Nigeria has experienced an average of more than 4,700 cyberattacks every week since the beginning of 2026, according to cybersecurity professional Anthony Fakiyesi.
Fakiyesi warned that keeping sensitive data within the country would not, on its own, provide adequate protection against the growing number of digital threats.
He spoke during an interview in Lagos on Saturday while assessing major cybersecurity trends affecting Nigeria in 2026.
Data Localisation Not a Complete Solution
Fakiyesi said Nigeria’s increasing focus on data localisation reflected a desire to gain greater control over critical information and strengthen digital sovereignty.
He cited the Central Bank of Nigeria’s data localisation directive as one of the measures intended to improve oversight of sensitive financial and customer data.
The cybersecurity expert, however, said storing data locally would provide limited protection if organisations failed to secure the systems and identities used to access it.
He called for stronger identity management, tighter access controls and improved monitoring of vendors and third-party technology providers.
According to him, control over data must be supported by the ability to withstand, detect and recover from cyber incidents.
Cybersecurity Now a Systemic Risk
Fakiyesi said cybersecurity could no longer be treated as an isolated responsibility of information technology departments.
He described it as a broader institutional issue that affected economic stability, public confidence and the continuity of essential services.
The concern has become more significant as Nigeria expands digital services across banking, government, telecommunications, commerce and financial technology.
Fakiyesi said institutions must ensure that their cybersecurity systems develop at the same pace as the country’s digital transformation.
Attackers Increasingly Use Valid Credentials
The expert said cybercriminals were gradually moving away from attacks that depended mainly on exploiting technical weaknesses.
Instead, attackers were increasingly using stolen login details, compromised identities and access provided through trusted third-party systems.
Once valid credentials are obtained, he explained, attackers may operate within an organisation’s network without immediately triggering traditional security alerts.
This makes it more difficult for institutions to distinguish malicious activity from the actions of authorised users.
Over 281,000 Accounts Reportedly Leaked
Fakiyesi said more than 281,000 Nigerian user accounts were leaked during the first quarter of 2026.
He identified banks, fintech companies, telecommunications providers and government institutions as some of the sectors most exposed to cyber threats.
These sectors hold large amounts of personal, financial and institutional information, making them attractive targets for cybercriminals.
He said the concentration of valuable data and digital access within these organisations increased the potential impact of a successful breach.
Third-Party Platforms Create Additional Risk
Fakiyesi warned that organisations were not exposed only through weaknesses in their internal systems.
They also inherited cybersecurity risks from vendors, software platforms, cloud services and other digital tools connected to their operations.
He said major cyber incidents recorded in 2026 had affected telecommunications companies, financial institutions, enterprise infrastructure and software-as-a-service platforms.
According to him, many of the attacks followed a similar pattern in which criminals gained entry through legitimate credentials or trusted third-party access.
He urged organisations to review every external system permitted to connect to their networks or handle sensitive information.
Poor Disclosure Weakens Collective Response
The cybersecurity professional also expressed concern about the limited public reporting of cyber incidents in Nigeria.
He said inadequate disclosure made it difficult for institutions to recognise recurring attack methods, share lessons and strengthen collective protection.
Improved reporting, he argued, would help regulators, companies and security professionals identify common vulnerabilities and respond more effectively.
Fakiyesi called for stronger incident-reporting standards and better cooperation between private organisations, public institutions and cybersecurity authorities.
Cybercrime Costs Nigeria Millions Annually
According to Fakiyesi, cybercrime costs Nigeria an estimated $500 million every year.
He warned that the financial impact could increase as more banking transactions, government services and commercial activities move online.
The expert said the expansion of Nigeria’s digital economy would create new opportunities but would also increase the number of systems available for attackers to target.
He therefore urged organisations to treat cybersecurity spending as an investment in business continuity and public trust rather than an optional technical expense.
Organisations Urged to Strengthen Resilience
Fakiyesi advised institutions to improve identity protection and continuously monitor access granted to employees, contractors and service providers.
He also called for stronger third-party risk management, faster incident reporting and more effective recovery plans.
Organisations should be able to continue essential operations, contain breaches and restore affected systems after an attack, he said.
Fakiyesi maintained that Nigeria’s pursuit of control over locally stored data must include adequate protection for the systems that determine who can access the information.
He said the ability to preserve digital trust would increasingly influence the stability and credibility of Nigerian institutions as the country’s digital economy expands.



















