News
Uber Breaches: Sophos Advices Organisations To Be More Security Conscious

By peter oluka
Following reports of massive data breaches suffered, but covered by Uber in 2016, Sophos has advised corporation to be more security conscious.
A report by Bloomberg indicates the data of 57,000,000 drivers and customers was stolen, after which Uber not only kept the breach secret from the victims, but also paid the hackers $100,000 to “delete the data [and] keep quiet”.
Apparently, Uber’s security chief, Joe Sullivan, lured to Uber from Facebook in 2015, has been sacked in the fallout, according report.
Bloomberg quotes Uber as follows:
Compromised data from the October 2016 attack included names, email addresses and phone numbers of 50 million Uber riders around the world… The personal information of about 7 million drivers was accessed as well, including some 600,000 US driver’s license numbers. No Social Security numbers, credit card information, trip location details or other data were taken.
Going by a report by Nakedsecurity, It seems that Uber’s programmers uploaded security credentials to a GitHub repository – GitHub is a place where you are supposed to store source code, not the keys to the castle! – where the hackers stumbled across them.
From there, the crooks were able to get into Uber servers hosted on Amazon, and from there to access the personal information involved in the breach.
If this sounds terribly familiar, Uber suffered a breach with a similar cause just over three years ago, an intrusion that was discovered in May 2014 but not disclosed until February 2015.
Reliable details of what data was stolen this time round are not yet available.
As mentioned above, driving licence details were acquired by the hackers, meaning that Uber certainly ought to have declared the breach promptly, because sensitive data was involved.
Uber’s claim that customer details such as credit card data and social security numbers were not involved in the heist is a slight silver lining, but how many customers are willing to believe Uber at this point is anybody’s guess.
What to do?
There’s so much still untold in this story that the only sensible recommendation we can make to Uber customers is: “Keep your eyes open for what comes out next.”
If you’re a programmer, repeat these words to anyone who will listen: “GitHub is for code, not for security keys!”
As our friend and colleague Chester Wisniwewski bluntly put it: Uber’s breach demonstrates once again how developers need to take security seriously and never embed or deploy access tokens and keys in source code repositories. I would say it feels like I have watched this movie before, but usually organisations aren’t caught while actively involved in a cover-up as well. Putting the drama aside and the potential impacts from the upcoming GDPR enforcement in Europe, this is just another careless development team with shared credentials and poor security practices. Sadly, this is common more often than not in “agile” development environments, especially in high-growth technology startups.
Commenting on the report, Sophos Principal Research Scientist Chester Wisniewski, believes,
“Uber’s breach demonstrates once again how developers need to take security seriously and never embed or deploy access tokens and keys in source code repositories. I would say it feels like I have watched this movie before, but usually organizations aren’t caught while actively involved in a cover-up. Putting the drama aside and the potential impacts from the upcoming GDPR enforcement, this is just another development team with poor security practices that has shared credentials. Sadly, this is common more often than not in agile development environments.”
From his perspective, Sophos Cyber Security Advisor, James Lyne says: “Uber isn’t the only and won’t be the last company to hide a data breach or cyberattack. Not notifying consumers puts them at greater risk of being victimized with fraud. It’s for precisely this reason that many countries are driving to regulations with mandatory breach disclosure.”
For Uber customers and drivers, Sophos advises that they monitor their credit scores and keep their eyes peeled for additional information on what was stolen.
News
NPC Opens Nationwide Digital Birth, Death Registration Platform

National Population Commission (NPC) has commenced the nationwide digital registration of births and deaths under the Electronic Civil Registration and Vital Statistics (E-CRVS) system to strengthen legal identity management and improve demographic data.

