Lawyers Without Borders raises the alarm over CAC data breach
Summarized and contextualized by DistantNews.
TLDR
- Lawyers Without Borders (ASF France) has raised concerns over a data breach at Nigeria's Corporate Affairs Commission (CAC).
- The organization warned that the breach could compromise the privacy rights of Nigerian entrepreneurs and violates data protection laws.
- ASF France criticized the CAC's handling of the incident, citing inadequate disclosure and lack of clear redress mechanisms for affected individuals.
Avocats Sans Frontiรจres France (ASF France) has voiced significant alarm regarding a recent data breach at the Corporate Affairs Commission (CAC), a critical government agency responsible for business registration in Nigeria. The organization contends that this security lapse not only exposes sensitive personal data of Nigerian entrepreneurs but also represents a potential violation of their fundamental privacy rights and existing data protection legislation.
The Corporate Affairs Commission is currently reviewing a cybersecurity incident involving unauthorised access to limited aspects of its information systems.
The CAC confirmed a cybersecurity incident involving unauthorized access to parts of its information systems, initiating response protocols and engaging with relevant authorities like the National Information Technology Development Agency (NITDA). However, ASF France alleges that the breach, reportedly linked to a threat actor known as 'ByteToBreach,' resulted in the compromise of vital information including handwritten signatures, national identity documents, and passport photographs. This, according to ASF France, constitutes a breach of constitutional privacy rights and contravenes the Nigeria Data Protection Act 2023.
The incident as a violation of the constitutional right to privacy and a breach of obligations under the Nigeria Data Protection Act 2023.
Critically, ASF France has faulted the CAC's communication and response strategy. The organization points to a perceived lack of transparency, particularly the failure to disclose the number of affected individuals, leaving many Nigerians in a state of uncertainty. Furthermore, ASF France argues that the CAC has not fully adhered to the data protection law's requirement for direct notification of individuals impacted by high-risk breaches. The absence of clear mechanisms for victims to seek redress or protect their identities, such as flagging NINs or passports, is also a major point of contention. From our perspective at The Punch, these concerns highlight the urgent need for robust cybersecurity measures and transparent data governance practices within Nigerian institutions to safeguard citizens' digital privacy.
The failure to disclose the number of affected individuals has left many Nigerians uncertain about the extent of the breach.
Originally published by The Punch. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.