Securva · Threat ResearchPrivate

Free meals,
not master thieves.

A sourced look at why Nigerian organisations actually get breached in 2024–2026 — and how it connects, almost one-to-one, to the weaknesses our own research measures.

The verdict: the breaches aren't sophisticated. Across regulators, security vendors, and incident forensics, Nigeria's breach wave is driven overwhelmingly by basic security-hygiene failures — unpatched known bugs, exposed unauthenticated databases and APIs, hardcoded secrets, broken access control, weak/stolen credentials. The attackers aren't picking locks. The doors are open.

1The receipts (real incidents, how they actually got in)

Every case below with a disclosed root cause was a hygiene failure, not a zero-day.
Sterling Bank → Remita → CAC (2026) — the national one
~3TB stolen incl. HSM/master-key material for 16+ banks + 25M CAC documents. Way in: an unpatched public CVE on an internet-facing server, AES keys hardcoded in the client-side JavaScript, dev servers running in production, unauthenticated internal APIs, a misconfigured S3 bucket. CAC: guessable sequential user-IDs + an unauth API → they requested valid tokens and fabricated an admin with 474 roles.
basic hygiene · "back door wide open"
MTN self-service portal (2025) — telecom, ~80M subscribers
A researcher found IDOR + broken session binding: a logged-in user could swap the phone number in a request and read ANY other subscriber's data — name, DOB, address, balance, history — with no extra auth. Textbook OWASP access-control failure.
basic hygiene
NASIMS federal social-investment platform (2025)
A misconfigured, public, unauthenticated S3 bucket exposed 23M+ files: NIN, passports, DOB, addresses, certificates. Open for most of a month.
basic hygiene · cloud misconfig
NIMC / "AnyVerify" (2024) — identity of ~104M Nigerians
Rogue sites resold citizens' NIN/BVN for ₦100 each via ungoverned verification APIs — no access control, no consent gate. (Proven by buying the President's own NIN slip.)
basic hygiene · API governance
CardinalStone · BestFin · CIBN
CardinalStone: a public phpMyAdmin with no password — "merely browsing the database sufficed." BestFin: an open MongoDB, 846k clients (OTPs, BVN logs). CIBN: admin RDP access sold for $330.
basic hygiene
First Bank insider (2024) — ₦40bn
A manager with final authorization and no second approver rerouted reversals to his own merchant accounts. Broken segregation of duties. EFCC: "every investigated case had insider involvement."
basic hygiene · controls/insider
And the tell that says it all
EternalBlue — an 8-year-old vulnerability (patched in 2017) — was still being exploited in Nigerian production systems in 2026. Website defacements of government CMS (NBS, Education Ministry) round out the picture.
basic hygiene · unpatched legacy

2What the people who'd know actually say

"Most recent incidents stem from preventable weaknesses in basic configuration, credential management, and operational controls, not sophisticated zero-day exploits. In plain terms, the doors were left open."— Digital Encode (Nigerian security firm)
"95% of all digital breaches are caused by human error, not technical failures."— Director-General, NITDA (Nigeria's own IT regulator)
"Not zero-day exploitation but unauthenticated APIs, internet-exposed admin panels, and hardcoded credentials… elementary defensive gaps."— CyHawk, on the 2026 bank campaign
The structural why: Nigeria has a ~90% cybersecurity workforce gap, and SMEs are literally labelled "low-hanging fruit." The official fraud stats agree — ~77% of 2024 bank fraud was phishing + SIM-swap + credential theft, i.e. human/controls failures, not technical exploits. The only genuine "sophistication" thread is AI making basic attacks (phishing) cheaper and faster — it amplifies the hygiene problem, it doesn't replace it.

3The dots connect to OUR research

The sectors we measured as weakest are exactly where the real breaches landed.
Our passive research doesn't just describe the problem in the abstract — it points at where the next free meal is, before the attacker gets there.

4Scenario: our research in a threat actor's hands

A realistic chain — every step exploits a weakness we measure. No zero-day anywhere.
1
Pick the target — for free. The attacker does exactly what we do: passive, public measurement. They find a mid-size hospital or DisCo whose site doesn't enforce HTTPS and runs an old, well-known stack. No contact with the target yet.
we measure this: HSTS %, legacy stack
2
Walk through the open door. That old stack has a public, years-old CVE with a ready-made exploit (like the Sterling Next.js bug, or EternalBlue). Or an admin panel / database is simply exposed with weak or no auth (like CardinalStone's phpMyAdmin, BestFin's Mongo). Ten minutes, a browser, a public tool.
we measure this: exposed surfaces, legacy/unpatched
3
Pick up the keys lying on the floor. Secrets hardcoded in the page's JavaScript, credentials in a config file, a service account with no second approver. Now they're inside with real access.
we check for this: secrets exposure, weak auth
4
Walk sideways. Flat networks and implicit trust between systems (how Sterling became Remita) let them pivot from one weak box to the crown jewels — the patient database, the subscriber records, the payment keys.
we flag this: segmentation, trust boundaries
5
The payoff — and it lands on real people. Mass exfiltration of patient records, citizens' identities, or interbank keys → identity theft and fraud against millions, an NDPA fine (up to ₦10m or 2% of revenue), and a reputation that doesn't recover. All from a door that was never locked.
The Securva point: every single step in that chain is a weakness we can see from the outside and fix before an attacker uses it. We find the open door first, and close it. That's not fear-mongering — it's the measured reality, and it's exactly the work we sell.

5Honest caveats (so it holds up)

Securva internal · 2026-10-01 · private, noindex. Sources incl. Digital Encode / Ogun Security, NITDA (Technext), CyHawk-Africa, websecuritylab.org, Check Point Africa 2025, CYFIRMA Nigeria assessment, NIBSS, EFCC, Premium Times / Paradigm Initiative, Cybernews, TechEconomy, NDPC. Companion to the Securva Research brief.