Connect with us

E-Business

Millions of Nigerians @ Risk as NASIMS Leaks over 23m FG Records

Published

on

Kindly share this post

National Social Investment Management System (NASIMS) has leaked millions of federal government records in a major system oversight  which could be exploited by cyber criminals.

Millions of Nigerians @ Risk as NASIMS Leaks over 23m FG Records

NASIMS is the central management platform for the administration and coordination of Social Investment Programmes under the Federal Ministry of Humanitarian Affairs, Disaster Management and Social Development

The major leak exposed everything from home addresses to work backgrounds of  tens of millions of Nigerians

According to the Cybernews research team, the exposed AWS S3 bucket stored over 23 million files, including passports, birth certificates, educational certificates, and N-Power-submitted applications.

N-Power is a social welfare scheme to combat youth unemployment. N-Power applicants use the NASIMS platform to apply to take part in the program.

Advertisement

“The implications of exposing 23 million application-related documents of N-Power candidates could be severe for the affected individuals. Identity theft, fraud, and targeted phishing attacks are the most likely risks for the leaks’ victims,” Cybernews research team said.

According to Cybernews research team, “Worryingly, the instance remains open to the public, even after multiple attempts to reach NASIMS administrators and relevant authorities in Nigeria. We have also reached out to the ministry behind NASIMS for a comment and will update the article once we receive a reply”

What data leaked, and why is it dangerous?

Documents stored on the exposed instance include different sets of citizens’ data. However, the team surmised that the leak revealed:

Full names

Advertisement

Dates of birth

Places of birth

National Identification Number (NIN)

Email addresses

Phone numbers

Advertisement

Home addresses

Work background

Education background

Exposing sensitive and personal data poses numerous threats to the individuals involved.

Most pressingly, attackers might utilize the information for identity theft and various fraud schemes. For one, malicious actors could try opening fraudulent bank accounts or use stolen identities for illicit activities, masking their own IDs.

Advertisement

“Another way attackers can exploit similar data sets is by exploiting the identities to access financial services or execute unauthorized transactions, potentially causing long-term financial damage to the victims,” Cybernews research team said.

Cybercrooks could also exploit the leak to carry out targeted phishing and social engineering attacks.

For example, malicious actors could attempt to masquerade as legitimate organizations in order to deceive individuals into providing even more sensitive data – such as login credentials – or downloading malware.

“The implications of exposing 23 million application-related documents of N-Power candidates could be severe for the affected individuals. Identity theft, fraud, and targeted phishing attacks are the most likely risks for the leaks’ victims.”

The leaks’ nature empowers attackers to craft spear-phishing attacks custom-made for each individual or group of individuals. Such attacks are hard to distinguish, as they often include targets’ personal details and other data points meant to lure in unsuspecting victims.

Advertisement

 

“Criminals could use the exposed data to offer fake job opportunities or promise assistance with the N-Power application process in exchange for payments or additional personal information, exploiting the candidates’ vulnerabilities,” the team explained.

Additional attack vectors involve risks to victims’ physical safety. For example, criminals could exploit leaked data to locate and target victims for various malicious purposes, such as stalking, harassment, or even burglary.

To avoid similar leaks in the future, Cybernews research team advised:

Change the access controls to restrict public access and secure the bucket. Update permissions to ensure that only authorized users or services have the necessary access.

Advertisement

Monitor retrospectively access logs to assess whether the bucket has been accessed by unauthorized actors.

Enable server-side encryption to protect data at rest.

Use AWS Key Management Service (KMS) to manage encryption keys securely.

Implement SSL/TLS for data in transit to ensure secure communication.

Consider implementing security’s best practices, such as regular audits, automated security checks, and employee training.

Advertisement

 

 

 

 

 

Advertisement

 

 

 

 

 

Advertisement

 

 

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

UNN to Partner Firm on AI, Smart Mobility Innovation Centre

Published

on

Kindly share this post

The University of Nigeria (UNN) is set to partner with The Roxettes Group to establish a research and innovation centre focused on artificial intelligence (AI), smart and green mobility, and digital technologies, in a move aimed at strengthening research, entrepreneurship and technology-driven industrial development.

