On 27 March 2026, an account using the alias "ByteToBreach" posted on a dark web forum that it had taken data from Sterling Bank. Four days later the same alias claimed Remita, the platform that moves federal salaries and pensions. Two weeks after that, the Corporate Affairs Commission. Read those dates as separate news stories and you have a bad spring for Nigerian institutions. Read them in order, attached to one name, and you have something more useful: a campaign with a rhythm, a target list, and a hand you can study.
The campaign as one timeline
Each disclosure landed as its own headline, its own panic, its own denial. Put them on one line by date and the panic resolves into a schedule. Here is the sequence as it became public.
- December 2025. First City Monument Bank (FCMB) detects a fraudulent attempt to move funds, with a portion transferred out before containment. The detection sat quiet for months. We unpack that incident, and the insider question it raised, in a separate look at the FCMB heist.
- 27 March 2026. ByteToBreach posts a claim against Sterling Bank, listing customer account records and employee data, including senior staff. The bank did not confirm the claim publicly.
- 31 March 2026. The same alias claims a large pull from Remita's cloud environment, including KYC documents and government payment records. Remita's public statement referred only to "some hitches" with its systems.
- 1 April 2026. The Nigeria Data Protection Commission (NDPC) opens a formal investigation naming Remita, Sterling Bank, CRC Credit Bureau, CardinalStone and other entities.
- 15 April 2026. The Corporate Affairs Commission (CAC), which registers every company in Nigeria, confirms "unauthorised access to limited aspects" of its systems and says it is working with the National Information Technology Development Agency (NITDA).
Three weeks. A mid-tier bank, a government payment rail, and the national company registry. The targets are not connected by sector. They are connected by what they hold: identity data and money movement, the two things a fraud operation can resell or reuse fastest in Nigeria.
Who is ByteToBreach
The alias is not new to people who watch these forums. ByteToBreach operates across platforms and across borders, with a pattern of claiming financial and government targets and then dripping the proof out over time. That last habit matters. A smash-and-grab actor dumps everything at once and moves on. This one announces, holds, and returns. The Sterling, Remita and CAC claims in close succession, followed by a stated promise of more, read less like luck and more like a worklist being processed.
What does that imply about method? Hitting three different kinds of institution inside a month suggests reconnaissance done in advance, not opportunism on the day. Someone mapped which Nigerian systems were exposed, ranked them by the value of the data behind them, and worked down the list. None of the reported entry points were exotic. Cloud environments left reachable, weak access boundaries, and monitoring that did not catch a large extraction in time are the same gaps senior penetration testers surface on routine engagements. The actor's edge was patience and target selection, not a novel exploit.
One caution worth holding. Several of the figures that circulated in April, the document counts and data volumes, came from the attacker's own posts or from tracking accounts repeating them, not from the breached organisations. ByteToBreach has a clear interest in inflating the haul. We treat those numbers as claims, not confirmed fact, and so should you.
Reading the regulatory response
The clearest signal in this campaign is not the breaches. It is how the state reacted, because that tells you what the system can and cannot yet do.
The NDPC moved first, opening its investigation on 1 April under the Nigeria Data Protection Act. That Act sets a real penalty ceiling: the higher of ₦10 million or 2% of annual gross revenue for a data controller of major importance. On paper that is a number a board would feel. In practice, few Nigerian organisations have faced a meaningful sanction under the Act since it came into force, so the deterrent has been theoretical. Whether this wave of cases is where enforcement finally bites is the open question, and the honest answer as at now is that we do not know.
The Central Bank of Nigeria followed with a directive requiring licensed banks to submit cybersecurity self-assessments. The shift from passive oversight to asking banks to account for themselves is the right direction. The weakness is built into the word self-assessment: it depends on each bank reporting its own gaps honestly, and a bank that already missed a breach is not obviously the best judge of its own posture. NITDA's appearance on the CAC response added a third agency to the picture, the first time it has been publicly named coordinating a federal breach of this scale.
So the spine of the official answer is three bodies (NDPC on data protection, CBN on banking supervision, NITDA on government systems) moving in parallel rather than under one command. That is more response than Nigeria would have mustered two years ago. It is also three overlapping mandates with no single owner of the campaign, which is exactly the seam a patient actor exploits.
The pattern the targets share
Sterling, Remita and the CAC are all regulated, all supervised, all presumably "compliant" on the day they were hit. Compliance did not stop any of them. That is not an argument against regulation. It is a reminder that a passed audit describes a controlled state on a date, while ByteToBreach was testing the live system at a time of its own choosing.
The reach goes past banking. Anyone holding identity data or moving money sits on the same target list: fintechs, insurers, pension administrators, registries, and yes, hospitals, whose patient records carry the same identity value. We have argued elsewhere that Nigerian hospitals could be the next sector in this line of fire. The useful question for any of them is not "are we compliant", but "if ByteToBreach mapped us tonight, would we see the extraction before they posted it".
- One actor, one timeline: FCMB (Dec 2025), Sterling Bank (27 Mar), Remita (31 Mar) and the CAC (15 Apr) read as a single ByteToBreach campaign, not four unrelated incidents.
- Treat the numbers as claims: document counts and data volumes came largely from the attacker's posts. Confirmed detail is thinner than the headlines suggested.
- Three agencies, no single owner: NDPC opened a probe, CBN ordered bank self-assessments, NITDA joined the CAC response. The NDPA penalty ceiling is real (₦10m or 2% of revenue); enforcement so far is not.
- Compliance did not stop any of them. The test is whether you could detect and contain an extraction today, not whether you passed your last audit.