Your Next Robbery Will Arrive by Email
Cybercrime has become Nigeria's quietest business expense. And as of June 2026, the law is no longer only chasing the criminals. It is watching you too.
29 July 2026
It happens on a Friday, because Fridays are busy and busy people don't double-check.
An email arrives from a supplier your company has paid for three years. Same name, same signature, same tone. They have changed banks, it says. Here are the new details. Kindly update your records before the next payment run.
Your accounts officer does exactly what she was trained to do. She updates the record. The following week, eleven million Naira goes out. Clean transfer, correct approval, proper documentation.
Three weeks later the real supplier calls, politely asking about his money.
Nobody hacked anything. No firewall failed. Somebody simply studied how your business pays its bills, waited for a Friday, and asked nicely. That is what cybercrime looks like in Lagos, Abuja and Port Harcourt today. Not a hooded figure in a basement. An email that looks like every other email you received that morning.
Cybercrime statistics in Nigeria are telling two different stories
On the surface, good news. At this year's Nigeria Electronic Fraud Forum, NIBSS reported that losses to electronic payment fraud dropped to 25.85 billion Naira in 2025, roughly half of the 52.26 billion Naira lost in 2024. Reported incidents have now fallen five years running.
Except the headline has a hole in it. NIBSS's own account of 2024 attributes the bulk of that year's total to a single fraud incident of 31.1 billion Naira at one entity. Strip that one event out and the 2024 baseline falls to somewhere near 21 billion, which means the celebrated fifty-one percent decline is substantially an artefact of one bad day at one institution rather than a year of broad improvement.
Then you read FITC's report for the fourth quarter of 2025, published in May. It counts something narrower than the NIBSS figure, returns filed by 29 deposit money institutions rather than the whole payments ecosystem, and the mood changes completely. Cases did not fall. They rose 34 percent on the previous quarter, to 19,719. The amount involved rose 141 percent, to 12.67 billion Naira. And the money actually lost rose 576 percent, from 776 million Naira to 5.25 billion. Measured against the same quarter a year earlier, actual losses were up 278 percent. FITC's own summary describes a marked escalation in both the volume of incidents and the value of losses. Not fewer, bigger attacks. More attacks, and bigger ones. FITC does not disaggregate the quarter, so part of that jump may itself sit in a small number of very large incidents. The direction is not in doubt either way.
And it came through one door. Computer and web channels carried 69 percent of the money involved and 86.7 percent of everything actually lost, with web-related losses rising more than fifteenfold in a single quarter. Nigerian banks lost more money through a browser in the last three months of 2025 than through every other channel put together, several times over.
And here is the part that should concern anyone running a business. Those statistics measure banks, the most defended institutions in the country, and the banks are losing ground. Through the first and third quarters of 2025 they blocked a steady 85 percent of the value criminals attempted to take. In the fourth quarter that fell to under 59 percent. More than two Naira in every five now gets through. And banks have fraud desks, monitoring centres and a regulator breathing down their necks.
Your company has one person in accounts.
The diverted vendor payment, the ransom quietly paid, the customer list that walked out with a resigning staff member: none of it enters any national statistic. It gets absorbed, written off, and never spoken of again. And the measuring itself is slipping: fraud reporting fell by roughly 34 percent in the final quarter of 2025, and the chief executive of NIBSS called that non-reporting unacceptable, noting that people involved in fraud had simply moved to other institutions because incidents were never logged. If the most regulated corner of the economy is under-reporting, consider the rest. The measured, protected institutions are winning. The unmeasured, unprotected ones are funding the criminals' expansion.
Nor is this a niche category any more. Interpol's 2025 assessment found that cyber offences now account for around 30 percent of all reported crime in West and East Africa, while 90 percent of African countries said their own law enforcement or prosecution capacity needs significant improvement. The crime has scaled faster than the response to it, which is the entire argument for not being a soft target in the first place.
How cybercrime actually happens to Nigerian businesses
Forget the movie version. Five patterns account for most of the damage.
The changed account number. Business email compromise, the one in our opening scene, remains the most expensive threat most companies will ever face, precisely because it contains no technology to detect. The criminal either hijacks a real mailbox or registers one that differs by a single letter, studies your payment rhythm for weeks, then steps in at the exact moment money is about to move. Nigeria keeps no count of this. The best-measured market does: in the United States the FBI recorded 3.05 billion dollars of business email compromise losses in 2025 from fewer than 25,000 reports, an average above 122,000 dollars a time, with 86 percent of the money moving by wire and most of it beyond reach before anyone noticed. The mechanics do not change at the border. What has changed is the disguise. Analysis of nearly 800,000 email attacks across 4,600 organisations found that impersonating a supplier now accounts for 61 percent of all business email compromise, and that a request to update billing details is the single most dangerous message a finance team can receive. Roughly one in four of those attempts succeeds. And it happens at every size. During a single month-long Interpol operation across nineteen African countries last year, a petroleum company in Senegal caught a scheme in which fraudsters had got inside its internal email and impersonated executives to authorise a wire transfer of 7.9 million dollars.
