Nigeria’s expanding digital ecosystem is facing increasing cybersecurity pressure, with Kaspersky, a cybersecurity firm, recording more than 1.6 million attacks from online resources targeted at users in the country during the first half of 2026.
The figure, contained in the latest threat intelligence report by Kaspersky’s Global Research and Analysis Team (GReAT), highlights the growing risks accompanying Nigeria’s rapid digital adoption as more individuals, businesses and institutions rely on internet-based services for financial transactions, communication and business operations.
According to the report, Nigeria ranked among the countries with significant exposure to web-based threats across the Middle East, Türkiye and Africa (META) region, with 18.4 per cent of users affected by online attacks during the period under review.
Türkiye recorded the highest proportion of users targeted by web threats in the region at 22.8 per cent, followed by Kenya with 21.2 per cent, Qatar with 19.3 per cent, Nigeria with 18.4 per cent, and South Africa with 17.2 per cent. While Saudi Arabia, Jordan and Pakistan registered the lowest share of users targeted by web-borne attacks in the region.
The cybersecurity firm said the growing sophistication of attacks is being driven by a combination of rapid technological adoption, artificial intelligence (AI) development and global economic uncertainties, which are creating new opportunities for cybercriminals.
As organisations increasingly adopt digital platforms, cybersecurity experts warn that the expanding online environment is also widening the potential attack surface for malicious actors.
One of the major developments identified by Kaspersky is the increasing use of artificial intelligence by cybercriminals to improve the speed, scale and effectiveness of their operations.
The report noted that threat actors are already using large language models to create phishing emails, generate malicious code and support various stages of cyber operations.
Beyond social engineering attacks, AI is also becoming a tool for malware development, with researchers observing cases where threat actors have used AI-generated components to build malicious software capable of stealing data, encrypting files and manipulating systems.
Kaspersky researchers pointed to campaigns linked to the FunkSec group, which deployed malware designed for data theft, encryption and process manipulation, as well as the RevengeHotels campaign in 2025, where large language models were reportedly used to generate parts of malware code.
Sergey Lozhkin, head of the Global Research and Analysis Team for APAC and META regions at Kaspersky, said AI would remain one of the biggest forces shaping the cybersecurity landscape in 2026.
“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” Lozhkin said.
He explained that by reducing the time and resources required to develop and modify malicious tools, AI is enabling attackers to move faster and expand their activities.
Beyond AI-driven malware, Kaspersky identified several emerging threats that organisations need to monitor, including the increasing misuse of legitimate cloud services for data theft.
According to the report, cybercriminals are increasingly using cloud storage and file-sharing platforms to move stolen information because such services can blend into normal business traffic, making detection more difficult.
The report also highlighted the changing nature of ransomware attacks, noting that some cybercriminal groups are shifting from simply encrypting data to disrupting business operations in order to increase pressure on victims.
Another emerging concern is the security risk associated with AI agents, which are increasingly being granted access to business systems and sensitive information.
Kaspersky warned that compromised AI agents could potentially be manipulated by attackers through changes to their configurations or instructions, turning trusted workplace tools into channels for unauthorised access.
The company also identified malicious AI skills as a new attack vector, where attackers exploit compromised AI tools to manipulate their behaviour, extract sensitive information, carry out unauthorised activities and maintain access to systems.
The rise in cyber threats comes as Nigeria continues to deepen its digital transformation, with increased adoption of online banking, fintech platforms, e-commerce services and cloud-based business solutions.
Industry stakeholders have repeatedly stressed that the growth of the digital economy must be matched with stronger cybersecurity investments, including improved threat monitoring, employee awareness and faster response mechanisms.
Kaspersky recommended that organisations strengthen their cybersecurity frameworks through continuous vulnerability management, timely software updates, employee training, threat intelligence and advanced security solutions capable of detecting AI-assisted attacks.
As cybercriminals continue to adopt emerging technologies, experts say businesses and individuals will need to move beyond traditional security measures and adopt more proactive approaches to protecting digital assets.





