← Remita

2026 Remita — NDPC investigation (alleged cloud/KYC leak; ByteToBreach claims; Apr 1)

2026 Unknown records affected Share on X

Data compromised

Potentially KYC documents and financial identity data if claims are substantiated

Technical writeup

In April 2026, Nigeria’s National Data Protection Commission (NDPC) served formal notices of investigation on Remita Payment Services Ltd. and related ecosystem parties following dark-web and cyber-intelligence claims attributed to actors such as “ByteToBreach.” Press citing regulatory statements and industry commentary described alleged exposure of large volumes from cloud-linked environments, including Know Your Customer–style documents (IDs, passports, bank statements) in unconfirmed aggregate figures (e.g., multi-terabyte claims in secondary reporting). NDPC framed the work as assessment of personal data categories, scope, safeguards, and mitigation under the Nigeria Data Protection Act 2023; outcomes and verified victim counts were pending at listing time. Sterling Bank was investigated in parallel (see sterling-bank-nigeria2026-ndpc).

Root cause

Under regulatory investigation; alleged unauthorized access per threat claims (not finally adjudicated in public sources)

References