Connect with us

News

ngCERT warns Nigerians over surge in stolen email credentials driving cybercrime – Technology Times

info

Published

on

1781866026 admin ajax.png

Stay connected via Google News


Add as preferred source on GoogleAdd as preferred source on Google

The Nigerian Computer Emergency Response Team (ngCERT) has issued a cybersecurity advisory warning Nigerians and organisations across the country about the rising threat posed by stolen email passwords and login credentials.

Compromised accounts are increasingly being used to enable cybercrime, identity theft, financial fraud and other online attacks, the nation’s internet watchdog said.

The agency raised concerns over the large volume of email credentials exposed through data breaches and subsequently traded on dark web marketplaces and underground forums, where cybercriminals purchase them for malicious use.

According to ngCERT, billions of compromised email credentials are currently circulating online, making email accounts one of the most attractive targets for cyber attackers globally.

“Organisations and individuals are strongly advised to treat email security as a priority and take immediate steps to safeguard their accounts,” ngCERT said.

ngcert-warns-nigerians-over-rising-email-threatngcert-warns-nigerians-over-rising-email-threat
ngCERT warns Nigerians about rising theft of email credentials used for cybercrime, fraud and phishing, urging stronger password and MFA protection. Image credit: image FX.

“Organisations and individuals are strongly advised to treat email security as a priority and take immediate steps to safeguard their accounts,” ngCERT said.

 

Credential theft and automated attacks on the rise, ngCERT says

The advisory explained that cybercriminals routinely harvest usernames, passwords and personal information leaked during data breaches, before selling the data in bulk to other attackers.

These attackers then deploy automated tools to test stolen credentials across multiple online platforms in a technique known as credential stuffing.

Because many users reuse the same passwords across different services, attackers are often able to gain access to multiple accounts using a single set of compromised login details.

ngCERT noted that once email accounts are breached, attackers can access sensitive communications, financial records, personal data and password reset links linked to other online services.

According to the agency, this allows cybercriminals to escalate access across multiple platforms associated with the same email address, significantly increasing the potential scale of damage.

Risks of identity theft, fraud and business email compromise

The advisory warned that successful exploitation of stolen email credentials can lead to unauthorised access to personal and corporate accounts, identity theft and financial fraud through misuse of banking and payment information.

It further highlighted that compromised accounts can be used to launch Business Email Compromise (BEC) attacks and sophisticated phishing campaigns. Because such messages originate from trusted email addresses, they are often more convincing and harder for victims to detect.

ngCERT also warned that exposed email accounts may lead to the leakage of sensitive personal and organisational data, potentially resulting in reputational damage, operational disruptions and significant financial losses.

The agency noted that the rapid expansion of digital services and online transactions has further elevated the importance of email security, as email accounts often serve as the central gateway to multiple personal and business platforms.

Security recommendations for users, organisations

To reduce exposure to cyber threats, ngCERT advised users to create strong and unique passwords for each email account and enable Multi-Factor Authentication (MFA) wherever available.

The agency also urged internet users to avoid password reuse across platforms and consider using reputable password managers to securely generate and store complex credentials.

As part of its guidance, ngCERT encouraged users to regularly check whether their email addresses have appeared in known data breaches using the Have I Been Pwned repository. Users whose credentials are found in breach databases are advised to change passwords immediately and closely monitor accounts for suspicious activity.

Additionally, the agency recommended vigilance against phishing attempts, caution against clicking suspicious links or attachments, and activation of login notifications to detect unauthorised access attempts in real time.

Organisational cyber hygiene, awareness

For organisations, ngCERT advised regular review of account access logs, deployment of spam filtering and anti-phishing systems, and strengthened cybersecurity awareness training for employees.

The agency also emphasised the importance of educating staff and family members on safe email practices and the risks associated with credential exposure.

According to ngCERT, improving awareness, strengthening authentication mechanisms and adopting strong digital hygiene practices remain critical to mitigating the growing threat posed by stolen email credentials and related cyberattacks.

Stay ahead with real-time reports, breaking news, and exclusive insights delivered directly to your phone. Don’t settle for outdated information. Join TECHNOLOGYTIMES NEWS on WhatsApp for 24/7 updates.

