Over 24.3 Million Nigeria Suffered Over 24.3 Million Leaked Account  in Q1 2026 in Sub-Sahara Africa

Over 24.3 Million Nigeria Suffered Over 24.3 Million Leaked Account  in Q1 2026 in Sub-Sahara Africa

The latest data from cybersecurity company Surfshark ranks Nigeria as the 38th most breached country in H1 2026, with 390.8k leaked accounts.

Globally, a total of 313.4 million accounts were breached, with the US ranking first and amounting to 29% of all breaches from January through June.

France takes second place, while Brazil is third, followed by India and the UK.
Surfshark’s data also highlights a notable regional shift: Europe surpassed North America in the number of breached accounts during the previous quarter. In Q2 2026, 1 in 3 breached accounts worldwide came from Europe, and 58% of those within the region were linked to France.

In addition, 4 out of 5 countries with the highest breach density (number of leaked accounts per 1,000 residents) are also European: 1st is France, then Poland, the US, Portugal, and Lithuania.

“Information taken in breaches years ago can remain in circulation for a long time, resurfacing in new fraud schemes, and used to target people long after the original incident.

The same is true for data being stolen today: even if it is not abused immediately, it can still come back years later in the form of account takeovers, identity abuse, scams, and financial theft,” says Tomas Stamulis, Chief Security Officer at Surfshark.
Since 2004, Nigeria is the 3rd in Sub-Saharan Africa, with 24.3M compromised user accounts.
A total of 7.5M unique emails were breached from Nigeria. 13M passwords were leaked together with Nigerian accounts, putting 54% of breached users in danger of account take over that might lead to identity theft, extortion or other cybercrimes.
Statistically, 10 out of 100 Nigerian people has been affected by data breaches.
In order to stay safe online and limit your exposure, Tomas Stamulis shares his tips :
  • As a general rule, treat all your personal information as sensitive by default and disclose it only when absolutely required.

  • Share your real personal details only when there is a genuine, necessary reason, such as completing official or legally required forms.

  • For everything else, limit your exposure by using an alias, a secondary email address, or an email-masking service.

The latest update for Surfshark’s
administrator

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *