The Nigerian Computer Emergency Response Team (ngCERT) has issued a cybersecurity advisory warning Nigerians and organisations across the country about the rising threat posed by stolen email passwords and login credentials.
Compromised accounts are increasingly being used to enable cybercrime, identity theft, financial fraud and other online attacks, the nation’s internet watchdog said.
The agency raised concerns over the large volume of email credentials exposed through data breaches and subsequently traded on dark web marketplaces and underground forums, where cybercriminals purchase them for malicious use.
According to ngCERT, billions of compromised email credentials are currently circulating online, making email accounts one of the most attractive targets for cyber attackers globally.
“Organisations and individuals are strongly advised to treat email security as a priority and take immediate steps to safeguard their accounts,” ngCERT said.
ngCERT warns Nigerians about rising theft of email credentials used for cybercrime, fraud and phishing, urging stronger password and MFA protection. Image credit: image FX.
“Organisations and individuals are strongly advised to treat email security as a priority and take immediate steps to safeguard their accounts,” ngCERT said.
Credential theft and automated attacks on the rise, ngCERT says
The advisory explained that cybercriminals routinely harvest usernames, passwords and personal information leaked during data breaches, before selling the data in bulk to other attackers.
These attackers then deploy automated tools to test stolen credentials across multiple online platforms in a technique known as credential stuffing.
Because many users reuse the same passwords across different services, attackers are often able to gain access to multiple accounts using a single set of compromised login details.
ngCERT noted that once email accounts are breached, attackers can access sensitive communications, financial records, personal data and password reset links linked to other online services.
According to the agency, this allows cybercriminals to escalate access across multiple platforms associated with the same email address, significantly increasing the potential scale of damage.
Risks of identity theft, fraud and business email compromise
The advisory warned that successful exploitation of stolen email credentials can lead to unauthorised access to personal and corporate accounts, identity theft and financial fraud through misuse of banking and payment information.
It further highlighted that compromised accounts can be used to launch Business Email Compromise (BEC) attacks and sophisticated phishing campaigns. Because such messages originate from trusted email addresses, they are often more convincing and harder for victims to detect.
ngCERT also warned that exposed email accounts may lead to the leakage of sensitive personal and organisational data, potentially resulting in reputational damage, operational disruptions and significant financial losses.
The agency noted that the rapid expansion of digital services and online transactions has further elevated the importance of email security, as email accounts often serve as the central gateway to multiple personal and business platforms.
Security recommendations for users, organisations
To reduce exposure to cyber threats, ngCERT advised users to create strong and unique passwords for each email account and enable Multi-Factor Authentication (MFA) wherever available.
The agency also urged internet users to avoid password reuse across platforms and consider using reputable password managers to securely generate and store complex credentials.
As part of its guidance, ngCERT encouraged users to regularly check whether their email addresses have appeared in known data breaches using the Have I Been Pwned repository. Users whose credentials are found in breach databases are advised to change passwords immediately and closely monitor accounts for suspicious activity.
Additionally, the agency recommended vigilance against phishing attempts, caution against clicking suspicious links or attachments, and activation of login notifications to detect unauthorised access attempts in real time.
Organisational cyber hygiene, awareness
For organisations, ngCERT advised regular review of account access logs, deployment of spam filtering and anti-phishing systems, and strengthened cybersecurity awareness training for employees.
The agency also emphasised the importance of educating staff and family members on safe email practices and the risks associated with credential exposure.
According to ngCERT, improving awareness, strengthening authentication mechanisms and adopting strong digital hygiene practices remain critical to mitigating the growing threat posed by stolen email credentials and related cyberattacks.
Stay ahead with real-time reports, breaking news, and exclusive insights delivered directly to your phone. Don’t settle for outdated information. Join TECHNOLOGYTIMES NEWS on WhatsApp for 24/7 updates.
Rivers State chapter of the African Democratic Congress, ADC, has uncovered an alleged plot by individuals linked to the Rainbow Coalition, including the University of Port Harcourt, UNIPORT, Vice Chancellor, Professor Princewill Chike, to rig the forthcoming election.
