2026 EFCC (Nigeria) — forum claims of operative phones, codes, password hashes (Apr)
Data compromised
Staff identifiers, phones, password hashes per reporting—sensitivity extreme
Technical writeup
In late April 2026, Nigerian trade press and OSINT accounts described a dark-web posting alleging exposure of Economic and Financial Crimes Commission internal directory–style material, including usernames, phone numbers, agent or operational codes, and password hashes, sometimes attributed to personas such as “ki4t” / Nullsec Nigeria in summaries. Nigerian CommunicationWeek and social alerts framed the episode as high-risk for law-enforcement operational security even where full authenticity remained contested.
Root cause
Criminal forum exfiltration claim; possible insider or web-app compromise (unconfirmed)