Nigeria loses $3bn to cybercrime in six years amid digital economy push
A $3 billion loss to cybercrime over six years underscores the systemic risks facing Nigeria’s rapid digital expansion, prompting a push for unified security standards across government agencies.
Cybercrime has cost Nigeria more than $3 billion between 2019 and 2025, a financial toll that highlights the vulnerabilities accompanying the country's rapid digital expansion. The figure, drawn from the Deloitte Nigeria Cybersecurity Outlook 2026, was disclosed on Tuesday by the National Information Technology Development Agency (NITDA).
For investors and corporates operating in the region, the scale of these losses signals material operational risk. As Nigeria accelerates the digitisation of public services to grow its digital economy, it is simultaneously expanding its attack surface. The United Nations Office on Drugs and Crime ranks Nigeria among the three most targeted nations for cybercrime in Africa.
NITDA Director-General Kashifu Inuwa warned that the threat landscape has shifted from isolated opportunistic hacking to highly organized operations. “The threat we face is no longer the work of the lone opportunist. We are contending with organised, financially motivated, and at times politically driven actors,” he said.
A core concern for market participants is the interconnected nature of government infrastructure. Inuwa stressed that vulnerabilities in a single ministry can compromise the wider network. “These actors do not respect boundaries between our agencies. A weakness in one MDA becomes a doorway into another, and this is why defence cannot be fragmented,” he said.
The risks are not merely theoretical. Workshop facilitator Hamza Lateef noted that recent incidents have involved ransomware, Advanced Persistent Threat groups, and foreign actors attempting to disrupt critical online portals. Digital activists protesting government policies have also targeted public infrastructure.
To mitigate these risks, NITDA is pushing for a centralized defence strategy. The agency is using its Computer Emergency Readiness and Response Team to bolster incident response capabilities, while workshop participants are currently reviewing draft Regulatory Guidelines for Government Information Security Management.
These upcoming regulations will likely increase compliance