Speaking at a press briefing in Lokoja on Tuesday, Mr Afolabi Yori, federal commissioner representing Kogi, said the initiative became operational nationwide on July 1, through the VitalReg platform.
Yori described the development as a landmark in Nigeria’s civil registration system, noting that it would modernise birth and death registration through a technology-driven platform that meets international standards.
He said the digital platform would improve service delivery, strengthen data integrity and ensure that every birth and death occurring in Nigeria was accurately documented and securely stored.
According to him, civil registration is more than an administrative process, as it provides reliable statistics that support public policy formulation, resource allocation and national development planning.
“Nigeria records an estimated five million births annually, yet millions of births and deaths remain unregistered.
“Birth registration coverage currently stands at about 57 per cent nationwide, while death registration remains below 20 per cent,” he said.
The commissioner said that the commission had established 4,011 functional registration centres across the country’s 774 local government areas and was working to expand the number to about 8,000.
He added that the commission was strengthening collaboration with stakeholders to improve the capacity of registration personnel and ensure prompt documentation of vital events through the VitalReg platform.
Yori said the platform would provide faster registration services, 24-hour online access, digital certificate issuance where applicable, and reduce paperwork, waiting time and unnecessary travel.
He disclosed that the platform was being operated under a Public-Private Partnership with Barnks-forte Technologies Ltd. as the commission’s technical partner to ensure system availability, cybersecurity and continuous technological improvement.
He called on parents, healthcare institutions, traditional and religious leaders, civil society organisations, development partners and the media to support the initiative by encouraging the prompt registration of births and deaths.
Earlier, Samuel Omonakpeme, director in Kogi, NPC State, described the commencement of the digital registration system as another milestone in efforts to strengthen Nigeria’s Civil Registration and Vital Statistics system.
Omonakpeme stated that the initiative aligns with the Federal Government’s digital transformation agenda and the Sustainable Development Goals, particularly Goal 16.9, which seeks to provide legal identity for all.
He appreciated the Federal Government, the leadership of the commission, UNICEF and other development partners for supporting the implementation of the initiative.
The state director also urged parents, guardians, health institutions, community leaders, religious organisations and the media to mobilise public support for the timely registration of all births and deaths.
The News Agency of Nigeria (NAN) reported that ICT personnel of the commission, led by Ehimoni Kolawole, conducted a live demonstration of the digital birth registration process using the VitalReg platform.
The demonstration showed that the registration process captures the biodata of both parents, while at least one parent must possess a valid National Identification Number (NIN) to complete the registration of a newborn.
News
YEDC Warns Customers, Says 20 Percent Electricity Bonus is Scam

Yola Electricity Distribution Company (YEDC) has alerted its customers to a fraudulent message circulating on social media, falsely claiming that electricity consumers can receive an additional 20 per cent bonus units when recharging their prepaid meters through unofficial channels.

In a statement issued by the company’s management on Monday, YEDC described the claim as false and urged customers to disregard the misleading information, stressing that it did not originate from the company.
According to the statement, YEDC does not offer bonus electricity units through individuals, agents, personal bank accounts, phone numbers, or social media contacts.
The company advised customers to purchase electricity tokens only through approved cashless payment platforms, including the YEDC Pay App, OPay, Interswitch, and other authorised vending channels, or to visit the nearest YEDC office for assistance.
YEDC also cautioned customers against sharing their meter details or personal information, or making payments to unauthorised persons claiming to represent the company.
The company further urged customers to rely exclusively on information disseminated through its official communication channels to avoid falling victim to fraud.
The management thanked customers for their continued cooperation and reaffirmed its commitment to serving them.
News
PFIPC Probe: Dollar, Pounds Accounts of Fake Agency Inactive – CBN

Central Bank of Nigeria (CBN) has disclosed that two foreign currency accounts opened in connection with the controversial Presidential Foreign Investment Promotion Council (PFIPC) have remained inactive since their creation, with no funds deposited and no transactions recorded.

