The National Identity Management Commission (NIMC) has denied claims that Nigerians’ National Identification Numbers (NINs) and other personal information were exposed or put up for sale online, as it ordered an investigation into the allegations.
The commission’s response followed a video circulating on social media claiming that citizens’ identity information had been compromised and was being offered for sale. In a statement issued in Abuja on Wednesday, NIMC’s Head of Corporate Communications, Kayode Adegoke, said the commission’s systems remained protected and urged Nigerians to disregard unverified information that could cause unnecessary concern about the safety of their personal data.
Adegoke said NIMC had measures in place to protect NINs and other personal information contained in the National Identity Database.
“Our systems are protected and the commission remains committed to ensuring the safety and security of citizens’ identity information,” he said.
He added that the commission would continue to strengthen its measures against unauthorised access to the database.
“NIMC takes the protection of citizens’ personal data seriously and will continue to strengthen measures against unauthorised access,” Adegoke said. Despite rejecting the breach claims, NIMC said it had commenced a comprehensive investigation to determine whether the allegations had any connection to its licensed agents.
According to the commission, its Director General, Abisoye Coker Odusote, ordered the investigation to establish whether any of NIMC’s tokenisation verification agents breached their licensing agreements. The investigation will also examine whether any breach of the agreements occurred directly through the agents or through sub licensees operating under them. Coker Odusote reaffirmed the commission’s responsibility to protect the identity information entrusted to it and uphold data protection and privacy standards.
“NIMC will continue to work with relevant stakeholders to ensure that the identity information entrusted to the commission is properly protected,” she said.
The commission also advised Nigerians to use only approved channels for NIN verification and other identity related services. NIMC said it would continue working with relevant stakeholders to strengthen the protection of citizens’ identity information and uphold data privacy. The latest allegation comes amid previous concerns over the security of Nigeria’s national identity database. In March 2024, the Nigeria Data Protection Commission investigated allegations of unauthorised access to NIN data after reports that a private website, XpressVerify.com, could retrieve Nigerians’ personal information.
NIMC subsequently restricted licensed agents’ access to its NIN database while the investigation continued. In June 2024, the commission also announced mandatory security vetting for its licensed Front End Partners and verification agents as part of efforts to improve the security of the database. The security of NIN data has become increasingly important as the number of services linked to the national identity system expands.
In June 2026, President Bola Tinubu signed the NIMC Act 2026 into law, replacing the 2007 legislation and expanding the commission’s powers over Nigeria’s digital identity infrastructure. The new law retains the NIN as the country’s foundational identity credential while providing enhanced protections for personal data.
For now, NIMC says its systems remain protected, while the investigation is expected to establish whether any licensed agent or sub licensee breached the conditions governing access to the commission’s identity systems.




