Post

Post: Nigeria Faces Over 4,700 Weekly Cyberattacks, Cybersecurity Expert Warns


Lagos: Cybersecurity professional, Mr. Anthony Fakiyesi, has highlighted that data localisation alone is insufficient in safeguarding Nigeria’s digital ecosystem from the escalating threat of cyberattacks.



According to News Agency of Nigeria, Fakiyesi revealed in an interview that Nigeria has been experiencing an average of more than 4,700 cyberattacks each week since the year began. This alarming statistic underscores the urgent need for enhanced cybersecurity measures beyond the current data localisation policies, such as the directive from the Central Bank to strengthen control over sensitive information.



Fakiyesi emphasized that while data localisation is a step towards digital sovereignty, it must be supported by robust identity management, access controls, and third-party risk management. He warned that without addressing vulnerabilities in access systems, localising data alone cannot mitigate cyber risks. He further explained that cybersecurity is evolving into a systemic issue that affects economic stability and institutional trust as Nigeria advances its digital transformation across various sectors including finance, government, and commerce.



The expert noted a significant shift in cyberattack strategies, with attackers increasingly using legitimate credentials and compromised identities to infiltrate systems. This change necessitates that organisations focus on securing their digital services and vendor platforms, as these have become common targets for cybercriminals. Nigeria recorded over 281,000 leaked user accounts in the first quarter of 2026, with cyberattacks primarily targeting sectors such as banking, fintech, telecommunications, and government institutions.



Fakiyesi highlighted the inadequacy of traditional security measures in countering modern threats that exploit legitimate access avenues. He pointed out that attackers can now operate within compromised systems without raising immediate suspicion, making supply chain and third-party relationships critical components of an organisation’s cybersecurity strategy.



In 2026, major cyber incidents have predominantly affected telecommunications, SaaS platforms, financial services, and enterprise infrastructure, where identity, data, and access converge. Fakiyesi expressed concern over the limited visibility of cyber incidents in Nigeria, which hampers the identification of recurring vulnerabilities and the strengthening of collective defences.



With cybercrime costing Nigeria an estimated $500 million annually, Fakiyesi called for stronger cybersecurity governance, improved incident reporting, and enhanced resilience to accompany the country’s digital transformation efforts. He stressed that securing digital trust will be crucial for the resilience of Nigerian institutions as the nation deepens its digital economy.



Fakiyesi concluded by urging organisations to bolster identity protection, monitor third-party access, and build resilience across their digital ecosystems to withstand increasingly sophisticated cyber threats. The pursuit of greater data control must be complemented by measures to secure systems that manage access to such data, ensuring Nigeria’s institutions can sustain their rapid digital transformation.