2 min read

Digital Growth, Deepening Exposure: Nigeria's Race to Regulate a Rising Cybercrime Economy- 263

Digital Growth, Deepening Exposure: Nigeria's Race to Regulate a Rising Cybercrime Economy- 263

July 18, 2o26

Nigeria's fraud statistics tell an uncomfortable story about the relationship between reported incident volume and actual harm: fraud reports fell nearly 46 percent between 2021 and 2025, yet losses over the same period climbed, as the country's cybercriminal ecosystem shifted from high-volume, low-value schemes toward fewer, more lucrative operations. The paradox sits at the center of the West African nation's attempt to regulate a digital economy that is expanding faster than its institutional capacity to secure it.

The scale of the exposure is striking on its own terms. Nigeria trails only Angola as Africa's most-attacked country, absorbing an average of 4,361 attempted attacks per organization per week as of June, roughly double the global average and, according to Check Point's regional security consulting lead, a figure that has stayed persistently elevated rather than trending in any clear direction over the past year. Digital-payment fraud losses rose from ₦17.67 billion in 2023 to ₦25.85 billion in 2025, with a single 2024 incident alone accounting for ₦31.1 billion in damages — a pattern regulators attribute partly to insider involvement and the continued effectiveness of SIM-swap fraud, account compromise, and phishing against a population where digital-security awareness has not kept pace with digital-services adoption.

a chart showing the core paradox: fraud incidents declining while losses rise, 2021–2025

Nigeria's regulatory response reflects a now-familiar template: the National Information Technology Development Agency is finalizing a cybersecurity framework mandating incident reporting, minimum cybersecurity investment, and public-private intelligence sharing, building on a 2023 Data Protection Act that already requires 72-hour breach notification. What the country's experience underscores, though, is a gap that legislation alone cannot close — enforcement capacity and compliance culture lag well behind the law itself, with incident reporting actually declining 34 percent in the final quarter of 2025 even as the underlying threat activity remained constant. As one regional CISO adviser put it, closing that gap, not writing further rules, is what will determine whether Nigeria's digital transformation outpaces the cybercriminal economy attached to it, or continues to fund it.