← Back to Blog
22 April 2026 · QuantomShield Admin
The CAC Breach: What Nigeria's Corporate Registry Hack Teaches Every Organisation
In April 2026, Nigeria's Corporate Affairs Commission (CAC) confirmed it was reviewing a cybersecurity incident involving unauthorised access to parts of its information systems. A group operating under the name ByteToBreach claimed to have exfiltrated roughly 25 million files — around 750 gigabytes of data — and went on to leak more than 15 million documents.
The CAC is not a small target. As Nigeria's official company registry, it holds incorporation records, shareholder and director details, and filings for millions of registered businesses — exactly the kind of structured, high-value dataset that threat actors look to monetise or use for downstream fraud, identity theft, and business email compromise.
What makes an incident like this dangerous isn't only the initial exposure. It's the ripple effect: once director and shareholder identity data is in circulation, it can be used to impersonate company officers, forge correspondence, or socially engineer banks and partners who rely on registry data as a trust anchor. Any organisation that has ever filed with the CAC — which is to say, almost every registered business in Nigeria — has a reason to pay attention.
A few lessons stand out for organisations of any size. First, unauthorised access is rarely detected at the moment it happens; it is usually discovered later, during monitoring, audit, or — as in several recent Nigerian cases — when a threat actor publicises the claim themselves. That gap between compromise and detection is where the damage compounds, which is why continuous monitoring and logging matter as much as perimeter defence. Second, data that looks purely administrative — company filings, identity documents, contact details — is still sensitive enough to be weaponised, and should be governed accordingly. Third, incident response plans need to be rehearsed before they're needed, not written for the first time during a live breach.
At QuantomShield Tech Partners Ltd, this is the work we do daily: risk assessments, vulnerability testing, and incident response planning that help government agencies and private organisations reduce the blast radius when — not if — an attempted breach occurs. If your organisation handles registry-grade or customer identity data, now is a reasonable time to ask when your systems were last independently assessed.