Join Our Whatsapp Channel

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

‘Security operatives connive with local militias to kill our people’ – Fulani youth leader alleges

info

Published

on

By

A Fulani youth leader in Bassa Local Government Area of Plateau State, Umar Yusuf, has accused security operatives of conniving with local militia gangs to kill herders, steal their cows and extort money from them to release the livestock.

Yusuf, who made the allegations during a town hall meeting convened by the Kautal Pulaaku Fulbe Association of Nigeria, KPFAN, on Saturday, said operatives of security agencies in the council go on raids alongside local Irigwe youths where they attack innocent herders, kill them and rustle their cattle.

While speaking during the meeting, Yusuf said the practice has been going on for years and has gotten worse in recent times.

“What has been happening in Bassa and other parts of Plateau State is a very worrisome situation.

“You will be surprised to hear that security personnel connive with local Irigwe militants to attack Fulani herdsmen during raids on Fulani communities,” he said. 

He further alleged that during such raids, some of which end up with casualties, cows are seized from the communities while the owners are later made to pay huge amounts of money to get them back.

“Our cattle are seized and stolen from us and taken to a military camp for days, weeks and sometimes months without an iota of reason for farm encroachment whatsoever.

“We will then have to pay huge sums of money to get them back from the security people. We, the Fulani herders, face severe economic backwardness as a result of this. We deserve protection as much as others,” Yusuf said.

He further alleged that on July 30th, some Fulani herders were attacked by armed Irigwe youths along with some security personnel, during which six cows were killed and others severely injured in an unprovoked attack at Ancha village in the LGA, while a herdsman identified as Muhammadu Rebo was killed while grazing peacefully without encroaching on any farmland.

Continue Reading

News

Osun Guber: Accord challenges police operations, alleges selective arrest 

info

Published

on

By

Accord party.jpg

Osun State chapter of the Accord Party has accused the State Police Command of selective policing and targeting its members ahead of the August 15 governorship election.

The party’s position follows the police dismissal of allegations by the Imole Campaign Council that it had compiled a list of political figures for arrest before the governorship poll. 

In a statement signed by the Osun Accord Chairman, Pastor Victor Akande, the party rejected the police’s explanation for recent raids and arrests, alleging that security operations were being used to intimidate its leaders and members rather than tackle criminal activities.

According to the Accord, “the police had departed from their constitutional responsibility by allegedly focusing on members of the party while failing to act against individuals it claimed were linked to the All Progressives Congress (APC).”

The party alleged that individuals such as Kazeem Oyewale, popularly known as Asiri Eniba, and others allegedly connected to the APC had not been subjected to similar security operations despite facing criminal allegations. It further claimed that selective policing was undermining public confidence in the security agencies.

Referring to an incident in Ikire, Accord alleged that one of its members, Taofeeq Akinyemi, who was recently arrested and transferred to the State Criminal Investigation Department, had earlier been shot by an individual identified as Akinkunmi Alabi, also known as Ojuyobo. 

The party claimed Akinyemi survived after receiving medical treatment and questioned why the alleged attacker had not been arrested.

Akande said, “As a political party, we very much support any effort that will put criminals away so as to guarantee a peaceful and free poll, but we will not accept the subtle attempt by the Police to brand the membership of Accord as being criminal.”

The Accord chairman urged the police to review their operations, release what the party described as political detainees, including Akinyemi, and ensure that policing remained impartial throughout the election period.

The Osun State Police Command has also maintained that their operations are strictly aimed at combating crime across the state.

The command denied the existence of any such list and insisted that its operations were not politically motivated.

Responding to the allegations, the Police Public Relations Officer, DSP Abiodun Ojelabi, reiterated that the command had not drawn up any list of politicians for arrest and was not targeting any political party.

Ojelabi said, “We are raiding black spots and criminal hideouts every day to sanitise the environment for the forthcoming election, and this raid is not targeted at any individual, group of persons or political party. It is targeted at criminal hideouts. We don’t have any list anywhere; the police do not formulate any list.”

He added that the command would continue intelligence-led operations against criminal elements across the state and advised parents to discourage their children from late-night movements and association with individuals with criminal records. 

Ojelabi also noted that the proposed joint security task force announced by the state government had yet to commence operations.

Continue Reading

Trending