The Quiet Bleed: A look at the breaches, the silence, and the bill the rest of us are about to pay.
There is a particular kind of quiet that follows a Nigerian data breach. It is not the quiet of a problem being solved. It is the quiet of an institution hoping you will scroll past, forget the headline, and move on with your life. That quiet has become so familiar in the past year that it almost feels like policy.
In the last twelve months alone, three of the most important pillars of our digital life have been cracked open. Sterling Bank. Remita. The Corporate Affairs Commission. Each breach was bigger than the last, and each official response followed the same script; confusion, denial, then silence. Meanwhile, the data sits on cybercrime forums waiting for the next round of buyers.
If you have a BVN, an NIN, a salary that runs through a government ministry, or a registered business, you are inside this story whether you want to be or not. So let us actually talk about it.
A timeline that should embarrass everyone
The pattern started in late March 2026, when a threat actor calling themselves ByteToBreach claimed to have walked into Sterling Bank’s systems and walked out with records on roughly 900,000 customers. We are not talking about marketing emails. The leaked sample reportedly included BVNs, NINs, passport details, and even employee information. The bank, instead of telling its customers what to freeze and what to watch for, said almost nothing.
A few weeks later, Remita got hit. This is the platform that quietly moves salaries, taxes, and government payments for millions of Nigerians. Investigators traced the intrusion path, the Nigeria Data Protection Commission opened a quiet investigation in early April, and again the public got crumbs. Then came the Corporate Affairs Commission, with reports of unauthorised access to portions of its system and over 750GB of data, including more than 25 million company documents, potentially exposed.
Independent reporting from outlets like Techloy and Triumph Times has done more to inform Nigerians about what happened than any of the affected institutions. Think about that for a second. The people who hold your most sensitive identifiers told you less than a Substack newsletter did.
The numbers behind the silence
$3B
Lost to cybercrime in Nigeria between 2019 and 2025
4,200
Weekly cyberattacks on Nigerian organizations in 2025 (Check Point)
25M+
CAC company records reportedly exposed in the 2026 breach
Sources: FBI IC3 2024 report, Check Point Research 2025, Nigerian press reporting on the CAC breach.
These numbers are not abstract. According to the FBI’s Internet Crime Complaint Center, Nigeria sits in the top 12 countries in the world by volume of cybercrime complaints filed against it. Check Point Research, in its 2025 African threat report, clocked Nigerian organisations being hit by an average of 4,200 attacks every week. Africa, as a region, is now the most attacked continent on earth on a per-organisation basis. We are at the centre of that storm.
And we are bleeding money for it. Industry estimates put Nigeria’s cybercrime losses at around three billion dollars between 2019 and 2025. That is not a typo. That is roughly the budget of an entire ministry, vanishing into wallets we will never trace, while the government quietly slaps a cybersecurity levy on every electronic transaction to "fund the fight."
The cybersecurity levy that nobody can explain
In May 2024, the Central Bank of Nigeria issued a circular directing banks and payment service providers to charge a 0.5 percent levy on electronic transactions, in line with the Cybercrimes (Prohibition, Prevention, Etc) (Amendment) Act, 2024. After public outcry the rate was revised, but the principle stayed: every time you send money, a fraction of it is supposed to be funding national cyber defence.
Here is the uncomfortable question. If we have been paying that levy, and the government has been collecting it, why are our biggest financial and regulatory platforms still being walked into through what investigators describe as basic vulnerabilities? Where exactly is the money going, and what does it actually defend? Nobody in a position to answer has answered.
When citizens pay for a service, the least they deserve is to see the receipts. Right now we are paying for a security service whose only visible product is press releases.
Why the silence is the real attack
In cybersecurity there is a principle that every junior analyst learns in their first month. The faster a breach is disclosed, the smaller the damage. Disclosure lets customers reset passwords, revoke tokens, freeze accounts, and watch for fraudulent loans opened in their names. Silence does the opposite. It gives the attacker a head start measured in months.
When Sterling Bank refused to publicly confirm the scope of what was taken, every customer who reused that password elsewhere stayed exposed. When Remita went quiet, every salary recipient lost the chance to monitor their payroll route for tampering. When CAC danced around the truth, every business owner lost the ability to check whether their company filings could be forged tomorrow to take out loans, divert funds, or impersonate directors.
The attackers win once when they steal the data. They win a second time, every single day, that the rest of us are kept blind. That second win is the one our institutions are handing them for free.
Who actually pays the bill
It is tempting to read these stories and feel like the victims are giant logos or corporations. They are not. The victim is the trader in Onitsha whose BVN is now part of a package being resold for fifty dollars. He is the civil servant in Abuja whose salary platform credentials are floating in a Telegram channel. He is the small business owner in Ibadan whose CAC documents could be cloned to open a fraudulent corporate account in another state.
It is also the next generation of Nigerian founders trying to build fintech, health tech, and identity products on top of an ecosystem where trust is being quietly eroded. International investors read the same headlines we do. Every breach that goes unaddressed makes the next round of funding for an honest Nigerian startup a little harder to raise.
What needs to change, plainly
- Mandatory breach disclosure with real timelines - The NDPC has the legal mandate. It needs the political backing to enforce it without being dismissed as "harassment of business."
- Public accountability for the cybersecurity levy - If we are paying it, we should know what it built, what it stopped, and what it failed to stop. An annual public report is not a radical idea.
- Independent post-incident reviews - Not internal investigations. Independent ones, published in plain English so a market trader and a CISO can both understand what happened.
- Basic hygiene at the institutional level - Patch management, multi-factor authentication on admin accounts, and proper segmentation. The ByteToBreach intrusions reportedly exploited known vulnerabilities. None of this is exotic.
- Citizen-facing guidance after every breach - Tell people exactly what to do that week. Reset what. Watch for what. Call which number. Treat us like adults.
The part where we stop pretending
Nigeria is not unlucky. Nigeria is unprepared, and the gap between how digital we have become and how seriously we treat that digital life is now wide enough to drive a truck through. We moved our identities, our salaries, our companies, and our taxes online before we built the muscle to defend any of it.
Other countries have been here. The European Union dragged itself through the same conversation a decade ago and came out with GDPR. The United States is still arguing, but at least it argues loudly and in public. Our version of the conversation has been a press release, a quiet investigation, and a hope that the next news cycle moves on.
We do not have the luxury of waiting for the next news cycle. Every week that passes without honest disclosure is a week that someone, somewhere, is using a stolen Nigerian identity to take a loan, register a company, or move money through a payroll route that should not be open. That is not a tech story. That is a sovereignty story.
A small ask, to end on
If you are reading this and you work inside any of the affected institutions, push for the truth to come out. If you are a customer, ask your bank in writing what was taken and what is being done. If you are a journalist, keep covering it long after the trend dies down. If you are a policymaker, remember that the levy you collect is a promise, not a tax.
And if you are just a regular Nigerian trying to live your life, do the boring things this week. Change the passwords you have reused. Turn on two-factor authentication wherever it is offered. Check your CAC filings if you own a business. Pull your credit report if you can. Treat your digital identity the way you would treat the keys to your house, because right now, somebody else might already have a copy.
Our digital sovereignty is not going to defend itself. It is the national treasure nobody put in the budget speech. The least we can do is stop pretending we did not notice it leaving through the back door.
Nigeria’s digital infrastructure is leaking, and most citizens have no idea how bad it has gotten.



