Morganable Cyber Watch
ngCERT warns Nigerian organisations over rising phishing, ransomware and AI-powered cyberattacks
Lagos —
Nigeria’s Computer Emergency Readiness Team (ngCERT) has warned organisations across the country about rising cyberattacks targeting businesses, government institutions and critical infrastructure.
In a security advisory issued on September 25, 2026, the agency highlighted phishing, ransomware, business email compromise and data breaches among the major threats facing organisations.
It also warned that cybercriminals are increasingly using artificial intelligence and cybercrime-as-a-service tools to make attacks more effective.
Attackers change tactics
According to ngCERT, cybercriminals are taking advantage of weak security systems, stolen credentials and unpatched software to gain access to organisational networks.
Phishing remains one of the common methods used to trick employees into revealing sensitive information or clicking on malicious links.
Ransomware is another growing concern.
In a ransomware attack, criminals can lock an organisation’s files or systems and demand payment before access is restored.
The emergence of ransomware-as-a-service has made the threat more serious because attackers can obtain ready-made tools without developing the technology themselves.
AI adds a new challenge
Artificial intelligence is also changing the way cybercriminals operate.
ngCERT said attackers are using AI and automation to create more convincing social-engineering messages, evade security measures and identify vulnerabilities.
This means employees may find it increasingly difficult to distinguish fraudulent messages from legitimate communication.
The agency therefore urged organisations to strengthen cybersecurity awareness among staff and regularly test their ability to detect phishing attempts.
Critical sectors face risks
The warning covers several important sectors, including telecommunications, financial services, healthcare, government institutions and other critical infrastructure.
An attack on these sectors could have wider consequences because they provide services that individuals and businesses depend on.
For example, a major data breach could expose sensitive customer information, while a ransomware attack could prevent an organisation from accessing important systems.
The disruption could also result in financial losses and affect public confidence.
Organisations urged to act
To reduce the risk of attacks, ngCERT recommended stronger security measures, including multi-factor authentication, regular software updates and continuous monitoring of networks.
It also encouraged organisations to conduct regular vulnerability assessments and penetration testing.
Secure backups are another important part of its recommendations.
The agency advised organisations to maintain offline backups so that important data can still be recovered if ransomware affects their main systems.
Employee training was also highlighted as an important defence.
Cybersecurity is no longer only a technical responsibility for IT departments. Employees across an organisation can become the first line of defence against phishing and other forms of social engineering.
Cyber threats continue to evolve
The latest warning comes as Nigerian organisations continue to move more services and operations online.
As businesses adopt cloud services, digital payments and remote work tools, more valuable information is stored and exchanged digitally.
This creates new opportunities for cybercriminals while increasing the potential impact of successful attacks.
The ngCERT advisory therefore highlights the need for organisations to regularly review their security systems instead of waiting until an attack occurs.
With cybercriminals adopting new technologies, organisations will need stronger security controls, better employee awareness and faster responses to emerging threats.
Organisational response remains important
Beyond preventing attacks, organisations also need to prepare for incidents that may occur despite existing security measures.
Having a clear incident response plan can help businesses act quickly when suspicious activity is detected. Such a plan should identify the people responsible for responding to an attack, the systems that need to be protected and the steps required to contain the damage.
Quick action can be important during ransomware and data breach incidents. Delays may allow attackers to move further through a network, compromise more accounts or access additional information.
Organisations should also ensure that their security teams can communicate quickly with management when an incident occurs. This can help decision-makers understand the situation and take appropriate steps to limit disruption.
Protecting sensitive information
Data protection is another area that requires greater attention as cyber threats increase.
Businesses and government institutions often hold sensitive information belonging to customers, employees and other stakeholders. Personal details, financial records, passwords and business information can become valuable targets for cybercriminals.
Organisations should therefore limit access to sensitive information and ensure that employees only have access to the data required for their responsibilities. Strong password policies and multi-factor authentication can also reduce the risk of compromised accounts being used to gain access to important systems.
Regular security reviews can help organisations identify accounts, software and systems that are no longer needed. Removing unnecessary access can reduce the number of possible entry points available to attackers.
Businesses also need to pay attention to third-party risks. Organisations often rely on vendors, technology providers and other external partners to deliver digital services. Weak security practices within a third-party system could create risks for the organisation connected to it.
Building a stronger cyber culture
Cybersecurity awareness must also extend beyond occasional training sessions. Organisations can build stronger security cultures by encouraging employees to report suspicious emails, unusual login attempts and other security concerns without delay.
Regular simulations and awareness exercises can help workers understand how cyberattacks happen. They can also show organisations where employees may need additional training.
As attackers continue to use AI and automated tools, traditional security practices may not always be enough. Organisations will need to combine technology with human awareness and clear internal procedures.
For Nigerian businesses, government agencies and critical service providers, the warning reinforces the importance of treating cybersecurity as an ongoing responsibility.
Regular updates, staff awareness, secure backups and effective response plans can help reduce the potential impact of attacks.
The growing use of digital services means cybersecurity will remain an important part of Nigeria’s digital development.
Organisations that regularly assess their systems and respond quickly to emerging threats can improve their ability to protect data, maintain services and keep the trust of the people who depend on them.












