On July 10, 2026, Nigeria's Police National Cybercrime Centre (NPF-NCCC) announced the arrest of 21 suspects across five distinct cybercrime investigations, according to Force Public Relations Officer CSP Anietie Okonko Iniedu. One strand of that sweep was the product of a genuinely international operation: four suspects arrested for allegedly running a Telegram-based network that stole and sold the personal and financial data of United Kingdom citizens, working under 'Operation Seraphim' — a joint effort between the NPF-NCCC and London's City of London Police, the UK's national lead force for fraud, alongside the National Crime Agency (NCA) and the Cyber Defence Alliance.
Seraphim is not a one-off. It has produced 31 arrests across the UK and Nigeria to date, spanning romance scams, business email compromise and stolen-data marketplaces. A separate strand of the same July 10 sweep — six suspects arrested in Asaba, Delta State, for impersonating public figures to defraud foreign victims — was opened after the NCA passed intelligence to Nigerian police through the British High Commission in Abuja. A third, unrelated case in the same announcement involved an alleged ₦7.7 billion ($5.6 million) fraud against telecom operator MTN, in which suspects allegedly exploited stolen staff credentials to convert fraudulent airtime credits into data bundles distributed across more than 2,000 prepaid lines.
The Case for This Model
It is worth steelmanning why this kind of enforcement deserves support rather than skepticism. Nigeria's advance-fee fraud reputation has evolved: what were once solo '419' scams are now organized, Telegram-mediated data markets that inflict real, quantifiable harm on foreign nationals who never consented to any exposure to Nigerian jurisdiction. The UK has a legitimate interest in seeing that harm prosecuted at the source, and Nigeria has a legitimate interest in not being a permissive haven for it — both reputationally and economically, given how central digital services have become to Nigerian GDP (the telecoms and information sector contributed ₦18.47 trillion, or 8.34% of real GDP, in 2025, per the National Bureau of Statistics). Cross-border data-theft rings are precisely the kind of narrow, identifiable, victim-specific crime that justifies mutual legal assistance, joint task forces, and — per Nigeria's Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024, which explicitly strengthened international-cooperation mechanisms and tied data retention rules to the Nigeria Data Protection Act (NDPA) 2023 — statutory backing for that cooperation. This is what proportionate cyber-enforcement should look like: targeted at conduct with an identifiable victim, evidenced through specific transactions and credentials, and prosecuted under provisions written to match the harm.
The Same Law, a Different Target
But the NPF-NCCC and the Cybercrimes Act are not only being used this way. Since the 2024 amendment narrowed — but did not eliminate — the Act's Section 24, which criminalizes electronic communication of information 'known to be false' and likely to cause a breakdown of law and order, the Committee to Protect Journalists has documented at least three Nigerian journalists detained since August 2025 alone: Tega Oghenedoro (known by the byline Fejiro Oliver), held since September 18 and unable to meet a ₦15 million bail; Azuka Francisca Ogujiuba, arrested twice in August after publishing a report she was later pressured to retract; and Sodeeq Atanda, detained for eleven hours in September on cyberbullying and defamation counts. CPJ counts five journalists prosecuted under the Act since the reform took effect — a track record CPJ Africa director Angela Quintal has called evidence that 'Nigerian authorities appear stuck in an era where they see the Cybercrime Act as a readily available tool to harass the press,' a concern she frames as particularly live ahead of Nigeria's 2027 general elections.
That contrast is the actual lesson of Operation Seraphim. It is not that Nigerian cybercrime enforcement is uniformly good or uniformly abusive — it is that the same statute and the same police unit can do both jobs, and the difference lies entirely in how narrowly a provision is drafted and how much prosecutorial discretion it leaves unchecked. The Seraphim cases rest on identifiable financial harm: stolen credentials, specific victims, traceable cryptocurrency wallets. The Section 24 cases rest on an official's judgment that a published claim was false and destabilizing — a standard capacious enough to sweep in accurate but embarrassing corruption reporting, as it reportedly has.
What Should Change
Nigeria does not need to choose between fighting cybercrime and protecting a free press; the NPF-NCCC's own casework this month proves the two are not in tension when the underlying law is precise. The fix is not to defund or distrust cross-border fraud cooperation — expanding NPF-NCCC's capacity and deepening NCA/City of London Police-style partnerships is exactly the direction other African and Asian jurisdictions building out national cybercrime centers should copy. The fix is narrower: Nigeria's National Assembly should revisit Section 24's 'false information' standard and replace its subjective public-order test with an objective, harm-specific one — mirroring the evidentiary rigor already on display in the Seraphim prosecutions. SERAP and the Nigerian Guild of Editors have already called for exactly this. Until that happens, every genuinely impressive fraud takedown will keep sharing a headline with a press-freedom case built on the same law.