NIMC probes alleged NIN data exposure as digital economy expands
The National Identity Management Commission (NIMC) has ordered a comprehensive investigation into allegations that Nigerians’ National Identification Numbers and other personal information may have been exposed, as concerns over digital identity security grow alongside the expanding use of the NIN across the economy.
NIMC denied that its systems had been compromised and urged Nigerians to disregard unverified claims circulating on social media that citizens’ identity information had been exposed and offered for sale.
Head of Corporate Communications, Kayode Adegoke, said the commission’s systems remained protected and that NIMC was committed to securing the personal information held in the National Identity Database.
But the Director-General of NIMC, Abisoye Coker-Odusote, has directed a full investigation to establish whether any licensed tokenisation and verification agents breached their agreements with the commission, either directly or through sub-licensees.
The investigation comes at a particularly sensitive time for Nigeria’s digital economy because the NIN has become a foundational identity credential used across an expanding range of public and private services.
Under the NIMC Act 2026, signed into law in June, the commission was given an expanded role in Nigeria’s digital identity and trust architecture, including responsibility for supporting secure authentication and digital public infrastructure. The new law also strengthens data-protection and privacy requirements.
NIMC’s own records show that NIN enrolment involves the capture of demographic information, fingerprints, facial images and digital signatures, making the national identity database one of the country’s most sensitive repositories of personal information.
The economic implications of a genuine breach would therefore extend far beyond privacy.
Financial institutions, telecommunications companies and government agencies increasingly rely on identity verification to prevent fraud, comply with regulation and provide services. NIN-linked digital identity is also being expanded through NINAuth, which allows users to verify their identity digitally and access identity-related services without relying solely on physical documents.
Any loss of confidence in the integrity of the system could raise compliance costs for businesses, increase the risk of identity fraud and make consumers more reluctant to use digital financial and government services.
NIMC said Nigerians should use only approved channels for NIN verification and other identity-related services, while the commission continues to strengthen safeguards against unauthorised access.
The agency has faced similar scrutiny in the past. In 2024, allegations of unauthorised access to NIN data prompted an investigation by the Nigeria Data Protection Commission, while NIMC subsequently tightened security requirements for licensed front-end partners and verification agents. The NDPC later reported that NIMC was not found liable or fined over the allegation.
The latest allegations therefore come at a time when the government is attempting to expand digital identity as a foundation for a more connected economy.
NIN is increasingly becoming a gateway through which citizens prove who they are to banks, government agencies and other service providers. NIMC’s own digital platform now allows Nigerians to download NIN slips and manage identity-linked services electronically.
NIMC’s denial means no data breach has been established by the latest allegations. The immediate economic issue, however, is whether the investigation can quickly establish the facts and preserve confidence in a national identity system on which an increasing number of transactions, services and digital businesses depend.
