The National Identity Management Commission (NIMC) is facing intense scrutiny over allegations that sensitive identity information of Nigerians is being sold on the black market. This controversy arose after a video shared on social media platform X on September 22 by digital rights and advocacy organisation GST showed an individual offering access to Bank Verification Numbers (BVN) and National Identification Numbers (NIN) for a fee as low as ₦250.
The video highlighted findings previously documented by the Foundation for Investigative Journalism (FIJ), which has been investigating illegal data harvesting operations involving Nigerians' personal information. According to FIJ, the individual featured in the viral video, Timothy Ebi, had earlier been exposed by the organisation for allegedly accessing and selling Nigerians' data through unauthorised channels.
FIJ reported that despite the earlier investigation, the alleged operator continued operating and was also offering paid training sessions on how to access BVN and NIN services for ₦60,000. Following the widespread circulation of the video, NIMC announced an internal investigation into possible breaches involving its verification ecosystem.
The Director-General of NIMC, Abisoye Coker-Odusote, ordered a comprehensive investigation into whether the commission's tokenisation verification agents violated licensing agreements by allowing unauthorised access, either directly or through illegal sub-license arrangements. However, questions have been raised over the timing of the commission's response, with claims that NIMC had been contacted before the publication of its findings.
According to FIJ, the organisation had written to NIMC with details of the alleged operator and sought clarification on the activities of NIMC's licensed partners before publishing its investigation. This development has raised concerns over whether warnings about possible abuse within the identity verification system were acted upon before the issue became a public controversy.
FIJ's earlier investigation published in June had alleged that some licensed Front End Partners (FEPs), including one identified as NEXTGEN, had allowed verification tokens to be accessed by unauthorised third parties through sub-leasing arrangements. This alleged practice raised concerns that individuals outside approved channels could gain access to services designed to verify Nigerians' identities.
Nigeria's National Identity Database currently contains records of more than 100 million registered NINs, making any unauthorised access to identity information a major concern for citizens. NIMC has repeatedly maintained that its database remains secure and that the ongoing investigation will determine whether any licensed partners breached operational guidelines.
Key points
- NIMC is investigating possible breaches involving its verification ecosystem.
- The controversy raised concerns over the security of Nigeria's National Identity Database.
- FIJ had alerted NIMC about the alleged operator before publishing its findings.