The voice on the phone. It is getting worse, because the machines have joined. Fraud powered by artificial intelligence is cheaper to run and far harder to spot than the traditional kind. AI now writes flawless emails in your MD's exact style and clones his voice well enough to approve a payment by phone while the real man is in a meeting in Abuja. The voice note that says "please treat that transfer as urgent" may not be from who you think. In 2025 the FBI began formally tracking artificial intelligence as a distinct element in cybercrime and logged more than 22,000 complaints with an AI component, carrying 893 million dollars in losses. It added that the figure is certainly too low, because most victims never realise a machine was involved.
The locked screen on Monday morning. Ransomware has moved down-market. The criminals worked out that a mid-sized Nigerian firm with no backups and a payroll to run on Friday will negotiate faster than a multinational with an incident response team. A trading company that cannot invoice is a company that will pay. Interpol's 2025 assessment of the continent counted 3,459 ransomware detections in Nigeria during 2024, third behind South Africa and Egypt. Those are detections. The number of Nigerian firms that quietly paid and said nothing is not counted anywhere.
The person with a staff ID. Uncomfortable, but the data insists. Insiders appear in a tiny fraction of cases and a wildly disproportionate share of the successful ones. In the last quarter of 2025, fraudulent withdrawals, a category in which bank staff were involved in seven of the nine cases, turned 81 percent of the money at stake into money actually gone. Web fraud managed 52 percent. When the person committing the fraud already holds the access, the controls do not get a vote. Note too what happened to enforcement: staff-linked cases edged up while terminations fell by 60 percent, from 25 to 10, which FITC itself flags as a possible gap in identifying or penalising internal collusion. And that is in banks, where duties are separated. In a business where one person raises, approves and reconciles payments, you are not running a control. You are running a prayer.
The partner you trusted. Every business now hands its data to others: banks, processors, software vendors, payroll platforms, tax intermediaries. Their weakness becomes your loss. When a vendor is breached, it is still your customers' data and your name in the story.
There is a symmetry here worth naming plainly. This particular crime grew up in Nigeria. Researchers tracking business email compromise through the late 2010s put Nigerian groups at the centre of it, and credited them with teaching the method to criminal networks elsewhere. The part rarely told is what came next: enforcement at home got serious enough that the operators scattered. The trade now runs from more than fifty countries, with roughly a quarter of identified actors sitting in the United States. The playbook left, went global, and has come back aimed at the businesses it was built among. Which means Nigerian companies are now defending against a fraud their own country understands better than anyone. That is not a cause for embarrassment. It is a reason to be unusually good at this, and no excuse whatever for being caught by a technique invented down the road.
The law caught up: the Cybercrimes Act, the NDPA and the new NIMC Act 2026
For a long time, Nigerian law treated cybercrime as the criminal's problem. That era is over. Three pieces of legislation now form a stack, and every layer touches your business.
The Cybercrimes Act, sharpened by the 2024 amendment, is the criminal spine, and it does more to you than for you. Section 32 makes phishing an offence in itself, carrying up to three years, a million Naira, or both. But the part businesses miss sits in section 21: any organisation running a computer system or network, public or private, is required to report attacks, intrusions and disruptions to the national Computer Emergency Response Team. The 2024 amendment built sectoral response teams and security operations centres beneath that, and gives you 72 hours to report an incident to yours. Almost every Nigerian business breached in the last two years had a reporting duty it did not know it had.
The Nigeria Data Protection Act changed whose problem a breach is. Lose customer or employee data today and you have not merely suffered a crime, you have created a regulatory event, and the exposure scales with your size: for a data controller of major importance, two percent of the previous year's gross revenue or ten million Naira, whichever is greater. This is not theoretical. The Nigeria Data Protection Commission has concluded 246 investigations, fined MultiChoice Nigeria 766.2 million Naira, and fined Fidelity Bank 555.8 million Naira for, among other things, engaging third-party processors that were not compliant. Read that last part again. A bank was penalised for its vendors' failings. In 2025 the Commission served compliance notices on 1,368 organisations, among them 795 financial institutions and 392 insurance brokers, each given 21 days to produce evidence. The breach costs you twice: once in the loss, and again in the accounting for it.
