Nigeria recorded 1.6 million online cyberattack attempts in the first half of 2026, reinforcing concerns that the country’s expanding digital economy is becoming an increasingly attractive target for cybercriminals using artificial intelligence to automate attacks, evade detection and exploit businesses at unprecedented speed.
New threat intelligence from cybersecurity firm Kaspersky shows that Nigeria was among the five most-targeted countries in the Middle East, Türkiye and Africa (META) region between January and June 2026. Its security systems blocked 1.6 million web-based attacks originating from malicious websites, phishing emails and compromised online services during the six-month period.
Read also: Data breaches fuel cybercrime supply chain as AI makes scams harder to detect
While Nigeria recorded fewer attacks than South Africa (5.7 million) and Kenya (4.5 million), the report reveals that 18.4 percent of Nigerian internet users encountered web-based cyber threats during the period, placing the country fourth in the META region behind Türkiye (22.8 percent), Kenya (21.2 percent) and Qatar (19.3 percent). South Africa followed Nigeria at 17.2 percent, while Saudi Arabia, Jordan and Pakistan recorded the lowest proportions of users affected by web-borne attacks.
The figures suggest that although Nigeria recorded a lower absolute number of attacks than South Africa and Kenya, a significant proportion of its online population remains exposed to malicious activity. Cybersecurity experts say this reflects both the rapid expansion of Nigeria’s internet economy and the growing sophistication of attacks targeting consumers, financial institutions, enterprises and government systems.
The latest findings come as Nigeria aggressively pursues a digital-first economy powered by fintech, artificial intelligence, cloud computing, digital identity, e-government services and electronic payments. These initiatives have accelerated financial inclusion and digital innovation, but they have also dramatically expanded the country’s cyber attack surface.
Industry experts warn that every new cloud deployment, AI application, mobile banking platform or digital government portal creates additional entry points for attackers if security measures fail to keep pace with innovation.
Perhaps the most significant finding in Kaspersky’s report is the growing role of artificial intelligence in cybercrime.
According to the company’s Global Research and Analysis Team (GReAT), threat actors are increasingly integrating Large Language Models (LLMs) into almost every stage of their operations. AI tools are now capable of generating highly convincing phishing emails, writing malicious software, translating malware into different programming languages and creating fake operational documents that make cyberattacks more scalable and harder to detect.
Researchers said AI-assisted malware is no longer theoretical.
They pointed to campaigns linked to the FunkSec cybercrime group, which deployed AI-assisted Rust-based malware capable of stealing sensitive information, encrypting files and manipulating system processes. In another campaign known as RevengeHotels, attackers used large language models to generate parts of malware code, reducing development time while improving the speed of deployment.
“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” said Sergey Lozhkin, head of global research and analysis team for APAC and META at Kaspersky.
According to him, AI is reducing the cost and technical expertise required to launch sophisticated attacks, allowing cybercriminals to rapidly adapt malicious tools whenever defenders develop new detection methods.
Beyond AI-generated phishing and malware, Kaspersky identified several emerging trends expected to reshape enterprise cybersecurity.
Among them is the growing use of legitimate cloud storage platforms to secretly move stolen corporate data, enabling hackers to blend malicious traffic with normal business operations. Another trend is the evolution of ransomware, where attackers increasingly aim to cripple production systems, manufacturing lines and business operations rather than merely encrypting files, thereby increasing pressure on victims to pay ransoms.
The company also warned of a new generation of attacks targeting AI agents. As businesses increasingly deploy AI assistants with broad access to enterprise systems, attackers may compromise these agents by manipulating their prompts, embedded skills or configurations, enabling persistent access, unauthorised transactions or continuous malware downloads every time the systems restart.
For Nigeria, the findings underscore a broader challenge.
Africa’s largest economy is simultaneously one of the continent’s fastest-growing digital markets. Mobile banking, digital lending, e-commerce, online education, health technology and artificial intelligence are expanding rapidly, while businesses continue migrating critical operations to the cloud. This digital acceleration is creating enormous economic opportunities, but it is also increasing exposure to sophisticated cyber threats.
The report also reflects a broader trend across Africa.
In 2025, Kaspersky reported that African businesses experienced rising web-based attacks, spyware infections and password-stealing malware, with Kenya, South Africa, Morocco and Nigeria among the continent’s most targeted countries. Password-stealer detections increased by 26 percent, while spyware attacks rose 14 percent, indicating that cybercriminals are increasingly focusing on identity theft and financial fraud rather than simply disrupting systems.
Nigeria has experienced this trend before. Ahead of GITEX Nigeria 2025, Kaspersky disclosed that password-stealer attacks in Nigeria surged 66 percent year-on-year during the first half of 2025, while spyware detections increased 53 percent, suggesting that attackers have been steadily intensifying operations against Nigerian users long before the latest AI-driven wave emerged.
Cybersecurity analysts believe the challenge facing Nigeria is no longer simply about defending against conventional hackers.
