes-cybersecurity-breach-at-cac
Dr Vincent Olatunji, National Commissioner/CEO, NDPC. Image credit: NDPC.

The Nigeria Data Protection Commission says it is probing an alleged data breach at the Corporate Affairs Commission, signalling what could be one of the most consequential cybersecurity incidents affecting Nigeria’s corporate database ecosystem.

NDPC flags sophisticated cyber threats

The Commission’s disclosure points to increasingly advanced cyber threats targeting national data systems, with the regulator warning that malicious actors are deploying complex methods to breach sensitive infrastructure.

According to the NDPC, “threat actors in the digital space have devised malicious methods of compromising the data security architecture of key databases,” adding that such attacks now involve “large-scale data exfiltration and cross-platform compromise across interconnected systems.”

This suggests that the alleged breach at CAC may not be an isolated incident but part of a broader pattern of coordinated cyber operations targeting critical data repositories across Nigeria.

The Commission stops short of detailing the scale or impact of the breach at CAC but indicates that the investigation will be comprehensive and technically rigorous.

The NDPC outlines a multi-layered investigative approach that will scrutinise key components of CAC’s data protection architecture.

It says the investigation will “cover the procedures and outcomes of Access Control Mechanisms, Data Privacy Impact Assessments, Vulnerability Assessment and Penetration Testing (VAPT), as well as due diligence on third-party data processors.”

This scope reflects a deep-dive into both internal controls and external dependencies, particularly the role of third-party processors, which are often a weak link in complex data ecosystems.

The Commission also signals that enforcement and remediation will be coordinated across institutions, noting that the National Commissioner/CEO, Vincent Olatunji, has “directed the Commission’s technical team to immediately interface with relevant authorities and pivotal organisations, with a view to reinforcing existing guardrails for the processing of personal data.”

Despite the seriousness of the probe, the NDPC seeks to reassure the public about the overall integrity of Nigeria’s data protection framework.

“The NDPC assures members of the general public that frameworks for data protection, in terms of technology and other requisite resources in Nigeria, remain fundamentally strong,” the Commission says.

It adds that this strength is “evident in the increasing rate of access to data-driven services,” suggesting that digital adoption trends remain robust despite emerging risks.

The regulator sees its intervention as part of ongoing efforts to sustain trust and investment, stating that its actions are “necessary regulatory actions geared towards sustaining public trust in these services and bolstering continuous investment in Nigeria’s digital economy.”

ndpc-probes-cybersecurity-breach-at-cacndpc-probes-cybersecurity-breach-at-cac
Hussaini Magaji, Registrar-General, CAC. Image credit: CAC.

NDPC advisory highlights escalating national risk

The CAC investigation follows closely on the heels of a broader regulatory advisory issued by the NDPC on Thursday, warning of escalating threats to Nigeria’s data security architecture.

In that advisory, the Commission states that its “technical assessment indicates that some shadowy threat actors have engaged in coordinated operations targeting financial systems and some key digital infrastructure in Nigeria.”

The language underscores a systemic risk environment in which multiple sectors, including financial services and government databases, are increasingly exposed to sophisticated cyber threats.

The NDPC highlights the advisory as a directive to all data controllers and processors, stating that it is issued “in response to the escalating threat to data security infrastructure.”

Presidential directive reinforces data protection urgency

The Commission anchors its advisory in national policy, referencing a directive by President Bola Ahmed Tinubu that elevates data governance as a strategic priority.

Quoting the President, the NDPC recalls the declaration that “Data is the new oil, its value increases the more it is refined and responsibly shared.”

The directive further mandates public sector compliance, with the President stating: “I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act 2023.”

This policy framing reinforces the significance of the CAC probe, positioning it within a broader national agenda to secure data as a critical economic asset.

In response to the heightened threat landscape, the NDPC is calling for immediate action across both public and private sector organisations.

The Commission “strongly advises that data controllers and processors (including MDAs) are to urgently step-up their technical and organisational measures to ensure the privacy of all Nigerians and other data subjects in line with the Nigeria Protection Act, 2023 (NDP Act).”

This directive signals a shift from advisory to expectation, with regulators emphasising proactive compliance rather than reactive remediation.

ndpc-probes-cybersecurity-breach-at-cacndpc-probes-cybersecurity-breach-at-cac
President Ahmed Tinubu. Image credit: State House.

The directive further mandates public sector compliance, with the President stating: “I therefore direct all Ministries, Extra-Ministerial Departments and Agencies to capture information rigorously and safeguard it under the Nigeria Data Protection Act 2023.”

Detailed compliance measures outlined

The NDPC provides an extensive checklist of measures that organisations are expected to implement to strengthen their data protection posture.

These include the “appointment of duly trained and certified Data Protection Officers” and the “development and effectual implementation of Privacy Policies and information security standards.”

Organisations are also required to undertake “Data Privacy Impact Assessments” and deploy “robust identity and access controls, including Multi-Factor Authentication (MFA).”

