Securva · Threat ResearchPrivate
Free meals,
not master thieves.
A sourced look at why Nigerian organisations actually get breached in 2024–2026 — and how it connects, almost one-to-one, to the weaknesses our own research measures.
The verdict: the breaches aren't sophisticated. Across regulators, security vendors, and incident forensics, Nigeria's breach wave is driven overwhelmingly by basic security-hygiene failures — unpatched known bugs, exposed unauthenticated databases and APIs, hardcoded secrets, broken access control, weak/stolen credentials. The attackers aren't picking locks. The doors are open.
1The receipts (real incidents, how they actually got in)
Every case below with a disclosed root cause was a hygiene failure, not a zero-day.
Sterling Bank → Remita → CAC (2026) — the national one
~3TB stolen incl. HSM/master-key material for 16+ banks + 25M CAC documents. Way in: an unpatched public CVE on an internet-facing server, AES keys hardcoded in the client-side JavaScript, dev servers running in production, unauthenticated internal APIs, a misconfigured S3 bucket. CAC: guessable sequential user-IDs + an unauth API → they requested valid tokens and fabricated an admin with 474 roles.
basic hygiene · "back door wide open"
MTN self-service portal (2025) — telecom, ~80M subscribers
A researcher found IDOR + broken session binding: a logged-in user could swap the phone number in a request and read ANY other subscriber's data — name, DOB, address, balance, history — with no extra auth. Textbook OWASP access-control failure.
basic hygiene
NASIMS federal social-investment platform (2025)
A misconfigured, public, unauthenticated S3 bucket exposed 23M+ files: NIN, passports, DOB, addresses, certificates. Open for most of a month.
basic hygiene · cloud misconfig
NIMC / "AnyVerify" (2024) — identity of ~104M Nigerians
Rogue sites resold citizens' NIN/BVN for ₦100 each via ungoverned verification APIs — no access control, no consent gate. (Proven by buying the President's own NIN slip.)
basic hygiene · API governance
CardinalStone · BestFin · CIBN
CardinalStone: a public phpMyAdmin with no password — "merely browsing the database sufficed." BestFin: an open MongoDB, 846k clients (OTPs, BVN logs). CIBN: admin RDP access sold for $330.
basic hygiene
First Bank insider (2024) — ₦40bn
A manager with final authorization and no second approver rerouted reversals to his own merchant accounts. Broken segregation of duties. EFCC: "every investigated case had insider involvement."
basic hygiene · controls/insider
And the tell that says it all
EternalBlue — an 8-year-old vulnerability (patched in 2017) — was still being exploited in Nigerian production systems in 2026. Website defacements of government CMS (NBS, Education Ministry) round out the picture.
basic hygiene · unpatched legacy
2What the people who'd know actually say
"Most recent incidents stem from preventable weaknesses in basic configuration, credential management, and operational controls, not sophisticated zero-day exploits. In plain terms, the doors were left open."— Digital Encode (Nigerian security firm)
"95% of all digital breaches are caused by human error, not technical failures."— Director-General, NITDA (Nigeria's own IT regulator)
"Not zero-day exploitation but unauthenticated APIs, internet-exposed admin panels, and hardcoded credentials… elementary defensive gaps."— CyHawk, on the 2026 bank campaign
The structural why: Nigeria has a ~90% cybersecurity workforce gap, and SMEs are literally labelled "low-hanging fruit." The official fraud stats agree — ~77% of 2024 bank fraud was phishing + SIM-swap + credential theft, i.e. human/controls failures, not technical exploits. The only genuine "sophistication" thread is AI making basic attacks (phishing) cheaper and faster — it amplifies the hygiene problem, it doesn't replace it.
3The dots connect to OUR research
The sectors we measured as weakest are exactly where the real breaches landed.
- Telecom — we measured it the WEAKEST (16% HSTS). Real-world result: the MTN portal IDOR exposing tens of millions of subscribers' data. Weakest on paper, breached in practice.
- Healthcare — we flagged it weak (31%) with the biggest exposed surface. Real-world result: ~130,000 Nigerian patient records sold off an exposed database.
- Government / identity. NASIMS (23M files, open S3) and NIMC (104M via ungoverned APIs) — the exact exposed-surface + weak-access class our scans flag.
Our passive research doesn't just describe the problem in the abstract — it points at where the next free meal is, before the attacker gets there.
4Scenario: our research in a threat actor's hands
A realistic chain — every step exploits a weakness we measure. No zero-day anywhere.
1
Pick the target — for free. The attacker does exactly what we do: passive, public measurement. They find a mid-size hospital or DisCo whose site doesn't enforce HTTPS and runs an old, well-known stack. No contact with the target yet.
we measure this: HSTS %, legacy stack
2
Walk through the open door. That old stack has a public, years-old CVE with a ready-made exploit (like the Sterling Next.js bug, or EternalBlue). Or an admin panel / database is simply exposed with weak or no auth (like CardinalStone's phpMyAdmin, BestFin's Mongo). Ten minutes, a browser, a public tool.
we measure this: exposed surfaces, legacy/unpatched
3
Pick up the keys lying on the floor. Secrets hardcoded in the page's JavaScript, credentials in a config file, a service account with no second approver. Now they're inside with real access.
we check for this: secrets exposure, weak auth
4
Walk sideways. Flat networks and implicit trust between systems (how Sterling became Remita) let them pivot from one weak box to the crown jewels — the patient database, the subscriber records, the payment keys.
we flag this: segmentation, trust boundaries
5
The payoff — and it lands on real people. Mass exfiltration of patient records, citizens' identities, or interbank keys → identity theft and fraud against millions, an NDPA fine (up to ₦10m or 2% of revenue), and a reputation that doesn't recover. All from a door that was never locked.
The Securva point: every single step in that chain is a weakness we can see from the outside and fix before an attacker uses it. We find the open door first, and close it. That's not fear-mongering — it's the measured reality, and it's exactly the work we sell.
5Honest caveats (so it holds up)
- Disclosure gap: several incidents (some bank/telecom/healthcare leaks) never published a root cause — they sit in "unknown." The "basic" verdict rests on the subset that WAS analysed; but nothing in the unknown pile was reported as sophisticated.
- Tradecraft nuance: a few 2026 attackers used capable tools AFTER getting in (Sliver C2, ADCS abuse). So "unsophisticated actor" is too strong — but the way IN was almost always an open door, not a picked lock.
- Power/DisCos: we found no publicly-sourced cyber incident — an honest gap, not proof they're safe (and notably, we measured them very weak at 21% HSTS).