Nigerian Banks Face Rising Cyber Threat as Global Attacks Target Financial Sector
Nigerian banks are operating amid a growing global cyber threat, with attacks on financial institutions more than doubling in 2025, according to Check Point. While an industry statement says Nigerian lenders have contained the latest international campaign, it does not identify any affected bank or provide evidence of a breach or attempted intrusion in Nigeria.

By Adesegun Adeshi Gbenga

Nigerian banks are operating amid a rapidly worsening global cyber threat environment, but there is no publicly available evidence showing that Nigerian lenders have been breached as part of the latest international campaign described in a statement circulated to the media.

The statement, issued by The Genius Media, says Nigerian banks have “swiftly” contained the effects of a sophisticated cyber campaign and that banking services, digital channels and customer deposits remain secure.

What is known about the global campaign?

There is independent evidence of a significant cyber-espionage campaign affecting organisations across several countries and sectors.

Cybersecurity researchers have linked one such campaign to MuddyWater, an Iranian threat actor also known as Seedworm or Static Kitten.

Research published in May found that the group had targeted at least nine organisations in nine countries across four continents during the first quarter of 2026.

The victims included organisations in financial services, manufacturing, education, aviation and the public sector.

A US bank was among organisations whose networks were compromised in activity attributed to MuddyWater earlier this year, according to reporting based on research by Broadcom's Symantec and Carbon Black teams.

However, those findings do not establish that a Nigerian bank was among the victims.

The distinction matters because the press statement describes the campaign as affecting more than 35 organisations, while publicly available reporting on the MuddyWater campaign identified at least nine organisations across nine countries.

The statement also presents the attacks as a single campaign affecting telecommunications, healthcare, government, energy, technology, corporate registries and finance.

Available evidence shows that multiple cyber campaigns have affected different sectors, but it is not clear from the statement what evidence links all of these incidents to one coordinated operation.

Financial sector attacks more than doubled

What is not in dispute is that financial institutions face a substantially higher level of cyber risk.

Check Point reported that attacks against financial organisations increased from 864 incidents in 2024 to 1,858 in 2025 — more than doubling in a single year.

Distributed denial-of-service attacks increased by 105%, while data breaches and leaks rose by 73%.

The trend means that banks do not need to have suffered a confirmed breach for the threat to matter to their customers.

Modern banking depends heavily on internet-facing systems, mobile applications, payment platforms, cloud infrastructure and third-party technology providers.

A successful intrusion can therefore affect not only the bank but potentially millions of customers and businesses that depend on its payment infrastructure.

Nigeria is tightening its defences

The Central Bank of Nigeria has been strengthening its cybersecurity requirements as the financial system becomes increasingly digital.

In March 2026, the CBN deployed a Cybersecurity Self-Assessment Tool for banks and selected other financial institutions.

The tool is intended to give the regulator information about institutions' cybersecurity governance, risk management, technology and third-party risks, incident-response capabilities and operational resilience.

The regulator's risk-based cybersecurity framework also requires deposit money banks and payment service banks to conduct cybersecurity self-assessments and report them to the CBN annually.

The assessments are expected to examine vulnerabilities, emerging threats, potential impact and an institution's ability to respond to and recover from cyber incidents.

That suggests that cybersecurity resilience is not simply a matter of banks declaring that their systems are safe.

It is also a regulatory issue requiring continuous assessment and oversight.

Customers remain an important target

Even when criminals cannot directly penetrate a bank's core systems, they can target customers.

The statement warns Nigerians against disclosing passwords, PINs, one-time passwords, card details or BVNs to callers claiming to represent their banks.

That advice is consistent with the broader fraud risks facing Nigeria's increasingly digital financial system.

The CBN has introduced additional controls around instant payments, including requirements for stronger identity verification and real-time fraud monitoring.

The Nigeria Inter-Bank Settlement System also says the BVN system is designed to strengthen customer identification and reduce exposure to identity theft and unauthorised access.

As of 27 July 2026, NIBSS reported more than 69.7 million BVNs in its system.

But customer vigilance cannot substitute for institutional security.

A phishing message may trick a customer into surrendering credentials, while a separate attack could exploit weaknesses in a bank's software, employees, suppliers or infrastructure.

The two risks require different responses.

The claim that “customer deposits” are safe should therefore not be interpreted as proof that Nigerian banks are immune from cyberattacks.

No serious cybersecurity system can guarantee immunity.

What can be assessed is whether institutions have adequate controls to prevent attacks, detect intrusions, contain them and recover from them.

Why this matters to bank customers

For millions of Nigerians, the issue is bigger than whether a banking app is working today.

A successful cyberattack could expose personal information, interrupt payments, facilitate fraud or undermine confidence in the financial system.

The increasing dependence on digital payments means that a prolonged disruption could affect businesses, salaries, online commerce and everyday transactions.

The CBN has itself recognised the need for stronger resilience.

Its recent cybersecurity measures and requirements for financial institutions show that the threat is being treated as an ongoing regulatory risk rather than a one-off incident.

For customers, the practical lesson is simple: do not assume that a message is genuine because it appears to come from a bank, and report suspicious activity through the bank's verified channels.

For banks and regulators, however, reassurance must eventually be backed by evidence.

Leave a Reply

Your email address will not be published. Required fields are marked *

Share with

Verified by MonsterInsights