Nigeria loses about $500 million yearly to cyberattacks, according to the Nigerian Communications Commission (NCC). In a recent report, Deloitte’s Senior Manager of Cyber Risk Services, Funmilola Odumuboni, disclosed that a cyberattack occurs every 39 seconds and noted that cybercrimes have increased by nearly 300 percent since the onset of the pandemic. A Sophos study found that 71 percent of Nigerian organisations were victims of ransomware in 2021, and 44 percent of those firms paid ransoms to recover their data. To combat the rising spate of attacks, the NCC’s Centre for Computer Security Incident Response issues advisories as needed. At the centre’s launch, NCC Executive Vice Chairman Prof. Umar Danbatta said, “The commission recognises that, given the borderless nature and pervasiveness of these incidents, relentless and concerted attention is required to protect Internet users and the Critical National Information Infrastructure and ensure they are resilient.”
Kaspersky, a global cybersecurity firm, warns that cybercrime remains an ongoing risk to individuals, organisations, and governments worldwide. Their research showed a 50 percent increase in attack attempts on corporate networks in 2021 compared with 2020. Beyond financial losses, businesses also suffer less tangible costs such as reputational damage and reduced consumer trust. Kaspersky defines a cyberattack as “an attempt by cybercriminals to disable computers, steal data, or use a breached computer system to launch additional attacks.” Because attackers need to exploit only one vulnerability while defenders must protect every possible entry point, the imbalance favours attackers, making it difficult even for large organisations to prevent breaches. Any internet‑connected device can be used as a weapon, a target, or both, putting individuals and businesses of all sizes at risk.
ICT expert and Senior Partner of e86 Limited, Olugbenga Odeyemi, observes that the surge in cyberattacks is linked to rapid technological growth. “More businesses are coming online, operating remotely and setting up technology infrastructures that were not desired a few years ago. That growth is leading to more attacks and greater sophistication,” he explains.
Kaspersky outlines several common types of cybersecurity attacks. Malware, or malicious software, includes ransomware (which locks a computer and demands payment), Trojans (hidden in email attachments or free downloads and capable of stealing credentials and payment information), and spyware (which covertly transmits data, functions as a keylogger, and can capture screenshots). Distributed denial‑of‑service (DDoS) attacks use multiple compromised systems to overwhelm a target, causing it to slow down or crash. Phishing involves fraudsters masquerading as reputable entities to distribute malicious links or attachments, tricking victims into revealing passwords, credit‑card details, or intellectual property. Variants include spear phishing (targeted at specific individuals or companies) and whaling (aimed at senior executives), with business email compromise—a form of whaling—costing the FBI an estimated $43 billion between 2016 and 2021.
Other attack vectors include SQL injection, where malicious queries manipulate database‑driven websites to create, modify, delete, or extract data; cross‑site scripting (XSS), which injects malicious code into web applications to steal session cookies, spread malware, deface sites, or facilitate further attacks; and botnets, networks of infected devices controlled remotely to send spam, conduct click‑fraud, or generate traffic for DDoS attacks.
To mitigate cyberattacks, Kaspersky advises businesses to act swiftly, focusing on stopping the attack and limiting its impact. The first step is to mobilise the cybersecurity team—ideally trained in incident response—to coordinate an effective defence.
Comments are closed for this story.