LegalDoc
Courts & Disputes

Cybercrime

Cybercrime covers offences committed using computers and networks, from unauthorised access and identity theft to online fraud. In Nigeria it is governed by the Cybercrimes Act 2015, as amended.

Create a Privacy Policyfrom ₦5,000, ready in minutes
C

What cybercrime means

Cybercrime is criminal conduct carried out through computers and networks.

Some of it is old crime with new tools. Fraud, theft, extortion and harassment did not change in nature because they moved online. Some of it is genuinely new: unauthorised access to systems, interference with data, and attacks on infrastructure.

Nigeria addresses both through the Cybercrimes (Prohibition, Prevention etc.) Act 2015, amended in 2024. It creates offences, imposes obligations on service providers and financial institutions, and establishes coordination arrangements for enforcement.

The offences include unlawful access to a computer system, unlawful interception of communications, system interference, computer related fraud and forgery, identity theft and impersonation, cybersquatting, child pornography, and cyberstalking.

How it is used

For individuals, the most common encounters are fraud and impersonation.

A cloned social media account soliciting money from friends. A phishing message imitating a bank. Unauthorised transfers from an account. A business email compromise, where an invoice is intercepted and account details changed. Sextortion and blackmail using intimate images.

Reporting routes exist. The Economic and Financial Crimes Commission handles financial cybercrime, the Nigeria Police Force has cybercrime units, and banks have their own fraud desks that must be contacted immediately when money has moved, because speed determines whether funds can be recalled.

For businesses, the Act creates obligations rather than only protections. Financial institutions carry duties around verifying customers and reporting. Service providers have duties around retaining traffic data and assisting law enforcement on lawful request. Businesses handling payment card data have specific obligations.

Evidence matters enormously and degrades quickly. Screenshots with visible timestamps, transaction references, headers of suspicious emails, and the account details used should be preserved immediately.

Key features

  • Governed by the Cybercrimes (Prohibition, Prevention etc.) Act 2015, amended 2024
  • Covers unlawful access, interception, system interference, fraud and identity theft
  • Imposes obligations on financial institutions and service providers
  • Enforced principally by the EFCC and the police, with bank fraud desks involved early
  • Cyberstalking provisions were narrowed by the 2024 amendment after criticism
  • Runs alongside data protection obligations rather than replacing them

How this works in Nigeria

Section 24, the cyberstalking provision, is the part of the Act that generated the most controversy.

As originally drafted it was broad enough to capture messages that were merely offensive or annoying, and it was used against journalists, critics and people posting complaints online. Courts and civil society challenged it, and the 2024 amendment narrowed its scope. Anyone facing a complaint under it should take advice on the current wording rather than the version they may have read about.

The other Nigerian reality is business email compromise, which has become the most damaging category for companies. An email account is accessed, an invoice is intercepted, bank details are altered, and payment goes to the fraudster. The protections are procedural rather than legal: verify any change of bank details by telephone using a number you already hold, require dual authorisation on payments above a threshold, and enable multi factor authentication on email.

Data protection sits alongside all of this. A cyber incident involving personal data is also a personal data breach under the Nigeria Data Protection Act, which requires notification to the Commission within seventy two hours. Businesses frequently handle the security incident and forget the regulatory obligation.

Cybercrime vs data breach vs civil claim

One incident often produces three separate processes, and businesses tend to run only one.

A cybercrime is prosecuted by the state. You report it to the EFCC or the police, and the outcome is punishment of the offender rather than compensation to you.

A personal data breach is a regulatory matter. Where personal data was compromised, the Nigeria Data Protection Act requires notification to the Commission within seventy two hours and, where the risk is high, to the individuals affected. That obligation exists whether or not anybody is prosecuted.

A civil claim is yours to bring. Against the fraudster if identifiable and worth suing, or against a party whose negligence enabled the loss, such as a service provider that failed to apply agreed controls.

After an incident, handle all three: report it, notify if personal data was involved, and take advice on recovery.

Limits and risks

Recovery is the hardest part. Money moved through several accounts and withdrawn quickly is very difficult to trace, and speed of reporting to the bank is usually the only thing that matters.

Cross border offences complicate matters further. Where the offender is outside Nigeria, prosecution depends on cooperation that may not be forthcoming.

Enforcement capacity is finite relative to the volume of reports, so individual cases involving modest sums may receive limited attention.

And the law does not prevent anything. The practical protections for a business are operational: multi factor authentication, verified payment procedures, staff awareness, and controls on who can change bank details.

Worth knowing

Verify any change of bank details by telephone, using a number you already hold rather than one in the email. Business email compromise is the most costly cyber loss Nigerian companies suffer, and this single procedure prevents almost all of it.

Questions people ask

What law covers cybercrime in Nigeria?

The Cybercrimes (Prohibition, Prevention etc.) Act 2015, amended in 2024. It creates offences including unlawful access, interception, system interference, computer related fraud, identity theft and cyberstalking.

Where do I report cybercrime in Nigeria?

The Economic and Financial Crimes Commission for financial cybercrime, and the Nigeria Police Force cybercrime units. Where money has moved, contact your bank's fraud desk immediately, because speed determines whether funds can be recalled.

Can I be arrested for a social media post?

The cyberstalking provision has been used that way, which drew sustained criticism, and its scope was narrowed by the 2024 amendment. Anyone facing such a complaint should take advice on the current wording.

What is business email compromise?

A fraud where an email account is accessed, an invoice intercepted and bank details altered so payment goes to the fraudster. It is the most damaging category for Nigerian businesses, and it is prevented by verifying details by phone.

Do I have to report a hack if customer data was exposed?

Yes. A cyber incident involving personal data is also a personal data breach under the Nigeria Data Protection Act, requiring notification to the Commission within seventy two hours and, where risk is high, to those affected.

What evidence should I preserve?

Screenshots with visible timestamps, full email headers, transaction references, account numbers used, and any communications with the offender. Evidence degrades quickly as accounts are deleted, so preserve it the same day.

Documents that use this

Cybercrime Law in Nigeria — LegalDoc