The revelation emerged on Monday during the ongoing investigation by the House of Representatives Ad-hoc Committee probing the circumstances surrounding the establishment and operations of the council.
Lawmakers are investigating allegations that the PFIPC was created and operated without a valid legal framework and outside the established procedures required for government agencies and institutions.
Appearing before the committee, representatives of both the Central Bank of Nigeria and the Office of the Head of the Civil Service of the Federation (OHCSF) distanced their institutions from the establishment of the council.
The Office of the Head of the Civil Service of the Federation stated that it neither created the council nor possessed the constitutional authority to establish federal agencies.
Representing the office, officials explained that the OHCSF is only responsible for approving administrative structures of government agencies after all necessary requirements have been fulfilled.
According to the office, records showed that the council submitted a request on August 6, 2025, seeking approval for its organisational structure.
However, the application was not approved because the required supporting documents were not attached.
The committee heard that despite the rejection of the request, officials linked to the Presidential Economic Advisory Council (PEAC)/PFIPC later appeared during the 2025 manpower budget defence exercise and sought approval for staffing and recruitment arrangements.
The office disclosed that the council informed government officials that its activities were being carried out largely through personnel seconded or deployed from other institutions.
Lawmakers were told that the council requested approval for a total of 314 positions. The figure consisted of 14 existing officers and an additional 300 proposed positions.
The Office of the Head of the Civil Service further revealed that concerns later arose regarding documents presented by the council as evidence of its legal backing.
Officials told the committee that upon examination, the documents failed to display essential features expected of an enabling law or valid legal instrument establishing a government body.
Mrs. Didi Esther Walson-Jack, head of the Civil Service of the Federation, also rejected claims that her office deployed civil servants to work for the council.
She maintained that the office did not assign personnel to the body and did not provide office accommodation for its operations.
According to her, matters relating to the creation, supervision and oversight of government agencies fall under the responsibilities of other relevant institutions, including the Office of the Secretary to the Government of the Federation.
The Central Bank of Nigeria also provided details regarding accounts linked to the council.Nigerian current events
Hamisu Abdullahi, director at the apex bank, who represented the CBN Governor before the committee, explained that the bank opened two foreign currency accounts following a formal request from the Office of the Accountant-General of the Federation.
He told lawmakers that the request was received on July 30, 2025, and instructed the bank to create a United States dollar domiciliary account and a Pound Sterling domiciliary account.
Abdullahi stressed that the CBN only opens accounts for government agencies after receiving official authorisation from the Accountant-General’s office.
However, he disclosed that the accounts never became operational because the council failed to provide authorised signatories required for activation.
As a result, both accounts remained dormant from the day they were opened.
He informed the committee that neither account had received deposits nor processed withdrawals. The accounts also recorded no foreign exchange allocations, remittances, inflows or outflows.Governor election news
According to him, the balances in both accounts remain at zero.
The CBN official further stated that the council did not engage directly with the apex bank regarding the management or operation of the accounts after they were created.
Following the submissions, members of the committee demanded more information as part of efforts to determine the full scope of the council’s activities.
Hon. Abdulmalik Danga, chairman of the committee, directed the Central Bank to submit comprehensive records relating to both the Presidential Foreign Investment Promotion Council and the Presidential Economic Advisory Council.
The committee requested details covering the opening of the accounts, their operational history and any information connected to related banking activities.
Lawmakers also instructed the CBN to work with commercial banks to identify and provide records of any accounts linked to the entities under investigation.
However, the committee is expected to continue its hearings as more government agencies and officials appear before lawmakers to provide explanations on the controversial council and the circumstances surrounding its operations.
News2 days agoAdebutu, PDP Chieftain Accuses Nigerian Governors of Embezzling LG Allocations
E-Financial2 days agoNDIC Urges Youths to Shun Ponzi Schemes, Embrace Savings
E-Financial2 days agoAccess Holdings Sells 7.44% Stake in Ghana Unit
News2 days agoNIMASA Unveils Accelerator Scheme to Drive Innovation, Sustainable Growth
E-Business2 days agoSERAP to Sue NASS over Bill Empowering NDPC to Regulate Social Media
E-Financial2 days agoNRS Issues July 31 Deadline for e-Invoicing Compliance
News2 days agoICPC Secures Final Forfeiture of N941m Linked to IPPIS Fraud
News2 days agoeBusinessLife Advocates Greater Support for Girls in ICT as Students Showcase AI Innovations




