Chairman of The Roxettes Group, Arc. Dr. Kaycee Orji-Kelechi, announced the proposed partnership while delivering his acceptance speech after receiving an Honorary Doctor of Business Administration (Honoris Causa) during the university’s convocation ceremony.

The proposed facility, to be known as the Dr. Kaycee Orji Centre for Artificial Intelligence, Smart/Green Mobility and Digital Innovation, is expected to provide a platform for research, innovation and collaboration between academia and industry, with a focus on developing commercially viable solutions to local and continental challenges.

Orji-Kelechi said the initiative was conceived as a long-term investment in human capital and technological advancement rather than simply another physical infrastructure project.

He said the vision was to position the University of Nigeria among Africa’s leading institutions in artificial intelligence, smart mobility and digital innovation through research, entrepreneurship and technology development.

Advertisement

According to him, the centre will house five specialised laboratories covering artificial intelligence and machine learning, smart and green mobility, robotics and the Internet of Things (IoT), digital finance and financial technology, as well as cloud computing and advanced data centre technologies.

He also announced plans for the proposed Kaycee Orji Founders Innovation Challenge, an annual programme intended to identify, mentor and support innovative ideas from students, researchers and academic staff with the potential to become scalable businesses.

“Every student of this University should know that a great idea conceived in a classroom should have a pathway to becoming a patent, a startup, a global enterprise, and a solution that transforms society,” he said.

Orji-Kelechi disclosed that preliminary conceptual work on the project had commenced, with architectural and engineering designs being prepared by K.KH Contractors Ltd., a subsidiary of The Roxettes Group.

He added that discussions with the university would begin on identifying a suitable site for the project, while a comprehensive proposal containing architectural drawings, engineering designs and an implementation framework would be submitted after completion of the design phase.

Advertisement

Reflecting on his career, Orji-Kelechi said Africa must move beyond consuming innovation to creating it through investment in manufacturing, technology and entrepreneurship.

“We have pursued one simple vision: that Nigeria and Africa must move from consumption to production; from importing innovation to creating it; and from waiting for opportunities to building them,” he said.

He urged graduating students to see their education as a foundation for solving societal challenges through innovation, leadership and enterprise, adding that he remained committed to promoting industrial development, youth empowerment and sustainable economic growth.

The proposed collaboration forms part of broader efforts to strengthen university-industry partnerships, which are increasingly seen as critical to improving research commercialisation, innovation capacity and technology-led economic development in Nigeria.

Advertisement

Kindly share this post
Continue Reading

E-Business

NPC Opens 131 Births, Deaths Registration Centres in Anambra

Published

on

Kindly share this post

National Population Commission (NPC) has announced commencement of full digital registration of births and deaths through the VitalReg platform, which became operational nationwide on July 1, 2026.

NPC Opens 131 Births, Deaths Registration Centres in Anambra

Chidi Ezeoke, federal commissioner representing Anambra, disclosed this in Awka during a press conference to announce commencement of full digital birth and death registration under the Electronic Civil Registration and Vital Statistics (E-CRVS) system and the marking of World Population Day commemorated every July 11.

He revealed that a total of 131 registration centres had been opened in the 21 local government headquarters and several communities in the state, adding that more centres would be opened later.

Ezeoke described the initiative as a major milestone in Nigeria’s Civil Registration and Vital Statistics (CRVS) system, to ensure every birth and death in the country was captured through a digitally enabled registration platform.

“It builds on the launch of the E-CRVS system and the inauguration of the National Coordination Committee on Civil Registration and Vital Statistics by President Bola Tinubu on Nov. 8, 2023.

Advertisement

“A total of 4,011 functional registration centres has been established across the 774 LGAs of the federation and the commission iswas working to expand the number to about 8,000.

“In Anambra, 131 registration centres have been opened in the 21 local government headquarters and several communities. More centres had been proposed for the state,” he said.

According to the Commissioner, the VitalReg platform would provide faster registration services, 24-hour online access, digital certificate issuance where applicable, reduced paperwork and waiting time, improved data validation and a more secure national CRVS database.

