NITDA LAUNCHES 2026 CYBERSECURITY AWARENESS MONTH, WARNS NIGERIANS OVER AI-DRIVEN SCAMS

By Iroyin Yoruba Television

The National Information Technology Development Agency has launched Nigeria’s 2026 National Cybersecurity Awareness Month, calling on citizens, businesses and government institutions to strengthen their digital security as artificial intelligence and other emerging technologies create new opportunities for cybercriminals.

The month-long campaign officially began on Thursday, October 1, 2026, under the theme “Together for a Safer Cyberspace”.

The campaign comes at a time when Nigerians are increasingly dependent on digital platforms for banking, communication, education, commerce, government services and business operations.

NITDA said this expanding dependence on technology has also increased the potential consequences of cyberattacks, making cybersecurity a responsibility that extends beyond information technology specialists and government security agencies.

According to the agency, the rapid development of artificial intelligence has changed the nature of online threats.

Cybercriminals are increasingly able to use automated technologies to create convincing fraudulent messages, impersonate individuals and manipulate digital information.

NITDA specifically identified AI-driven social engineering, deepfake impersonation, voice cloning and fraudulent QR-code attacks as emerging risks that Nigerians need to understand.

The agency's warning is particularly relevant because traditional assumptions about how people identify scams are becoming less reliable.

In the past, fraudulent messages could sometimes be recognised because of poor spelling, unusual wording or obvious inconsistencies.

Artificial intelligence can now help criminals produce messages that appear professionally written and can be tailored to specific individuals or organisations.

Synthetic voices can also make a fraudulent telephone call appear to come from a person the victim knows.

Deepfake technology can similarly be used to create manipulated audio or visual material that appears authentic.

This creates additional challenges for individuals who may normally rely on recognising a familiar voice or face before trusting a request.

NITDA is therefore encouraging Nigerians to adopt stronger verification practices rather than relying solely on how convincing a message appears.

The agency has also warned about fraudulent QR-code attacks, commonly referred to as “quishing”.

QR codes have become increasingly common in Nigeria, particularly in payments, advertising, transportation, hospitality and other digital services.

A malicious QR code can redirect a user to a fraudulent website designed to steal passwords, financial information or other personal data.

Because QR codes can hide the destination address from the user until the code is scanned, criminals can potentially use them to make fraudulent links less obvious.

NITDA is urging Nigerians to treat unexpected QR codes with the same caution they would apply to suspicious links received through email or messaging platforms.

The agency's campaign is built around the idea that cybersecurity must become part of everyday digital behaviour.

NITDA said securing cyberspace is no longer exclusively the responsibility of government agencies, information technology professionals or cybersecurity specialists.

Individuals, businesses and institutions all play a role because the security of one account, device or organisation can affect others within a connected digital environment.

For example, a compromised employee account can potentially provide attackers with access to corporate systems.

A stolen banking credential can result in financial losses for an individual.

A compromised government system can disrupt public services or expose sensitive information.

A cyberattack against a major business can also affect customers, employees and suppliers.

The interconnected nature of modern digital services means that cybersecurity weaknesses can spread beyond the original victim.

NITDA has therefore advised Nigerians to strengthen their basic cyber hygiene.

One of its key recommendations is the use of strong and unique passwords.

Users are advised not to use the same password across multiple accounts.

Password reuse creates additional risk because if criminals obtain a password from one compromised service, they may attempt to use the same credentials on banking, email, social media or other accounts.

Using different passwords reduces the likelihood that one breach will automatically expose several other accounts.

NITDA has also encouraged users to consider reputable password managers for creating and securely storing complex passwords.

Another major recommendation is the use of multi-factor authentication.

Multi-factor authentication adds another layer of protection beyond a password.

Depending on the service, the additional verification may involve an authentication application, security key, biometric confirmation or another approved method.

The purpose is to make it more difficult for an attacker to access an account even when a password has been compromised.

NITDA is encouraging Nigerians to activate multi-factor authentication on personal, professional and financial accounts wherever the option is available.

The agency has also warned Nigerians never to share sensitive financial credentials.

This includes one-time passwords, personal identification numbers and online banking login details.

Criminals frequently use social engineering to persuade victims to voluntarily disclose such information.

A scammer may pretend to be a bank employee, government official, telecommunications representative, employer, friend or family member.