The Commission further emphasises modern security architectures, calling for the “implementation of zero-trust security architecture and network segmentation,” alongside “immediate remediation of identified system vulnerabilities and continuous patch management.”

Additional measures focus on securing digital infrastructure, including “cloud infrastructure, APIs, databases, and access credentials,” as well as implementing “real-time monitoring, logging, and threat detection mechanisms.”

The advisory also highlights the importance of cryptographic controls, recommending the “implementation of encryption, key management, and secure credential handling.”

To ensure system resilience, organisations are instructed to conduct “Vulnerability Assessment and Penetration Testing (VAPT) on critical systems” and maintain “regular backup, recovery, and resilience testing.”

The NDPC makes clear that compliance is not optional, warning that failure to implement required measures could attract legal consequences.

“Organisations that fail or neglect to implement appropriate measures as required under the Nigeria Data Protection Act, 2023 may incur legal liabilities,” the Commission states.

At the same time, it offers support for compliance efforts, noting that it “is prepared to provide requisite regulatory support to organisations in order to ensure adequate level of data privacy and protection.”

The regulator reiterates its institutional mandate, stating that it “remains committed to protecting personal data, strengthening institutional resilience, and ensuring compliance across all sectors.”

CAC breach probe signals broader systemic implications

The convergence of the CAC investigation and the national advisory highlights a critical moment for Nigeria’s digital governance framework.

The alleged breach at the Corporate Affairs Commission is significant not only because of the volume and sensitivity of corporate data involved, but also because of its central role in Nigeria’s business ecosystem.

As the official repository of company registrations and corporate records, CAC’s database underpins business identity, compliance, and transactional trust across sectors.

A compromise of such infrastructure, if confirmed, could have ripple effects across:

* corporate governance systems

* financial services verification processes

* investor confidence

* regulatory compliance frameworks

ndpc-probes-cybersecurity-breach-at-cacndpc-probes-cybersecurity-breach-at-cac
Nigeria’s data protection regulator is investigating an alleged breach at CAC while warning of rising cyber threats targeting critical databases and infrastructure. Image credit: Image FX.

“Organisations that fail or neglect to implement appropriate measures as required under the Nigeria Data Protection Act, 2023 may incur legal liabilities,” the Commission states.

Data-driven economy faces trust test

The NDPC’s actions suggest that Nigeria’s transition to a data-driven economy is entering a phase where security and trust are becoming as critical as access and innovation.

While the Commission maintains that existing frameworks are “fundamentally strong,” the dual issuance of a breach investigation and a national advisory indicates that regulators are responding to heightened threat intensity and systemic exposure.

The CAC probe, therefore, is more than an isolated enforcement action, it is a stress test of Nigeria’s data protection architecture.

With the investigation underway, stakeholders across government and industry are likely to face increased scrutiny regarding their data governance practices.

The NDPC’s emphasis on areas such as:

* access control mechanisms

* third-party processor due diligence

* vulnerability testing

signals where regulatory focus will be concentrated in the coming months.

Organisations operating critical data systems may need to reassess their compliance posture in light of the Commission’s detailed advisory and enforcement stance.

Stay ahead with real-time reports, breaking news, and exclusive insights delivered directly to your phone. Don’t settle for outdated information. Join TECHNOLOGYTIMES NEWS on WhatsApp for 24/7 updates.

Join Our Whatsapp Channel

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

SSA Adeboye’s Media Aide Jide-Ojo Joins African Leaders for Sport Business Summit in Nairobi

info

Published

on

IMG 20261002 WA0027.jpg

Jide-Ojo Jide Olusola, SA Media to the Senior Special Assistant to the President on Grassroots Sports Development, Hon. Adeboye Anthony Adeyinka, has been named among the speakers for the Year of Return Africa (YORA) Summit & Expo 2026 holding in Nairobi, Kenya.

Jide-Ojo, Founder/CEO of 247SportsNetwork Limited, publishers of Sports247.ng, will join leading African business executives, investors, innovators and industry stakeholders at the summit scheduled for October 13–14 at Broadwalk Mall, Westlands, Nairobi.

The veteran media executive, who has accumulated over 30 years of experience in the media industry, will participate in the summit’s sport business segment on October 14, bringing perspectives from sports journalism, grassroots development, strategic communications, partnerships and the commercialisation of African sport.

Jide-Ojo joins a diverse speakers’ lineup that includes Blue Mahoe Capital Chairman and CEO David Mullings, Kenya Film Commission Board Chairman Sudi Wandabusi, Capital Markets Authority Blockchain and Fintech Analyst James Hillary Obonyo, Emmppek Group Chairman Emmanuel Audu-Ohwavborua, and B|E Strategy Founder and Chief Strategist Charles Ellison, among others.

The summit, themed “Fueling the Future: Unlocking Africa’s Entrepreneurial Potential,” will examine investment, innovation, technology, entrepreneurship and opportunities within Africa’s creative economy.

