NIN Database Breach: What NIMC Says About Viral Claims
The National Identity Management Commission (NIMC) has denied claims that Nigeria’s National Identification Number (NIN) database has been breached, after a video circulated online alleging that Nigerians’ personal information was being sold.
The video claimed that NIN and Bank Verification Number (BVN) details could be obtained for as little as ₦100. It also alleged that some NIMC officials in Lagos were selling people’s NIN information for ₦1,000 outside the commission’s office.
NIMC described the claims as “false and unfounded”, saying its National Identity Database (NIDB) had not been breached or compromised.
However, the commission has also ordered an investigation into whether any of its tokenisation verification agents breached their licensing agreements, including through sub-licensees.
This distinction is important because the viral claim concerns the security of information belonging to millions of Nigerians, while NIMC’s investigation is looking into whether authorised verification arrangements may have been misused.
What NIMC said about the alleged breach
In a statement issued on Wednesday and circulated on Thursday, NIMC said the video currently making the rounds is a recycled report from 2024 that the commission had previously dismissed.
“The Commission National Identity Database (NIDB) has not been breached or compromised at any point,” NIMC said.
The commission said it maintains a multi-layered security infrastructure designed to protect the personal information of registered citizens and legal residents.
It also warned that unverified reports about the national identity system could mislead Nigerians and create unnecessary panic.
NIMC urged the public to obtain information about the National Identity Management System through its official channels rather than relying on viral social media posts.
Why NIMC is investigating
Although NIMC rejected the claim of a database breach, the commission is not simply ignoring the allegations.
According to reports citing the commission, Director-General Abisoye Coker-Odusote ordered a comprehensive investigation to determine whether any tokenisation verification agents breached their licensing agreements.
The investigation will also examine whether such a breach occurred directly or through sub-licensees.
This means the investigation is not confirmation that the NIN database was breached.
Rather, it is intended to establish whether agents operating within NIMC’s verification ecosystem violated the terms under which they were authorised to provide services.
NIMC said it would continue working with relevant stakeholders to ensure that identity information entrusted to the commission is protected.
The 2024 NIN data controversy
The latest viral claim has similarities to a separate controversy that drew attention in 2024.
In March that year, reports emerged that a private website known as XpressVerify had allegedly been able to retrieve Nigerians’ NIN details and other personal information.
The Nigeria Data Protection Commission (NDPC) subsequently opened an investigation into the alleged unauthorised access.
The NDPC said its investigation found that a third-party company that had been authorised to provide verification services may have allowed XpressVerify to use its NIN verification credentials.
NIMC also ordered an investigation at the time into whether one of its tokenisation verification agents had breached its licensing agreement directly or through a sub-licensee.
That history helps explain why the latest video has attracted attention, but it does not establish that the 2024 incident and the current viral claim are the same event.
NIMC’s current position is that the video is recycled and that the National Identity Database has not been compromised.
NIMC launches NINAuth
Amid the renewed concerns, NIMC has also highlighted its NIN Authentication platform, known as NINAuth.
The commission describes NINAuth as a web, API and mobile verification service designed to strengthen data security and privacy.
According to NIMC, the platform requires the explicit consent of a NIN holder before their information is shared for Know Your Customer (KYC) processes or other verification purposes.
The commission said the system can be used for identity verification in services including SIM registration, immigration and passport processing, tax filings and financial transactions without unnecessarily exposing a person’s raw NIN or personal information.
What Nigerians should do
For now, NIMC is asking Nigerians not to rely on the viral video and other unverified claims about the alleged database breach.
The commission advises people to use approved channels for NIN verification and other identity-related services.
NIMC also provides official channels for people who have questions or concerns about their NIN or identity information, including its toll-free line and customer-care contacts.
The key point is that NIMC has denied that its National Identity Database was breached, while an investigation is examining whether verification agents or sub-licensees may have violated their agreements.
Until the investigation produces further findings, claims that Nigerians’ entire NIN database has been hacked or is being openly sold should not be presented as established fact.