Nigeria Nigeria cybercrime social media NCC

Nigeria's Sextortion Advisory Is Right to Stress Reporting, but Platform Accountability and Clear Law Must Follow

NITDA's October 2 warning on AI-faked explicit images is useful public education. Real protection needs precise criminal law and fast platform response, not speech-chilling rules.

Sextortion Figures Cited in NITDA's Advisory People of Internet Research · Nigeria 54,000+ FBI-recorded victims, 2024 Up from about 34,000 in 2023, as c… ~$65M Losses tied to Nigerians Over two years, as cited in the ad… Feb 28, 2024 Cybercrimes Act amended Most recent amendment of the 2015 … peopleofinternet.com
Sextortion Figures Cited in NITDA's Ad… People of Internet Research · Nigeria 54,000+ FBI-recorded victims, 2024 ~$65M Losses tied to Nigerians Feb 28, 2024 Cybercrimes Act amended peopleofinternet.com

Key Takeaways

On October 2, 2026, Nigeria's National Information Technology Development Agency (NITDA), acting through its Computer Emergency Readiness and Response Team (CERRT), warned of rising sextortion threats. The advisory, reported by Nairametrics, says criminals can now use AI to create convincing fake explicit images without holding any real intimate image of the victim. It adds that schemes often begin on social media, messaging, dating and gaming platforms. It follows the October 1 launch of the 2026 National Cybersecurity Awareness Month.

The strongest case for tougher intervention

The case for a firmer state response is serious. Sextortion has always relied on shame and secrecy, and generative AI removes the last barrier to entry: an offender no longer needs a victim to have sent anything. A public photo is enough raw material. Children and teenagers are the most exposed, because fear keeps them silent. A regulator that waits for perfect evidence of harm before acting will always be late. Advisories are cheap, and a state with limited investigative capacity is right to use every tool it has.

That argument deserves respect. The question is which tools actually work.

What the advisory gets right

The guidance is practical and proportionate. According to the Nairametrics report, NITDA tells victims to save evidence (screenshots of messages, usernames, payment requests and account details), stop contact, report the account and content to the platform, avoid paying, and report to the Nigeria Police Force cybercrime unit. This is sound advice. Paying rarely ends demands, and preserved evidence is what makes prosecution possible.

The advisory also cites outside figures. As reported, it points to FBI data showing more than 54,000 sextortion victims in 2024, up from about 34,000 in 2023, and roughly $65 million in losses over two years tied to Nigerian nationals. We could not trace these figures to their original publications, so treat them as the advisory's claims. They do show that Nigeria is cast as both a victim country and an origin point, which gives the state a reputational stake in getting enforcement right.

Where policy has to go beyond awareness

An advisory is not a remedy. Three gaps matter.

First, the criminal law has to be precise. Nigeria's Cybercrimes (Prohibition, Prevention, etc.) Act 2015 includes provisions on child pornography and cyberstalking, and it was amended on February 28, 2024. Its cyberstalking provision, section 24, has a troubled history. The ECOWAS Court of Justice found section 24(1) violated freedom of expression, and an academic study of section 24 describes the original offence as one that did not clearly define its elements. The study credits the 2024 amendment with better safeguards but says it does not fully secure digital rights. The lesson for sextortion is straightforward. The conduct that should be criminal is coercion for money or further images, and creating or threatening to distribute non-consensual intimate imagery, whether real or synthetic. It should not be vague offences about "annoying" or "offensive" messages, which have been used against journalists and critics. Lawmakers should confirm that synthetic imagery is plainly covered, and that the offence is defined by the coercion and the harm, not by the content of speech.

Second, platforms need to respond quickly, and the rules should be narrow. The advisory tells victims to report to platforms, which puts the burden on the person least able to carry it. The workable approach is a fast-response duty tied to specific notices. That means timely removal of non-consensual intimate imagery once a victim or the police flag it, with a clear route to appeal wrongful takedowns. Broad monitoring mandates or proactive scanning of private messages would be a mistake. They would weaken encryption and expose the whole user base to surveillance, to catch a crime that is mostly arranged in private channels. Targeted, notice-based duties protect victims without turning intermediaries into censors.

Third, victim data deserves real protection. Sextortion evidence is among the most sensitive personal data a person can hold. The Nigeria Data Protection Act 2023, enforced by the Nigeria Data Protection Commission, sets a higher standard of care for sensitive personal data, including data about a person's sex life. Agencies handling victim reports, from CERRT to the police, should treat that evidence under those rules. If victims fear that reporting means their images circulate through an investigation, they will not report.

Capacity matters more than new offences

Nigeria does not obviously need a new statute. The 2024 amendment is recent, and stacking new offences onto an unsettled framework invites the same overbreadth problems that followed section 24. What it needs is investigative capacity and process. That means trained police cybercrime units, clear evidence-preservation steps, working relationships with platforms' law-enforcement teams, and cross-border cooperation, since many sextortion operations span jurisdictions. Awareness campaigns such as Cybersecurity Awareness Month are a reasonable start, but they should be measured by outcomes: reports filed, accounts taken down, cases prosecuted.

A pro-innovation reading

The AI-fakes angle can push policy toward blunt instruments, such as restrictions on image-generation tools or mandatory identity verification for social platforms. Both would hit the large majority of legitimate users and developers, and neither would stop determined criminals, who can use tools hosted abroad. The better target is the harm: coercion, extortion, and non-consensual distribution. Those are already wrongs the law can describe. Pairing narrow criminal provisions with fast victim-centred takedown, protected reporting channels and funded enforcement lets Nigeria address the threat without damaging its open internet or its growing tech sector.

NITDA's advisory is a good first step because it tells people what to do today. The test is what follows. If the next move is a precise legal clarification and better enforcement, Nigeria will protect victims. If it is another broad speech offence, it will repeat the section 24 mistake.

Sources & Citations

  1. Nairametrics: NITDA sextortion advisory
  2. Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended 2024)
  3. Nigeria Data Protection Act 2023 (NDPC)
  4. Study of section 24 of the Cybercrimes Act