The Nigerian Computer Emergency Response Team (ngCERT) has issued a cybersecurity advisory warning Nigerians and organisations across the country about the rising threat posed by stolen email passwords and login credentials.
Compromised accounts are increasingly being used to enable cybercrime, identity theft, financial fraud and other online attacks, the nation’s internet watchdog said.
The agency raised concerns over the large volume of email credentials exposed through data breaches and subsequently traded on dark web marketplaces and underground forums, where cybercriminals purchase them for malicious use.
According to ngCERT, billions of compromised email credentials are currently circulating online, making email accounts one of the most attractive targets for cyber attackers globally.
“Organisations and individuals are strongly advised to treat email security as a priority and take immediate steps to safeguard their accounts,” ngCERT said.
ngCERT warns Nigerians about rising theft of email credentials used for cybercrime, fraud and phishing, urging stronger password and MFA protection. Image credit: image FX.
“Organisations and individuals are strongly advised to treat email security as a priority and take immediate steps to safeguard their accounts,” ngCERT said.
Credential theft and automated attacks on the rise, ngCERT says
The advisory explained that cybercriminals routinely harvest usernames, passwords and personal information leaked during data breaches, before selling the data in bulk to other attackers.
These attackers then deploy automated tools to test stolen credentials across multiple online platforms in a technique known as credential stuffing.
Because many users reuse the same passwords across different services, attackers are often able to gain access to multiple accounts using a single set of compromised login details.
ngCERT noted that once email accounts are breached, attackers can access sensitive communications, financial records, personal data and password reset links linked to other online services.
According to the agency, this allows cybercriminals to escalate access across multiple platforms associated with the same email address, significantly increasing the potential scale of damage.
Risks of identity theft, fraud and business email compromise
The advisory warned that successful exploitation of stolen email credentials can lead to unauthorised access to personal and corporate accounts, identity theft and financial fraud through misuse of banking and payment information.
It further highlighted that compromised accounts can be used to launch Business Email Compromise (BEC) attacks and sophisticated phishing campaigns. Because such messages originate from trusted email addresses, they are often more convincing and harder for victims to detect.
ngCERT also warned that exposed email accounts may lead to the leakage of sensitive personal and organisational data, potentially resulting in reputational damage, operational disruptions and significant financial losses.
The agency noted that the rapid expansion of digital services and online transactions has further elevated the importance of email security, as email accounts often serve as the central gateway to multiple personal and business platforms.
Security recommendations for users, organisations
To reduce exposure to cyber threats, ngCERT advised users to create strong and unique passwords for each email account and enable Multi-Factor Authentication (MFA) wherever available.
The agency also urged internet users to avoid password reuse across platforms and consider using reputable password managers to securely generate and store complex credentials.
As part of its guidance, ngCERT encouraged users to regularly check whether their email addresses have appeared in known data breaches using the Have I Been Pwned repository. Users whose credentials are found in breach databases are advised to change passwords immediately and closely monitor accounts for suspicious activity.
Additionally, the agency recommended vigilance against phishing attempts, caution against clicking suspicious links or attachments, and activation of login notifications to detect unauthorised access attempts in real time.
Organisational cyber hygiene, awareness
For organisations, ngCERT advised regular review of account access logs, deployment of spam filtering and anti-phishing systems, and strengthened cybersecurity awareness training for employees.
The agency also emphasised the importance of educating staff and family members on safe email practices and the risks associated with credential exposure.
According to ngCERT, improving awareness, strengthening authentication mechanisms and adopting strong digital hygiene practices remain critical to mitigating the growing threat posed by stolen email credentials and related cyberattacks.
Stay ahead with real-time reports, breaking news, and exclusive insights delivered directly to your phone. Don’t settle for outdated information. Join TECHNOLOGYTIMES NEWS on WhatsApp for 24/7 updates.
Former governor of Ekiti State, Ayo Fayose, on Tuesday, predicted that the presidential candidates of the African Democratic Congress, ADC, Atiku Abubakar and Nigeria Democratic Congress, NDC, Peter Obi will lose to President Bola Tinubu in 2027.
Fayose made the remark while recalling how former president Olusegun Obasanjo lost his third term bid.
Featuring on Channels Television’s Politics Today, the former governor said Atiku and Obi’s loss will be too bad if they stand alone.
He said: “When Obasanjo wanted to do his third term he failed, anybody can deny but I don’t want to join issues with Obasanjo, I’m just giving this as an example.
Recommended
“When he wanted to do a third term it didn’t work because there are unwritten constitution that is within the norms of our politics.
“Today when you go by the book, in what way will Obi and Atiku, even if they come together, this man, President Tinubu, will still defeat them. But let us say that they didn’t come together, too bad for them.
“Southwest will come up with not less than five or six million difference, who will vote for Obi and Atiku in Ekiti? Who will vote for them in Osun? Who will vote for them in Ondo? What is their structure?”
The World Health Organisation (WHO) has reported that 11 African countries recorded active transmission of mpox in the six weeks between 6 July and 16 August 2026, with 1,153 confirmed cases and seven deaths.
The organisation disclosed this in its Mpox: Multi-country External Situation Report published on 14 September.
According to the report, Madagascar recorded785 cases, the highest during the period, followed by Angola with 184, Kenya with 94, the Democratic Republic of the Congo (DRC) with 41, and Cameroon with 28.
WHO noted that “reported weekly confirmed cases have remained somewhat stable on the continent, with about 200 cases per week in recent weeks.”
However, it cautioned that the figures could be underestimated due to reporting delays and reduced surveillance.
Mpox cases since 2025
The latest figures form part of the multi-country mpox outbreak, which has affected 35 African countries since January 2025.
According to the WHO report, the countries reported 52,424 confirmed mpox cases and 238 deaths between 1 January 2025 and 16 August 2026.
Globally, 65,784 confirmed cases and 264 deaths were reported in 105 countries between 1 January 2025 and 31 July 2026.
The WHO said 32 countries reported 1,370 confirmed cases and seven deaths in July alone, with the African Region accounting for 74.8 per cent of the cases.
New spread
WHO also reported new developments in the virus’s spread. Chile and Hungary reported mpox caused by clade Ib for the first time. In contrast, community transmission of the clade was reported in Czechia, France, Germany, Ireland, Italy, the Netherlands, Portugal, Switzerland and the United Kingdom.
Spain had the highest cumulative number of clade Ib cases in the group, with 241, followed by France with 173, Portugal with 162, and Germany with 140.
Madagascar remains a major concern, with WHO describing its outbreak as the largest mpox outbreak globally and in the African Region since December 2025.
As of 16 August, Madagascar had recorded 3,436 confirmed cases and 22 deaths.
Emergency status
The latest development comes months after the Africa Centres for Disease Control and Prevention (Africa CDC) declaredan end to mpox as a Public Health Emergency of Continental Security (PHECS) in January 2026.
Africa CDC said at the time that the emergency declaration was being lifted as the continent moved from an emergency response towards longer-term control and elimination of the disease.
The agency reported that suspected mpox cases had fallen by 40 per cent and confirmed cases by 60 per cent between early and late 2025, while the suspected case fatality ratio fell from 2.6 per cent to 0.6 per cent.
However, it stressed that mpox remained endemic in some settings and that vaccination would remain central to the response.
The WHO now considers the ongoing multi-country outbreak a graded health emergency and has extended its standing recommendations on mpox until August 2027.
Discover more from Premium Times Nigeria
Subscribe to get the latest posts sent to your email.