In a video clip sighted by DAILY POST, the Publicity Secretary of the party in Rivers State, Chizy Enyi, alleged that the VC is a member of the Rainbow Coalition, a cross-party socio-political movement formed by the Minister of the Federal Capital Territory, Nyesom Wike.
According to the ADC spokesperson, there are indications that the VC, who he claimed had publicly identified with the coalition, will nominate returning officers for the forthcoming election.
He alleged that Professor Chike “was not only recommended by Wike to be the VC but that he was imposed on the university.
Recommended
“In order to show the public that he is truly Wike’s product, at the entrance of the university, what you will see is the signpost of the VC with the caption, ‘Academia Rainbow Coalition of the Renewed Hope,’ with his picture on it.
“Those he will nominate as INEC returning officers for the election must be members of the coalition.
“It’s not even election time yet, but see what he is doing. During the election, all those who will be recommended are definitely going to come from the coalition.
“Professor Chike, only God knows what you have come to do in Port Harcourt. Let us see those you will recommend. Let us see whether they will rig the election.”
Islamic cleric, Sheikh Sani Yahaya Jingir, has described claims that he harbours hatred for Christians as “mere lies”.
This was just as he clarified that his recent controversial public l comments were taken out of context.
Jingir made the clarification on Sunday in Jos, Plateau State, while speaking at a one-day national symposium themed, “Enhanced Political Participation and Social Justice as a Panacea for Unity and Development in Nigeria.”
The cleric had recently attracted criticism over remarks made during a mass wedding ceremony organised by the Kano State Government for 1,500 couples, with some Nigerians accusing him of making comments capable of deepening religious divisions.
But addressing the controversy, Jingir said he never expressed hatred towards Christians or people of other faiths.
“A lot of people are saying I dislike Christians. I didn’t say I dislike Christians. It is a lie. My remarks were misinterpreted,” he said.
He stressed that Islamic leadership was founded on justice and fairness, arguing that Muslims were not permitted to discriminate against people of other faiths.
“Leadership in Islam is not about cheating people of different faiths. Islam teaches us to share love with people of different faiths or sects,” he added.
Jingir further said Muslims would be held accountable for any injustice committed against non-Muslims, while citing the Prophet Muhammad’s relationship with people of other faiths as an example of peaceful coexistence.
Sheikh Sani Yahaya
He consequently urged President Bola Tinubu, state governors and other political leaders to govern with fairness, regardless of the ethnic, religious or political affiliations of citizens.
“I call on President Bola Ahmed Tinubu not to cheat non-Muslims and Muslims alike. I also call on you not to cheat those who are not in the same political party with you. You should lead with justice and fairness to all Nigerians,” he said.
The JIBWIS leader also defended the right of Nigerians to make independent political choices, stressing that every citizen should be free to support any candidate of his or her choice during elections.
“Everyone has the right to vote for whoever he feels is okay with him to vote for during an election,” Jingir stated.
He called for greater commitment to peace, unity and national cohesion, warning that insecurity and division would continue to undermine Nigeria’s development.
“Without peace, there will be no development,” he said, urging Nigerians to strengthen peaceful relations among the country’s diverse ethnic and religious communities.
Jingir’s latest comments come against the backdrop of his earlier political remarks in Kano, where he publicly backed the Muslim-Muslim presidential ticket and described President Tinubu as his “political hero” for supporting the arrangement.
At the campaign event held in support of Governor Abba Kabir Yusuf, the cleric urged Muslims to obtain their Permanent Voter Cards and mobilise ahead of future elections.
He had said those opposed to the Muslim-Muslim ticket should “leave Nigeria because it belongs to us,” while referring to non-Muslims opposing the arrangement as “infidels” and urging his audience to “show the infidels their limit” at the polls.
Those remarks sparked criticism from sections of the public, with many accusing the cleric of promoting religious extremism.