A major focus of the sport business conversation will be the monetisation of Africa’s sports, media and entertainment industry, including how the continent can transform its enormous sporting talent, passionate audiences and compelling stories into sustainable commercial opportunities.

Through Sports247 and his current media role supporting the Presidency’s grassroots sports development agenda, Jide-Ojo has consistently promoted emerging athletes, grassroots competitions and initiatives aimed at creating greater visibility and opportunities within Nigeria’s sports ecosystem.

His contribution in Nairobi is expected to highlight the increasingly important role of media, digital storytelling, athlete branding, sponsorship and strategic partnerships in building commercially sustainable African sports properties.

The Nairobi platform will also provide an opportunity to share Nigeria’s grassroots sports experience while strengthening connections between sport, media, investment and business across Africa.

Following the Nairobi programme, YORA activities will continue in Kilifi, Kenya, from October 16–17.

YORA Summit & EXPO Kenya, 2026 is a three-day event including YORA Awards taking place from  12th – 17th Nairobi | Kilifi, Kenya

Continue Reading

Business

NAIPE 11th Annual Conference Moves to 12 Noon as 28 Stakeholders Back Event

info

Published

on

About 28 insurance and pension regulators and operators have backed the upcoming 11th edition of the Nigerian Association of Insurance and Pension Editors (NAIPE) Annual Conference, scheduled to hold in Lagos.

This is even as the timing of the event scheduled to hold on Thursday, October 8, 2026, at Oriental Hotel, Victoria Island, Lagos, has been shifted from 9:00am to 12:00pm same day.

This is to allow Insurance operators, who will be attending Insurers Committee meeting earlier that day, conclude their meeting and attend the conference.

The national conference with a focus on the emerging market dynamics in Nigeria’s insurance and pension sectors, follows  the just concluded recapitalisation exercise in the insurance sector and ongoing exercise in the pension industry.

Themed: “Post-Recapitalisation and Market Dynamics in Insurance & Pension Sectors,” the Chief Executive Officer of United Capital Asset Management Limited, Dr. Odiri Oginni, will deliver the keynote address, focusing on the insurance  perspective while Mr. Oguche Aguda,
Founder and Managing Partner of HRISP Partners, will equally deliver a paper on the theme, focusing on the pension perspective.

The Group Managing Director of Custodian Investment Plc, Mr. Wole Oshin, will chair the event.

According to NAIPE, the conference is coming at a critical period for the two sectors, as insurance operators have just concluded their recapitalisation exercise, while pension operators are expected to conclude theirs in 2027.

The high level discourse will therefore examine how funds raised through recapitalisation can be strategically invested and deployed to generate stronger returns, deepen market confidence and improve service delivery to shareholders and policyholders.

Expected dignitaries include the Commissioner for Insurance & Chief Executive Officer of the National Insurance Commission (NAICOM), Mr. Olusegun Omosehin; Director-General of the National Pension Commission (PenCom), Ms. Omolola Oloworaran; chief executives of insurance companies, broking firms, investment and securities companies and Pension Fund Administrators (PFAs), as well as regulators, labour unions, students and other stakeholders.

Speaking ahead of the conference, Chairperson of NAIPE, Mrs. Ebere Nwoji said, the annual gathering provides a platform for insurance and pension journalists to contribute to the development of both sectors by promoting greater public understanding of insurance and pension as instruments for financial security and protection against old-age poverty.

Nwoji expressed appreciation to operators and regulators in the two sectors for their continued support for the conference, stressing that, the benefits derived from the annual event outweigh the resources committed to organising it.

She described this year’s theme as timely, given the significant structural changes taking place in the insurance and pension industries through recapitalisation.

She noted that, the insurance industry concluded its recapitalisation exercise on July 31, 2026, while the pension industry is currently undergoing a similar process expected to be completed next year.

The NAIPE chairperson, particularly, commended the leadership of NAICOM for successfully concluding the insurance industry’s recapitalisation exercise, describing it as a major achievement for Omosehin.

According to her, the Commissioner ‘took the bull by the horns’ in breaking what she described as the longstanding cycle of inconclusive recapitalisation exercises in the insurance industry.

She also expressed optimism that the pension industry, under the leadership of Ms. Omolola Oloworaran, would achieve a seamless and successful recapitalisation exercise.

“The conference would provide operators with an opportunity to gain insights into prudent and judicious investment of the capital raised through the recapitalisation process.

“I am confident that speakers at the event would provide practical perspectives on how insurance and pension operators can deploy their strengthened capital bases to deliver superior investment returns while enhancing value for investors, shareholders and policyholders” she affirmed.

Meanwhile, NAICOM, PenCom, SanlamAllianz, Veritas Kapital and 24 others have offered their support and partnership towards the conference.

The post NAIPE 11th Annual Conference Moves to 12 Noon as 28 Stakeholders Back Event appeared first on Business Today NG.

Continue Reading

Trending