The Corporate Affairs Commission (CAC) has officially confirmed a high-level cybersecurity breach involving unauthorized access to its digital infrastructure. This incident, confirmed on Wednesday, April 15, 2026, has sent shockwaves through Nigeria’s business community, as the agency holds the sensitive records of over 4 million registered entities.
1. The Hacker: “ByteToBreach” Strikes Again
The breach has been attributed to a notorious dark web actor known as ByteToBreach.
- The Track Record: This is the same hacker who recently compromised the Remita KYC database on March 31.
- The Motive: Evidence suggests the actor sells these institutional databases to other cybercriminals for use in blackmail, corporate impersonation, and identity theft.
2. The Scope: What Data Was Stolen?
While the CAC initially stated that only “limited aspects” of its system were affected, investigators have found that the exfiltrated data is incredibly sensitive. The leaked files reportedly include:
- Password Repositories: Hashed or plain-text credentials for user accounts.
- KYC Documents: National Identity Cards (NIN), Voter Cards, and International Passports.
- Legal Filings: Court affidavits, company resolutions, and signatures of directors and shareholders.
- Biometrics: Passport photographs submitted during company registrations.
- Scale: Unverified reports from cybercrime trackers suggest as many as 25 million documents may have been exfiltrated.
3. The “AI-Powered” Irony
The breach comes at a time when the CAC has been boasting about its rapid digital transformation.
- Since July 2025, the commission has used Artificial Intelligence to process over 10,000 registrations daily.
- Critics argue that the agency prioritized speed and automation over robust cybersecurity architecture, leaving the “front door” open to sophisticated dark web actors.
4. Urgent Advisory for Business Owners
The CAC and NITDA (National Information Technology Development Agency) have issued an immediate security protocol for all registered businesses and individuals:
- Change Credentials: Update your login passwords for the CAC portal immediately.
- Monitor Records: Regularly check your company profile on the portal for unauthorized changes to directorship or shareholding.
- Phishing Alert: Be extremely cautious of unsolicited emails or phone calls claiming to be from the CAC or banks asking for “verification” details.