Years ago, cyber attackers relied heavily on phishing emails, stolen passwords, and social engineering. Nowadays, Artificial Intelligence (AI) systems are making those attacks faster, cheaper, and harder to detect.
However, global cybersecurity experts from Five Eyes, in a rare joint statement, warned that these advanced AI systems could dramatically increase the sophistication and scale of cyberattacks within months.
Evidently, AI-generated phishing messages can now mimic writing styles, research and reference real projects, and also target specific individuals. Deepfake videos and cloned audio voices can impersonate executives, public figures, politicians, and business leaders. Fraudsters can also use AI to create manufactured identities and bypass traditional verification systems.
The AI threat is no longer theoretical but practical. Reports indicate that the Nigerian organisations faced more than 4,000 cyberattacks per week in 2025. Ranging from identity-based attacks and AI-assisted campaigns becoming increasingly common.
Industry analysts warn that attackers are now using AI to scale fraud operations that once required considerable human effort.
However, the growing risk became more visible in early 2026 when several high-profile cyber incidents affected government agencies and private-sector organisations.
In early 2026, the Corporate Affairs Commission (CAC) confirmed that it experienced a cyber attack that disrupted parts of its digital infrastructure and affected access to some online services. The incident triggered investigations and renewed concerns about the security of critical government platforms that hold millions of corporate records.
This attack proved one thing: that is Government databases are now becoming attractive targets for cyber attacks. Databases that contain valuable identity, business, and regulatory information are now facing serious threats.
In April 2026, the financial sector including Remita Payment Services Ltd, Sterling Bank, and other entities encountered a data breach.
Afterward, the Nigerian Data Protection Commission (NDPC) launched an investigation which proved that threat actors had claimed access to sensitive customer and institutional data. Regulators moved quickly to determine the scope of the incident and assess potential risks to affected users.
The case raised fresh concerns about the resilience of Nigeria’s digital payments ecosystem. As more transactions move online, financial institutions have become high-value targets for cybercriminals seeking personal and financial data.
The Nigerian education sector isn’t left behind in cyber backlash. Universities hold large volumes of student, staff, and research data. Cybersecurity experts have repeatedly warned that many institutions continue to operate with limited security resources and outdated systems, making them attractive targets for attackers.
Notably, AI-generated attacks are different from traditional phishing systems because they produce convincing emails, realistic voice recordings, and highly personalised scams at scale.
Also, Deepfake technology has also emerged as a growing threat to businesses and public institutions.
The danger extends beyond financial loss. A successful deepfake can damage reputations, manipulate public opinion, or undermine trust in digital systems.
Recognising the growing threat, Nigerian authorities have started strengthening their response. The National Information Technology Development Agency (NITDA) took the first step of expanding the role of its Computer Emergency and Response Team (CERRT).
This will provide incident response, threat intelligence, security awareness, and coordination support for organisations facing cyber incidents.
The agency has also continued to push cybersecurity awareness initiatives and collaboration across the public and private sectors.
Meanwhile, the Federal Government has also signalled stricter cybersecurity requirements, including stronger reporting obligations, information-sharing frameworks, and measures aimed at improving national cyber resilience.
These efforts are designed to improve how organisations detect, report, and respond to cyber threats.
The evidence suggests Nigeria is better prepared than it was a few years ago. Regulators are becoming more proactive. NITDA has strengthened incident response capabilities.
Also, data protection enforcement is becoming more visible. Organisations are now investing more in cybersecurity.
