Cybercrime & Digital Rights
The Cybercrimes Act is the principal law for offences committed with computers and networks in Nigeria, from fraud and identity theft to unlawful access to systems.
Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended)
Our explanation, written for a general reader. It is not the text of the law.
The Act creates a framework for offences that older criminal law handled awkwardly: unauthorised access to computer systems, electronic fraud, identity theft, and interference with critical information infrastructure. It also places obligations on institutions to protect systems and to cooperate with lawful investigations.
Everyday exposure is usually on the victim side. Account takeovers, impersonation, payment redirection and phishing are ordinary cybercrime patterns, and the practical response — preserve evidence, report quickly, notify the institution — comes from the way these cases are actually investigated.
The Act has been amended, and some of its provisions touching online speech have been the subject of sustained public debate and litigation. Where speech is involved, this is an area to take advice on rather than to reason about from a summary.
Where the official text lives, beside what it means in ordinary language.
Official text
Unlawful access to a computer system
Cybercrimes (Prohibition, Prevention, etc.) Act 2015 — offences against computer systems
Plain language — our explanation
Accessing a computer system without authorisation is an offence, and the Act treats access aimed at obtaining data more seriously.
Official text
Electronic fraud and identity theft
Cybercrimes (Prohibition, Prevention, etc.) Act 2015 — fraud and identity offences
Plain language — our explanation
Using electronic means to defraud, or assuming another person's identity online, are offences under the Act.
Official text
Duties of institutions
Cybercrimes (Prohibition, Prevention, etc.) Act 2015 — duties of service providers and financial institutions
Plain language — our explanation
Institutions carry obligations around securing systems, retaining certain records and assisting lawful investigations.
In real life
A supplier's email is compromised and a customer pays an invoice into a substituted account.
This is a recognised electronic-fraud pattern. Speed matters: the bank and the police both need to be told immediately, with the original messages preserved.
In real life
Someone creates a profile in another person's name to solicit money from their contacts.
Impersonation online is squarely within the Act's identity provisions, and screenshots with URLs and timestamps are the evidence that carries it.
What you should do
What you should not do
“Online fraud is not real theft.”
The Act treats computer-related fraud as criminal conduct in its own right, with its own offences and penalties.
“Nothing can be done once money has left the account.”
Outcomes vary, but speed of reporting materially affects what the institution and investigators can attempt.
What this instrument was, what changed, and what is in force now. Superseded versions are kept on the record rather than deleted.
What changed
If you have read about this Act and free expression, check which version the discussion is about — the provision at the centre of that argument has been amended.
What changed
When to speak to a lawyer