The criminal may create a sense of urgency by claiming that an account will be blocked or that immediate action is required.

NITDA is advising Nigerians to slow down and independently verify such requests before providing information or authorising transactions.

The growing use of artificial intelligence has made this advice even more important.

A criminal could potentially use publicly available information to create a more convincing impersonation.

For example, a scammer may gather a person's name, workplace, photographs and relationships from social media before attempting to contact them.

AI-generated audio could then be used to imitate someone's voice.

The result may appear convincing enough to cause a victim to act quickly.

NITDA's campaign therefore encourages Nigerians to develop habits that do not depend entirely on recognising a person's voice, photograph or writing style.

Verification through an independent communication channel can provide an additional safeguard.

If someone receives an urgent financial request from a relative, colleague or business partner, the recipient can independently contact that person through a known telephone number or established communication channel rather than replying directly to the suspicious message.

The agency has also advised Nigerians to be careful about the information they enter into public artificial-intelligence models and unfamiliar online services.

AI tools are becoming increasingly common in workplaces, schools, businesses and personal activities.

People may use them to draft documents, analyse information, generate images, translate text or assist with professional tasks.

However, uploading confidential information into an unfamiliar platform can create privacy and security risks.

NITDA is therefore advising users to avoid submitting sensitive personal, financial or proprietary corporate information to public AI models or unfamiliar digital services when the security arrangements are unclear.

Businesses face particular risks because employees may unintentionally upload confidential information while attempting to use AI to perform ordinary work.

A company document containing customer information, financial data, passwords, intellectual property or internal strategies could expose the organisation if handled improperly.

Organisations therefore need clear policies explaining what employees are allowed to enter into AI systems.

NITDA's warning also highlights the importance of keeping software and devices updated.

Security updates frequently contain fixes for vulnerabilities that criminals may exploit.

Delaying updates can leave computers, phones, servers and other connected devices exposed to weaknesses that have already been identified.

The agency is encouraging Nigerians to install operating-system and software updates promptly.

For organisations, this should be supported by formal processes that identify vulnerable systems and ensure that critical security patches are applied.

Cybersecurity is not only about preventing attacks.

NITDA also recommends maintaining regular backups so that important information can be recovered if systems are compromised.

Ransomware attacks can prevent organisations from accessing their files by encrypting data and demanding payment.

A reliable backup can reduce the impact of such an attack by providing another way to recover important information.

NITDA recommends maintaining both offline and cloud backups of critical personal and organisational data.

For businesses, backups should form part of a wider disaster-recovery strategy.

It is also important to ensure that backups themselves are protected.

If attackers gain access to every connected copy of an organisation's data, they may be able to compromise or delete the backups as well.

Keeping appropriate offline copies can therefore provide an additional layer of protection.

The agency is also warning Nigerians about oversharing personal information on social media.

People frequently publish information about their homes, workplaces, families, birthdays, travel plans and other personal details.

Although individual pieces of information may appear harmless, criminals can combine them to build detailed profiles of potential victims.

Those profiles can then be used in targeted social-engineering attacks.

NITDA is encouraging Nigerians to consider carefully what information they make publicly available.

The campaign also stresses the importance of checking links and attachments before opening them.

Phishing remains one of the most common methods used to obtain passwords and other sensitive information.

A fraudulent message may appear to come from a bank, delivery company, government agency, employer or social-media platform.

Users may be directed to a fake website that looks almost identical to the legitimate service.

If the victim enters a username, password or financial information, the attacker can capture the information.

AI can make these scams more convincing by improving the language and personalisation of fraudulent messages.

This means that users need to examine the destination of links, the context of requests and the legitimacy of the sender.

NITDA is particularly warning Nigerians to be cautious when messages use extreme urgency.

Pressure to act immediately is often used to prevent victims from taking time to verify a request.

Messages involving unexpected financial transactions, account warnings, prizes, investment opportunities or requests for confidential information should therefore receive additional scrutiny.

The agency's cybersecurity campaign also has implications for Nigerian businesses.

As companies move more operations online, cyber incidents can affect business continuity.

A successful attack can interrupt services, expose customer data, damage reputation and create financial costs.

For financial institutions and telecommunications companies, the consequences of a major cyberattack can extend beyond a single organisation because millions of customers depend on their services.

