Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Leaks » Nigeria Faces Major Privacy Scare After Hacker Claims 35GB NSIPA Data Leak

Nigeria Faces Major Privacy Scare After Hacker Claims 35GB NSIPA Data Leak

Last updated:October 2, 2026
Human Written
  • A threat actor on a dark web forum claims to have posted over 35GB of data from Nigeria’s NSIPA portal.

  • The alleged files reportedly hold names, NIN, BVN, banking details, and GPS data for millions of Nigerians.

  • No cybersecurity researcher has confirmed the data’s origin yet, and NSIPA has not responded publicly.

Hacker Claims 35GB NSIPA Data Leak Affecting Millions of Nigerians

A threat-intelligence account has flagged a fresh claim making the rounds on the dark web. The post says someone leaked a huge file tied to Nigeria’s social welfare system.

The account, known on X as Dark Web Intelligence, first shared the claim on October 1. The account said a forum user claims to have published over 35GB of data. The actor linked the files to the National Social Investment Programme Agency, or NSIPA. The post says the data covers millions of citizens enrolled in government support programmes.

So far, nobody outside the forum post has confirmed this. No independent researcher has checked where the files truly came from. Nobody has confirmed how old the data is either, or whether it is even real.

Details of the Alleged Leak

According to the forum post, the files may hold basic details like names, gender, and birth dates. The claim also lists phone numbers, home addresses, and GPS locations tied to beneficiaries.

Banking details sit in the mix too. The actor says the dump includes National Identification Numbers, Bank Verification Numbers, and loan records. That combination worries security watchers the most.

Identity numbers plus banking details plus location data create a dangerous bundle. A criminal with all three can impersonate a real person with ease. They could also target someone’s bank account directly.

Still, none of this has passed independent review. A forum listing alone does not prove a breach happened. Verification would need real data samples or a direct statement from NSIPA.

NSIPA Holds the Kind of Data Described

NSIPA runs some of Nigeria’s biggest social welfare programmes. The agency’s own site says it serves millions of Nigerians through several schemes.

One of those tools is the National Social Register. It pulls in NIN and BVN numbers from enrolled citizens. The agency’s FarmerMoni programme also collects names, phone numbers, home details, and partial BVN digits from beneficiaries.

This matters for one reason. The type of data in the alleged dump does match what NSIPA genuinely stores. That fact alone does not confirm a breach. But it means the claim is not far-fetched on paper.

Large government welfare databases hold rich personal records by design. That makes them appealing targets for anyone chasing stolen data to sell.

A Familiar Pattern Around Nigerian Welfare Records

This is not the first time a Nigerian social programme database drew attention for alleged exposure. In 2025, reports surfaced about leaked credentials tied to NASIMS, a related platform used to coordinate social investment programmes under a separate federal ministry.

Security researchers tracking Nigerian cyber threats noted several dark web posts referencing social investment portals throughout the year. Other Nigerian government agencies have also faced confirmed data-breach incidents, including the Corporate Affairs Commission breach that exposed sensitive records. Those posts involved different actors and different claimed datasets each time.

The new NSIPA claim should not be treated as the same event as any earlier one. Different platforms and different actors are involved. But the pattern says something important. Nigeria’s welfare databases keep drawing criminal interest, confirmed or not.

NIN and BVN numbers, paired with banking and location data, give bad actors nearly everything needed for fraud. Past incidents show these records are a real and recurring target.

For now, treat the October 1 claim as an unverified report. It is not proof that NSIPA’s systems were actually breached. Confirming it would require authentic data samples, technical evidence, or an official statement.

Neither NSIPA nor any Nigerian government agency has responded publicly as of this report. If the alleged files are genuine, millions of enrolled Nigerians could face real risk. Until researchers examine the data directly, the full picture stays unclear.

Anyone enrolled in NSIPA programmes, including TraderMoni, FarmerMoni, and N-Power, should watch their bank accounts closely. Report any strange activity to your bank right away. Avoid sharing your NIN, BVN, or personal details with unknown callers or sites, even if they claim to represent NSIPA.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.