E-Business
Ransomware: Microsoft Gives Details of Attack, Decries Govts’ Inaction

Microsoft has stressed the need for urgent collective action to keep people safe online, following the world’s biggest cyberattack at the weekend, sending countries into ‘disaster recovery mode.
In a blog post, ‘Lessons from last week’s cyberattack’, Brad Smith, president and chief legal officer at Microsoft, said the global tech giant takes every single cyberattack on a Windows system seriously.
Starting first in the United Kingdom and Spain, the malicious “WannaCrypt” software quickly spread globally, blocking customers from their data unless they paid a ransom using Bitcoin.
The WannaCrypt exploits used in the attack were drawn from the exploits stolen from the National Security Agency, or NSA, in the United States, Smith said. “That theft was publicly reported earlier this year. A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally. As a result, hospitals, businesses, governments, and computers at homes were affected.
“All of this provides the broadest example yet of so-called “ransomware,” which is only one type of cyberattack”.
He lamented that, unfortunately, consumers and business leaders have become familiar with terms like “zero day” and “phishing” that are part of the broad array of tools used to attack individuals and infrastructure.
“We take every single cyberattack on a Windows system seriously, and we’ve been working around the clock since Friday to help all our customers who have been affected by this incident. This included a decision to take additional steps to assist users with older systems that are no longer supported. Clearly, responding to this attack and helping those affected needs to be our most immediate priority.
“At the same time, it’s already apparent that there will be broader and important lessons from the ‘WannaCrypt’ attack we’ll need to consider to avoid these types of attacks in the future. I see three areas where this event provides an opportunity for Microsoft and the industry to improve.
“As a technology company, we at Microsoft have the first responsibility to address these issues. We increasingly are among the first responders to attacks on the internet. We have more than 3,500 security engineers at the company, and we’re working comprehensively to address cybersecurity threats.
“This includes new security functionality across our entire software platform, including constant updates to our Advanced Threat Protection service to detect and disrupt new cyberattacks. In this instance, this included the development and release of the patch in March, a prompt update on Friday to Windows Defender to detect the WannaCrypt attack, and work by our customer support personnel to help customers afflicted by the attack.
“But as this attack demonstrates, there is no cause for celebration. We’ll assess this attack, ask what lessons we can learn, and apply these to strengthen our capabilities. Working through our Microsoft Threat Intelligence Center (MSTIC) and Digital Crimes Unit, we’ll also share what we learn with law enforcement agencies, governments, and other customers around the world.
“Second, this attack demonstrates the degree to which cybersecurity has become a shared responsibility between tech companies and customers. The fact that so many computers remained vulnerable two months after the release of a patch illustrates this aspect.
“As cybercriminals become more sophisticated, there is simply no way for customers to protect themselves against threats unless they update their systems. Otherwise they’re literally fighting the problems of the present with tools from the past. This attack is a powerful reminder that information technology basics like keeping computers current and patched are a high responsibility for everyone, and it’s something every top executive should support.
“At the same time, we have a clear understanding of the complexity and diversity of today’s IT infrastructure, and how updates can be a formidable practical challenge for many customers. Today, we use robust testing and analytics to enable rapid updates into IT infrastructure, and we are dedicated to developing further steps to help ensure security updates are applied immediately to all IT environments.
“Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world.
“Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen. And this most recent attack represents a completely unintended but disconcerting link between the two most serious forms of cybersecurity threats in the world today – nation-state action and organized criminal action”.
Smith noted that the governments of the world should treat the attack as a wake-up call. “They need to take a different approach and adhere in cyberspace to the same rules applied to weapons in the physical world. We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits.
“This is one reason we called in February for a new ‘Digital Geneva Convention’ to govern these issues, including a new requirement for governments to report vulnerabilities to vendors, rather than stockpile, sell, or exploit them. And it’s why we’ve pledged our support for defending every customer everywhere in the face of cyberattacks, regardless of their nationality. This weekend, whether it’s in London, New York, Moscow, Delhi, Sao Paulo, or Beijing, we’re putting this principle into action and working with customers around the world.
“We should take from this recent attack a renewed determination for more urgent collective action. We need the tech sector, customers, and governments to work together to protect against cybersecurity attacks. More action is needed, and it’s needed now. In this sense, the WannaCrypt attack is a wake-up call for all of us. We recognize our responsibility to help answer this call, and Microsoft is committed to doing its part”.
Brad Smith is Microsoft’s president and chief legal officer. Smith plays a key role in representing the company externally and in leading the company’s work on a number of critical issues including privacy, security, accessibility, environmental sustainability and digital inclusion, among others.
E-Business
HURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria

Human Rights Writers Association of Nigeria (HURIWA) has opposed a bill seeking to compel major global social media companies to establish physical offices in Nigeria.