Instead, organisations must prepare for AI-powered adversaries capable of producing thousands of personalised phishing emails within minutes, automatically rewriting malware to bypass security software, identifying vulnerable systems faster than human attackers and continuously adapting attack techniques with minimal human intervention.
For financial institutions, telecom operators, government agencies and critical infrastructure providers, this represents a significant shift in cyber risk. Traditional signature-based security tools are becoming less effective against AI-assisted attacks that can rapidly mutate, disguise themselves as legitimate traffic and exploit trusted cloud platforms.
Kaspersky advised organisations to strengthen their cyber resilience through continuous vulnerability assessments, timely software patching, employee cybersecurity awareness programmes, proactive threat intelligence and advanced detection platforms capable of identifying AI-assisted attacks before they disrupt operations.
The report suggests that as Nigeria pushes ahead with its ambitions to become Africa’s digital innovation hub, cybersecurity can no longer be treated as an afterthought. In the AI era, protecting digital infrastructure is becoming just as important as building it, because the technologies driving economic growth are also giving cybercriminals new tools to attack at greater speed, lower cost and unprecedented scale.
Join BusinessDay whatsapp Channel, to stay up to date
Open In Whatsapp
Facts Only
* Nigeria recorded 1.6 million online cyberattack attempts in the first half of 2026.
* Nigeria was among the five most-targeted countries in the Middle East, Türkiye and Africa (META) region between January and June 2026.
* Security systems blocked 1.6 million web-based attacks originating from malicious websites, phishing emails, and compromised online services during the six-month period.
* 18.4 percent of Nigerian internet users encountered web-based cyber threats during the period.
* Nigeria ranked fourth in the META region for web-based cyber threats, behind Türkiye (22.8 percent), Kenya (21.2 percent), and Qatar (19.3 percent).
* South Africa recorded 17.2 percent of users affected by web-borne attacks.
* Password-stealer attacks in Nigeria surged 66 percent year-on-year during the first half of 2025.
* Spyware detections increased by 53 percent in Africa in 2025, and password-stealer detections increased by 26 percent continent-wide in 2025.
* Threat actors are integrating Large Language Models (LLMs) into operations to generate phishing emails, write malicious software, and translate malware.
* Attackers are using legitimate cloud storage for data exfiltration and evolving ransomware to cripple production systems.
Executive Summary
Nigeria experienced 1.6 million online cyberattack attempts in the first half of 2026, stemming from the growing sophistication of cybercriminals utilizing artificial intelligence for automation and evasion. Threat intelligence indicated Nigeria was among the five most-targeted countries in the Middle East, Türkiye, and Africa (META) region between January and June 2026. While Nigeria recorded fewer attacks than South Africa or Kenya, 18.4 percent of its internet users faced web-based cyber threats during this period. This exposure correlates with the rapid expansion of Nigeria's digital economy across fintech, AI, and cloud computing, which has expanded the country’s overall cyber attack surface.
Cybersecurity experts note that the rise in attacks is linked to attackers integrating Large Language Models (LLMs) into operations, enabling them to generate highly convincing phishing emails and malware code at scale. Emerging trends indicate that attackers are increasingly using legitimate cloud storage for data exfiltration and evolving ransomware tactics to target operational systems rather than just encryption. Furthermore, there is a growing threat against AI agents deployed by businesses, where compromise can grant persistent access through prompt manipulation.
Full Take
The narrative highlights a critical divergence between Nigeria's rapid digital economic expansion—fueled by fintech, AI, and cloud migration—and the lagging pace of its cybersecurity posture against increasingly sophisticated, AI-assisted threats. The core pattern emerging is that technological growth inherently increases exposure; every new digital deployment, from mobile banking to e-government portals, serves as an expanding attack vector. This acceleration creates a latency gap where defensive measures, often reliant on traditional signature-based tools, cannot keep pace with adversary capabilities, which are now leveraging LLMs for autonomous attack generation and adaptation.
The focus shifts from simple intrusion defense to systemic resilience against adaptive adversaries. The integration of AI into the threat landscape, evidenced by AI-assisted malware deployment and AI agents being targeted directly, suggests that future security must pivot beyond perimeter defense to encompass the integrity of cloud platforms, identity management, and the operational logic of AI systems themselves. This dynamic implies a risk distribution where the cost of security failure is not just data loss but the destabilization of entire digital infrastructure supporting economic growth. The historical trend shows that specific attack types (password theft, spyware) have been escalating against African populations long before the current AI-driven wave intensified, indicating a persistent baseline vulnerability being exploited by modern, high-velocity methods.
What are the systemic implications for agency? If security cannot keep pace with innovation—specifically in areas like cloud deployment and AI application—then digital development itself becomes an act of vulnerability. The challenge is not merely mitigating immediate threats but restructuring risk management to account for non-human, adaptive threat actors operating at machine speed. This necessitates a shift from reactive patching to proactive, holistic resilience where security investment is integrated into the very architecture of digital innovation rather than treated as an external layer.
Sentinel — Human
The text appears to be a well-researched journalistic piece synthesizing specific threat data with broader AI implications, demonstrating the complex synthesis characteristic of human analysis rather than pure LLM generation.