Then, on 26 June, the President signed the NIMC Act 2026, and this is the one most businesses have not yet digested. Repealing the 2007 law entirely, it rebuilds Nigeria's identity infrastructure around the NIN, makes the Commission the root certification authority for digital trust services across private-sector platforms as well as government, and speaks directly to how organisations outside government handle NIN-linked data, a subject on which the old law was almost silent. Corporate violations are reported to carry fines of up to twenty million Naira. Unauthorised access to identity data carries a minimum of five years. And the Commission now holds court-authorised powers to search premises, seize evidence and decrypt data.
Now look at what the same Act does on the other side. It makes the NIN a prerequisite for opening bank accounts, buying telecoms services, claiming on insurance, drawing a pension, accessing consumer credit, transacting in land and paying tax, and it expects businesses to build NIN verification into how they take customers on. So the volume of NIN data sitting in ordinary company files is about to rise sharply, at precisely the moment the penalty for mishandling it does. Pause on that. Your HR files hold your employees' NINs. Your KYC records hold your customers'. That drawer of photocopied ID cards and that unprotected spreadsheet of staff records are no longer just untidy. They are regulated assets sitting in an unregulated container, and there will shortly be more of them.
The direction of travel could not be clearer. The law used to chase the thief. Now it also examines the victim's locks.
The defence is cheaper than the loss. We tested it on ourselves.
Here is the encouraging part: most of what protects a Nigerian business costs discipline, not money. We can say that with a straight face because we ran the experiment on our own people.
Earlier this year we ran a phishing simulation across Doftwerks and Stransact. Every member of staff received it, partners included, with no advance warning and no exemptions for seniority. It was a realistic mail, the kind that catches real companies every week. Not one person took the bait. Several reported it to the IT department within minutes of it landing.
That result was not luck, and it was not intelligence. Our people are no smarter than yours. It is simply what happens when staff have been shown what an attack looks like and know exactly what to do the moment something feels off. The strongest firewall in any Nigerian business is a suspicious member of staff who knows where to report. Training builds that, and it costs less than any software you will ever buy.
So teach your people what to look for:
- An address that is almost right. One letter changed, a strange domain, a free email account wearing a corporate name. The eye reads what it expects; teach it to slow down.
- Urgency plus secrecy. "Treat as confidential." "The MD needs this before 2pm." Pressure is the criminal's favourite tool, because hurried people skip checks.
- Any change to payment details, no matter how routine it sounds.
- A link or attachment you were not expecting, even from someone you know, because their mailbox may not be theirs anymore.
- Something small that is simply off. The greeting, the tone, the timing. Staff should be told plainly: if it feels wrong, it probably is, and you will never be criticised for checking.
And teach them what to do the moment a mail feels wrong:
- Do not click, do not reply, and do not forward it around the office asking whether it is genuine. Forwarding a live phishing mail spreads the attack.
- Report it at once to IT or whoever is designated. Speed is the whole game.
- Verify through a channel you already trust. Call the sender on the number you have on file, never the number printed in the email.
- If someone has already clicked, they must be able to say so immediately, without fear. A business where staff hide mistakes turns a small incident into a catastrophe. Reward the report. Never punish the reporter.
Then one rule above all, and make it religion. No change to any beneficiary's bank details is ever acted on from an email alone. It is confirmed by a phone call to a number you already had on file, every single time, no matter how senior the person asking or how urgent the tone. That one habit, costing nothing but two minutes, defeats the most expensive fraud in the country.
Then let process carry its share. Two people on every significant payment, and never the same person raising and approving. Multi-factor authentication on email and banking, because a stolen password should open nothing by itself. Backups that are tested and kept beyond the network's reach, so a ransom note becomes an inconvenience instead of a hostage crisis. And a written plan for the bad day: who is called, what gets disconnected, what is said to customers. The companies that improvise their response pay in hours that become weeks.
When it has already happened
Prevention is most of this article. But some of you will find it on the afternoon it has already gone wrong, so here is the part almost nobody writes down. Recovery is very largely a function of speed. Once funds are split across accounts or converted, tracing becomes slow and partial. The window is measured in hours. And three clocks start at the same moment: the commercial one, in which money can still be frozen, and two regulatory ones that each run for 72 hours whether or not you get a single Naira back.
- Call your bank's fraud desk before anything else, and follow the call with written instruction to attempt a recall. Do not start with an email to your relationship manager. Ask explicitly for a hold to be placed on the receiving account.
- Contact the receiving bank yourself as well. Your bank should do it; do not assume it has. If that account can be restricted before the money is withdrawn, you get it back. If not, you very likely do not.