The rights advocacy group urged the National Assembly to discard the proposed legislation, warning that it could become a tool for censorship and undermine citizens’ constitutional right to freedom of expression, despite being presented as a measure to strengthen Nigeria’s digital economy and improve corporate accountability.
The position was contained in a presentation submitted yesterday by Emmanuel Onwubiko, national coordinator, HURIWA, to the chairman of the Senate Committee on ICT and Cyber Security.
The bill, sponsored by Senator Ned Munir Nwoko, has already passed second reading in the Senate and is before the committee for further legislative consideration.
HURIWA said it carefully reviewed the proposed legislation and concluded that compelling global technology companies to establish offices in Nigeria was unnecessary and potentially counterproductive.
The organisation argued that while the firms generate substantial revenue from Nigeria’s vast digital market, they already engage Nigerians through existing structures, including paying eligible content creators, working with local technology professionals and participating in legal proceedings whenever required.
According to the group, appointing local representatives where necessary would adequately address concerns about engagement with regulators and users without forcing the companies to maintain physical offices.
It also dismissed claims that mandatory country offices would significantly improve consumer complaint resolution, technology transfer or employment generation.
HURIWA maintained that the platforms already have effective feedback mechanisms for resolving users’ complaints and routinely appear before Nigerian courts through their representatives whenever litigation arises.
The group, however, said its greatest concern was the potential for the proposed law to be used as an instrument for restricting freedom of expression.
It argued that establishing local offices could expose global social media companies to pressure from government authorities to remove online content considered critical of those in power.
According to the rights group, the presence of social media companies in Nigeria could become an avenue for authorities to pressure them into abandoning internationally recognised digital rights standards in favour of politically motivated content moderation.
It recalled previous attempts to regulate social media in Nigeria that generated widespread concerns over possible restrictions on free speech, stressing that any legislation affecting the digital space must contain clear safeguards against abuse.
The organisation warned that the proposed law should never become “a backdoor mechanism for government surveillance, arbitrary content removal or political censorship.
E-Business
Nigeria Leads Africa in Online Gambling Regulation – GCI

Nigeria has emerged as one of Africa’s most regulated online gambling markets, even as illegal operators continue to dominate the continent, according to a new report by Gaming Compliance International (GCI).

The report, the first comprehensive assessment of online gambling across all 54 African countries, showed that Africa’s online gambling Gross Gaming Revenue (GGR) reached $23 billion in 2025.
However, only $5.2 billion (23 per cent) was generated by licensed operators, while $17.8 billion (77 per cent) remained in the unregulated market.
In West Africa, total online gambling revenue rose to $4.8 billion in 2025 from $4.3 billion in 2024. Of the 2025 figure, regulated operators accounted for $1.5 billion (31 per cent), while $3.3 billion (69 per cent) flowed to unlicensed platforms, highlighting the region’s persistent enforcement challenges.
Nigeria stood out as the region’s strongest performer, recording the lowest unregulated market share at 56 per cent, compared with the West African average of 69 per cent and the African average of 77 per cent.
The study also found that online gambling participation across Africa increased from 198 million people (13 per cent of the population) in 2024 to 215 million (14 per cent) in 2025.
Despite this growth, GCI estimated that illegal operators deprived African governments of about $3.55 billion in tax revenue in 2025. The number of unlicensed gambling platforms targeting African consumers also rose to 4,129, up from 3,644 in 2024.
Commenting on the findings, Matt Holt, chief executive officer, GCI, said the report provides regulators with the first continent-wide benchmark for strengthening oversight and consumer protection.
Ismail Vali, president, GCI, urged governments to develop competitive and well-regulated markets that encourage consumers to patronise licensed operators, boost public revenue and attract greater investment.
Online gambling in Nigeria is regulated by the Nation Lottery Regulatory Commission.
E-Business
Kaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators

At the height of the Northern Hemisphere tourist season, demand for communications and mobile Internet services rises sharply. Kaspersky’s security experts have uncovered scams that target anyone purchasing mobile connections or SIM cards worldwide.

Fraudsters create counterfeit websites that look like the portals of major regional and international telecom providers to trick users into revealing their phone numbers, personal details or banking information.
Kaspersky is sharing several examples of these fake login pages that mimic legitimate telecom operator sites and giving recommendations on how not to be deceived.
In the first case, scammers exploit the brand name of an international telecommunications company operating services in Asia, Africa and Europe. Fake authentication pages encourage users to put in their phone number and credentials.
While the first example shows the different design, the second scam site closely mimics the original log in page, making it hard for users to tell the difference and spot a fake. Entering authentication or payment data on fraudulent web sites may result in money or data loss and become a reason for more frequent spam and fraudulent calls.
Another example is a scam page which poses as another international communications company, working in North Africa, the Middle East and Southeast Asia. In this scheme scammers encourage users to top up their mobile data/Internet plans by entering their personal information and bank cards details.
Kaspersky experts have also identified a scam when cyber criminals suggest users enter their personal data to check and pay a bill inquiry. Such scam schemes are usually aimed at gaining victims’ personal data for further fraud or account hacking and stealing money.
“Because of the active use of AI, scammers can now create fake pages with ever increasing accuracy and speed, targeting the most popular user interest areas. We constantly see scams revolving around sports events, music concerts, seasonal sales and holidays. Unfortunately, the telecoms industry is no exception.
To keep your data and money safe, be vigilant when purchasing mobile or Internet plans online. Using an eSIM – purchased through an official app – is one way to avoid fake telecom sites, as it eliminates the need to enter personal details on questionable web pages.
If you’re unsure about a site’s legitimacy, search for the brand name directly in a search engine and enable a security solution that blocks phishing links for you,” comments Tatyana Kulikova, cybersecurity expert at Kaspersky.
E-Business3 days agoKaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators
General News3 days agoThree Entrepreneurs Secure ₦5 Million at The Gathering on 100 Pitchathon
E-Financial3 days agoChatPay Unveils Public Waitlist for WhatsApp-Based Banking Platform
News3 days agoAfrican Judges Pledge Support for AfCFTA’s Success
Telecom2 days agoGSMA Supports Abuja Declaration on Meaningful Connectivity for Africa, Joins Partners to Launch ATLAS Umoja
Telecom3 days agoAirtel Africa Backs London Listing
Telecom3 days agoGSMA Says High Smartphone Costs Threatens Africa’s AI Future
News3 days agoHow 21 Former Almajiri Children Learned to Build Computers and Drones in Months














