NIMC Dismisses Viral NIN Hack Claim

The National Identity Management Commission has denied that Nigeria’s national identity database was hacked, describing a video circulating online as a recycled and previously disclaimed claim from 2024.

In a statement signed by its Head of Corporate Communications, Kayode Adegoke, and posted on the commission’s X handle on Wednesday, 23 September 2026, NIMC called the allegation false and unfounded. It said the National Identity Database, known as the NIDB, had not been breached or compromised at any point.

The commission said it maintains a robust, multi-layered security infrastructure to protect the personal data of registered citizens and legal residents, in line with international best practice. It urged the public to disregard the video and to rely only on NIMC’s official channels for information about the identity system.

According to the statement, NIMC views the spread of such unverified claims with concern, warning that they could mislead the public and cause needless panic.

The current denial follows a familiar pattern. The commission issued similar rebuttals through 2024 after separate reports alleged that NINs and identity slips were being harvested and sold online. At the time, officials including the commission’s IT director, Lanre Yusuf, said the items being sold were fake slips generated by data harvesters rather than records drawn from the database itself, and that the national data centre hosted in Nigeria had never been breached.

Alongside the denial, NIMC pointed to its NIN Authentication platform, NINAuth, which it presented as central to how identity data is now shared. The commission said the DG, Abisoye Coker-Odusote, unveiled NINAuth on 30 October 2025 as a consent-based, citizen-controlled service covering web, application programming interface and mobile verification.

The commission said NINAuth requires the explicit consent of the NIN holder before data is released for Know Your Customer checks or other verification. It said the system allows people to confirm their identity for services such as SIM registration, immigration and passport processing, tax filing and financial transactions without exposing their raw NIN or other personal details.

NIMC framed the platform as part of its compliance with the NIMC Act 2026 and the Nigeria Data Protection Act 2023, which set out rules for the fair, lawful and transparent handling of personal data. The 2026 Act repealed the 2007 law that established the commission and gave stronger legal backing to the identity programme.

The renewed scrutiny lands as the NIN sits at the centre of daily life for millions of Nigerians. It is now the gateway for SIM registration, bank account verification, passport applications, tax administration and access to social programmes, which raises the stakes attached to any suggestion that the underlying data is unsafe.

The commission has reported steady growth in the number of records it holds. NIMC said enrolment reached 136 million in July 2026, up from about 123.9 million in October 2025, and the DG later put the figure above 137 million. President Bola Tinubu has directed the commission to capture every eligible person before the end of 2026, with the government targeting 95 per cent coverage by December.

The gap between enrolment and population remains wide. Coker-Odusote has said Nigeria’s population is estimated at between 200 million and 250 million, meaning tens of millions, particularly children, rural residents and vulnerable groups, are yet to be registered. She has said the database now has the capacity to hold 250 million records, and that free enrolment was extended in February 2026 to all 8,809 wards under a World Bank supported identification project.

Reporting elsewhere indicated that the commission’s leadership treated the latest claim seriously despite the public denial. Coker-Odusote was said to have ordered an investigation into the allegation, and NIMC said it would continue working with security agencies to strengthen its systems and its public engagement against misinformation.

For now, the position is clear on one point and open on another. NIMC has stated categorically that no breach occurred and that the circulating video is old material repackaged as current news. What has not been made public is any independent verification of the commission’s systems, and the outcome of the investigation the DG reportedly ordered has not been disclosed. Until those details emerge, the commission’s account rests on its own assurances and its record of issuing near-identical denials in previous years.

The commission’s advice to the public has stayed consistent across each episode. It has repeatedly warned Nigerians not to submit their NIN and personal details to unauthorised websites or phishing platforms, saying such disclosures, rather than any weakness in the central database, are what expose individuals to identity theft.