- Petition the EFCC in writing, with transaction references, the fraudulent email exported with its full headers, and your bank's correspondence. The Commission does trace and restitute. It returned 802.4 million Naira to First Bank in January 2026 after following funds through several accounts. But it works with what it is given, and with how early it is given.
- Preserve everything and change nothing. Do not delete the mail, do not tidy the mailbox, do not let a well-meaning colleague log in to look around. Export the message with full headers. Mailbox audit logs expire, and sooner than you expect.
- Start the regulatory clocks deliberately rather than discovering them later. If personal data was exposed, section 40 of the Data Protection Act requires you to notify the NDPC through its breach portal within 72 hours of becoming aware, not 72 hours from the breach itself, and to tell affected individuals immediately where the risk to them is high. Separately, the Cybercrimes Act requires the incident to be reported to your sectoral response team, also within 72 hours. Neither duty waits for your investigation to finish.
- Tell your other suppliers and customers the same day. If it was your mailbox that was compromised, the identical message is already on its way to everyone you invoice.
Finally, demand of your partners what the law now demands of you. Before any provider touches your transaction data, your payroll or your customers' identity records, ask how it is protected and ask for evidence: ISO 27001 certification, NITDA accreditation, registration with the Nigeria Data Protection Commission. These are not decorations. They are proof that a regulator or an auditor has already looked. Any firm asking to handle your data should be able to say the same, and show it.
The bottom line
The thief no longer breaks in. He logs in, or he simply writes to you.
Cybercrime in Nigeria has become a finance problem wearing a technology costume, and the law has quietly redistributed responsibility for it onto every business that holds money or data, which is to say every business. The ones that treat security like a bank reconciliation, boring, disciplined and non-negotiable, will keep their money, their data and their name.
The rest are paying school fees for everyone else's education.
If you would like to know how your own staff would handle that Friday email, ask us to run the same simulation we ran on ourselves. A week, and you will know.
Frequently asked questions
What is business email compromise?
Business email compromise (BEC) is a fraud in which criminals hijack or imitate a genuine email account, usually a supplier's or an executive's, and use it to redirect payments, most often by sending changed bank account details just before a payment run. It involves no malware, which is why technology alone rarely catches it.
How much are Nigerian businesses losing to fraud?
NIBSS reported 25.85 billion Naira lost to electronic payment fraud in 2025, down from 52.26 billion in 2024, though that earlier figure was inflated by a single 31.1 billion Naira incident. The trend also turned late in the year: FITC recorded 5.25 billion Naira lost by banks in the fourth quarter of 2025 alone, up 576 percent on the quarter before, while the share of attempted fraud value the banks managed to block fell from 85 percent to under 59 percent. Losses suffered by ordinary businesses, such as diverted supplier payments and ransoms, are largely unreported and sit outside all of these statistics.
What should staff do when they suspect a phishing email?
Do not click, reply, download attachments or forward the mail around the office. Report it immediately to IT or the designated person, and verify the request through a channel you already trust, such as a phone number on file. Anyone who has already clicked should say so at once; speed matters far more than blame.
What does the NIMC Act 2026 mean for businesses?
Signed on 26 June 2026 and repealing the 2007 law, the Act rebuilds Nigeria's digital identity framework around the NIN, speaks to how organisations handle NIN-linked data, and is reported to carry fines of up to twenty million Naira for corporate violations and a minimum five-year term for unauthorised access to identity data. Most businesses hold employees' NINs in HR records and customers' NINs in KYC files, so how that data is stored and protected is now a regulatory question, alongside existing duties under the Nigeria Data Protection Act.
What is the single most effective protection against payment fraud?
A verification rule: no change to any beneficiary's bank details is ever acted on from an email alone. The change is confirmed by a phone call to a number already on file, every time, regardless of who is asking or how urgent the request sounds.
What should a business do if it has already paid a fraudulent invoice?
Move within hours, not days. Call your bank's fraud desk and follow up in writing with a recall instruction, asking for a hold on the receiving account. Contact the receiving bank directly yourself. Petition the EFCC in writing with transaction references and the fraudulent email exported with full headers. Preserve the mailbox untouched, since audit logs expire. If personal data was exposed, section 40 of the Nigeria Data Protection Act gives you 72 hours from becoming aware to notify the NDPC through its breach portal, and the Cybercrimes Act separately requires the incident to be reported to your sectoral response team within 72 hours. And warn your other suppliers and customers the same day.
Doftwerks West Africa Limited is the technology practice of Stransact Chartered Accountants. The firm is ISO 27001 certified, NITDA accredited, and holds dual NRS accreditation as a Systems Integrator and Access Point Provider.