While noting that the platform would serve as a foundational database to support other national data systems and strengthen interoperability across Nigeria’s digital identity ecosystem, Ezeoke urged Nigerians and other stakeholders to support the initiative by ensuring prompt registration of all births and deaths.

Speaking on the 2026 World Population Day themed, “Realising the Hopes and Aspirations of Young People – Today and for the Future”, the Commissioner called for greater investment in education, healthcare, skills development, decent employment opportunities and youth participation in governance for sustainable national development.

Advertisement

Earlier, Mr Obiakonwa Okagwu, state director, NPC, said the occasion served as a reminder of great opportunities provided to harness young people’s capabilities, which he said would shape the future of the country when adequately harnessed.

He called on residents to take registration of births and deaths as national responsibility, just as he urged the media to take the message on civil registration to all parts of the State.

Kindly share this post
Continue Reading

E-Business

Report Says Cybercriminals Deploy Malware to Hijack Crypto Wallets, Monitor Browsers Telegram

Published

on

Kindly share this post

Cybersecurity researchers at Kaspersky have uncovered a sophisticated malware framework, dubbed OkoBot, that is targeting cryptocurrency users by stealing wallet recovery phrases, browser credentials and other sensitive information through a multi-stage attack campaign spanning more than 25 countries.

Report Says Cybercriminals Deploy Malware to Hijack Crypto Wallets, Monitor Browsers Telegram

The researchers said the malware, active since April 2025, employs more than 20 malicious payloads and has evolved into an advanced cybercrime platform focused on compromising digital asset holders. According to Kaspersky’s Global Research and Analysis Team (GReAT), the campaign remains active and has already affected hundreds of users worldwide.

Kaspersky disclosed that one of the framework’s most dangerous components, known as SeedHunter, injects malicious code into legitimate cryptocurrency wallet applications, including Ledger Wallet, Ledger Live and Trezor Suite, before displaying fake recovery phrase prompts designed to trick victims into surrendering their seed phrases.

The security firm explained that once attackers obtain a victim’s recovery phrase, they gain complete control over the cryptocurrency wallet, enabling them to transfer digital assets with virtually no chance of recovery.

Commenting on the discovery,  Dmitry Galov, security researcher at Kaspersky’s GReAT, said.

Advertisement

“This campaign has been running for more than a year and remains active. OkoBot is not just a single piece of malware but an extensible framework built primarily to compromise cryptocurrency users.”

Galov added that the malware is continuously maintained and enhanced, underscoring the attackers’ long-term focus on financial theft.

According to Kaspersky, victims are typically infected through ClickFix phishing attacks or malicious GitHub repositories masquerading as legitimate software downloads. In one instance, a fake Microsoft SQL Server Management Studio repository secretly installed a trojanized version of the Audacity audio editor embedded with malicious code.

Following the initial compromise, the attackers deploy a PowerShell downloader called TookPS,which establishes an encrypted SSH connection to attacker-controlled infrastructure.

The malware then harvests browser cookies, wallet files, stored credentials and system information before downloading additional malicious modules.

Advertisement

Among the additional payloads is OkoSpyware which monitors more than 100 applications, which includes cryptocurrency wallets and password managers—records user activity and captures keystrokes and video of application windows. Another module silently installs malicious browser extensions capable of stealing financial information and authentication tokens.

However, Kaspersky’s telemetry indicates that the largest concentrations of victims have been recorded in Brazil, Vietnam, Canada, Mexico and Türkiye, although the malware campaign has spread to users across more than 25 countries.

The cybersecurity firm advised cryptocurrency users never to enter wallet recovery phrases into prompts displayed by desktop applications or websites unless they have independently verified their authenticity.

Furthermore,It also urged users to download wallet software exclusively from official sources, enable multi-layered endpoint protection, and remain cautious of software offered through unofficial repositories or phishing websites.

Kaspersky noted that while hardware wallets themselves remain secure, attackers are increasingly exploiting the software that accompanies them, making user awareness a critical line of defence against evolving cryptocurrency-focused cyber threats.

Advertisement

 

 

Kindly share this post
Continue Reading

Trending