Nigeria's Corporate Affairs Commission suffered a data exposure incident that made business registration records, directors' personal information and BVN-linked data publicly accessible through an unsecured API endpoint.
Security researchers discovered that the Corporate Affairs Commission (CAC), the Nigerian government agency responsible for business registration, had an unsecured API endpoint that exposed sensitive business and personal data without authentication.
The exposed endpoint returned detailed records including company registration details and RC numbers, directors' full names, home addresses and phone numbers, BVN and NIN numbers linked to business registrations, shareholding structures and financial filing histories, and memoranda and articles of association documents.
A Nigerian cybersecurity researcher discovered the vulnerability during routine research and attempted to report it through responsible disclosure. The CAC initially did not respond to the disclosure, and the endpoint remained active for several weeks before being secured.
This breach has serious implications for Nigeria's business community. With directors' personal information and BVN numbers exposed, affected individuals face heightened risk of corporate identity fraud, where criminals could register companies in their names or impersonate them in financial transactions.
Step-by-step guide
Step 1 — Check your CAC records
Visit search.cac.gov.ng and search your full name to see what business records are linked to you.
Step 2 — Contact your bank
Inform your bank that your BVN may have been compromised and ask them to flag your account for unusual activity.
Step 3 — Report to NDPC
File a complaint with the Nigeria Data Protection Commission at ndpc.gov.ng if you believe your data was misused.
Original source
TechCabal
Share this article
No community notes yet
Be the first to add a technical insight.