Government institutions also face significant responsibilities.

Public-sector organisations hold large quantities of personal and administrative information and operate systems that citizens rely on.

Protecting those systems is therefore part of maintaining public confidence in digital government services.

NITDA's computer emergency response structure is expected to support efforts to improve national readiness.

The agency's Computer Emergency Readiness and Response Team was established to coordinate information sharing, provide mitigation guidance and support incident response and recovery.

The structure also provides cybersecurity awareness and education for citizens.

This means that the awareness campaign is not limited to general public messaging.

It is connected to wider efforts to improve Nigeria's capacity to identify, respond to and recover from cyber incidents.

The growth of Nigeria's digital economy makes those efforts increasingly important.

More Nigerians are using online banking, digital payments, e-commerce platforms, mobile applications and internet-based government services.

Businesses are also relying on cloud systems, digital communication and online customer platforms.

As more activities move online, the potential economic impact of cybercrime increases.

Cybersecurity therefore has become closely linked to economic development.

A secure digital environment can support confidence in online services and encourage businesses to invest in digital technologies.

A less secure environment can create additional costs and discourage users from adopting new services.

The theme “Together for a Safer Cyberspace” reflects this connection between digital growth and collective responsibility.

NITDA is encouraging Nigerians to view cybersecurity as an everyday practice rather than an issue that only becomes important after an attack occurs.

The campaign is expected to continue throughout October with awareness activities and cybersecurity guidance.

For individuals, many of the recommended measures are relatively straightforward.

Using unique passwords, enabling multi-factor authentication, installing updates, protecting financial credentials, checking suspicious links and maintaining backups can significantly improve basic digital security.

For businesses and institutions, the requirements are more extensive.

They need access controls, monitoring systems, employee training, incident-response plans, vulnerability management and reliable backup arrangements.

They also need to understand how emerging technologies such as artificial intelligence change their risk environment.

The growing use of AI means organisations must consider both its benefits and potential security implications.

AI can help businesses automate work, analyse data and improve productivity.

At the same time, criminals can use similar technologies to automate scams, impersonation and social engineering.

The challenge for organisations is therefore to adopt AI while maintaining appropriate safeguards.

For Nigerian consumers, the immediate lesson from NITDA's campaign is that increasingly convincing digital deception requires greater caution.

A message that looks professional may still be fraudulent.

A voice that sounds familiar may have been artificially generated.

A video that appears genuine may have been manipulated.

A QR code that looks ordinary may lead to a malicious website.

Technology is making digital services more useful, but it is also giving criminals new tools.

NITDA is asking Nigerians to respond by strengthening basic security habits and taking responsibility for protecting their own digital identities.

The agency's campaign also encourages cooperation between government, businesses, technology professionals and ordinary internet users.

No single organisation can eliminate every cyber threat.

Cybersecurity requires multiple layers of protection, from secure technology and strong policies to informed users who know how to recognise suspicious activity.

Nigeria's continued digital expansion will make this cooperation increasingly important.

The country's financial system, telecommunications networks, businesses and public institutions are all becoming more dependent on connected technologies.

Protecting those systems is therefore not only a technical responsibility but also an economic and social priority.

As National Cybersecurity Awareness Month begins, NITDA's message is that every Nigerian who uses a phone, computer, bank application, social-media platform or other online service has a role to play.

The agency is urging citizens to remain alert, protect sensitive information, verify suspicious communications and report incidents when they occur.

For organisations, the campaign is a reminder to review security controls, train employees, update systems and ensure that important information can be recovered after an attack.

The growing sophistication of AI-enabled scams means that cybersecurity practices cannot remain static.

Threats will continue to evolve as criminals adopt new technologies.

Nigeria's response will therefore require continuous awareness, investment and cooperation.

The 2026 National Cybersecurity Awareness Month provides an opportunity to reinforce those practices across the country.

Under the theme “Together for a Safer Cyberspace”, NITDA is placing individual behaviour alongside institutional responsibility.

The agency's warning is clear: protecting Nigeria's digital environment requires more than advanced technology.

It also requires users who think carefully before clicking, sharing, downloading, responding or providing sensitive information.

As the month-long campaign gets underway, Nigerians are being encouraged to make cybersecurity part of their everyday digital routine and to recognise that staying safe online is a shared national responsibility.