The N100 Question NIMC Keeps Having to Answer 

Last week, a video started circulating with a claim serious enough to spook anyone carrying a National Identification Number: that NIN and BVN details, the same information tied to your bank account, your SIM card, and your tax records, could be bought for as little as N100, and that NIMC officials in Lagos were personally selling citizens’ data for N1,000 outside the commission’s own office. The National Identity Management Commission responded fast and flatly. False and unfounded, they said. The National Identity Database has not been breached or compromised at any point.

Ordinarily, a firm denial from the agency in charge would be the end of it. But NIMC’s own statement contains the detail that keeps this story alive past a single news cycle: they noted the claims were “recycled” from a report published in 2024, one they say they’d already debunked. That’s true, as far as it goes. But the 2024 report wasn’t an anonymous video or a WhatsApp forward. It came from Paradigm Initiative, a respected digital rights organization, which found that sensitive data belonging to prominent Nigerians was being sold online which was credible enough that it reportedly led to a lawsuit against NIMC over digital rights breaches. So the honest framing isn’t “a viral rumor resurfaced.” It’s “NIMC has now had to deny nearly the same allegation twice, from two very different kinds of sources, a year and a half apart.” That’s a much harder thing to wave away with one statement on X.

2021: NIMC is first accused of negligence after a self-service identity verification app is breached, with personal data reportedly turning up for sale on the dark web. NIMC’s response, then as now, is denial.

March 2024: Investigative outlet FIJ.ng exposes XpressVerify.com.ng, a private website with access to registered Nigerians’ data, commercializing it for profit. NIMC denies XpressVerify was ever a licensed partner. A Nigeria Data Protection Commission investigation later finds NIMC’s security infrastructure compliant but attributes the breach to access abuse by an NIMC agent. Not a systems failure. A person with legitimate access, misusing it.

June 2024: Paradigm Initiative goes further and proves it. Researchers don’t just allege a breach, they buy the evidence. Executive director Gbenga Sesan’s team purchases the NIN slip of Bosun Tijani, Nigeria’s own Minister of Communications, Innovation, and Digital Economy, for N100. Then they buy the NIN slip of Vincent Olatunji, the country’s top data protection regulator, the person literally in charge of preventing exactly this. Both slips, they say, were confirmed as genuine NIMC data. The website responsible, AnyVerify.com.ng, had been running since November 2023 and had logged nearly 568,000 visits in a single month.

July 2024: Paradigm Initiative moves to the Federal High Court in Abuja, filing public-interest litigation naming NIMC as the first respondent, alongside eight other agencies, including the CBN, INEC, and FIRS.

September 2026: A new video alleges the same thing is still happening, and BVN details sold for N100–N1,000, officials allegedly complicit. NIMC denies it, again, calling it “recycled” from the 2024 report.

For the average Nigerian, a NIN isn’t optional. It’s mandatory infrastructure tied to SIM registration, bank verification, passport applications, exam registration, and even pension access. There’s no realistic opt-out if you want to function in the formal economy, which is exactly what makes a breach of this system different from a breach anywhere else: you can’t simply stop using it.

That captive-audience reality is what made the Paradigm Initiative demonstration land as hard as it did. When researchers bought the NIN slip of Nigeria’s own data protection commissioner for N100, the message to every ordinary citizen was blunt: if the person whose literal job is protecting your data can’t protect his own, what chance does yours have? For the average person, that’s not an abstract privacy debate; it’s the realistic possibility that someone can pull your BVN, apply for a loan in your name, port your SIM, or pass identity verification as you, all for less than the cost of a bag of sachet water.

The corrosive part is what happens next, even among people who were never personally affected. Trust doesn’t need a majority of citizens to be breached to erode; it just needs enough credible cases that everyone starts asking, “Could that be me next?” Once that question takes hold, people become cagier about sharing their NIN, slower to complete verification steps that already frustrate them, and more suspicious of every institution that asks for it, even the ones that were never involved. NIMC doesn’t just risk its own credibility here. It risks becoming the weak link every other system built on top of the NIN now has to quietly account for.

Here’s where this story gets genuinely uncomfortable for the businesses that were supposed to be protected by all this identity infrastructure in the first place: BVN and NIN integration is credited with cutting Nigeria’s digital lending fraud losses by 51%, from ₦52.26 billion in 2024 to ₦25.85 billion in 2025, which is a real, measurable win, and the CBN has staked its entire anti-fraud strategy on this identity rail continuing to hold.

But the EFCC’s own investigations show the exact same identity system being actively undermined from the inside. Authorities uncovered a scheme involving more than 12,000 young Nigerians operating as “Account Suppliers,” convincing individuals to hand over their BVN, NIN, and biometric data for ₦1,500–₦2,000 each of this data that was then resold to fintech companies for roughly ₦5,000 per person. That’s not a hypothetical risk from a viral video. It’s a documented pipeline where the same identity data NIMC insists hasn’t been compromised is being harvested and sold at an industrial scale, with fintechs themselves sitting on the buying end of some of it, whether knowingly or through compromised onboarding partners.

For a bank or fintech, that’s the real cost: every fraud-reduction gain the sector has booked from BVN-NIN integration is only as solid as the data underneath it, and that data has now been shown, repeatedly, to leak through insider access rather than sophisticated hacking. A lender extending credit off a “verified” BVN can’t fully price the risk that the identity behind it was harvested for ₦1,500 rather than genuinely confirmed. Compliance teams end up building extra layers of biometric and behavioral checks, increasing real operational cost specifically to compensate for a national identity system that keeps needing to defend its own integrity instead of simply providing it.

There’s a sharper irony sitting underneath all of this too: the same fintech sector that benefited most from the BVN-NIN fraud crackdown is, per the EFCC’s findings, also a buyer in the black market that undermines it. Nigeria’s businesses aren’t just victims of a leaky identity system; some are quietly part of the demand keeping the leak profitable.

Zoom out far enough, and this stops being a story about one viral video and becomes a story about how much international capital is riding on Nigeria’s identity system actually being trustworthy. The World Bank’s Digital Identity for Development (ID4D) project has committed $430 million to building out Nigeria’s national ID infrastructure, with a target of 180 million registered NINs by December 2026, a scale the World Bank itself has said could position Nigeria as a benchmark for digital identity across Sub-Saharan Africa, rivaling India’s Aadhaar system in scope. As of mid-2025, enrollment stood at around 121–127 million, meaning NIMC is racing to onboard tens of millions more people in the final stretch of a multi-year, multi-donor investment.

That’s the part easy to miss in the noise of a single denial: every one of those new enrollments is being asked to hand over the exact category of data—biometrics, NIN, BVN that recurring reports say has already leaked at least four times since 2021. The World Bank isn’t just funding server capacity and enrollment centers; it’s funding a system whose core value proposition is that citizens can trust it enough to use it for banking, government aid, and digital transactions. Every credible breach report chips at the thing the entire $430 million investment depends on: adoption built on confidence, not just infrastructure built on capacity.

There’s a compounding effect too. Nigeria is explicitly leaning on this identity rail to solve financial inclusion for roughly half of its 210 million citizens, which are disproportionately women, persons with disabilities, and other vulnerable groups who remain outside the formal financial system. That’s the World Bank’s own stated rationale for the project. But identity-driven financial inclusion assumes people find it safer, not riskier, to be captured in the system. A population that’s already skeptical of formal institutions doesn’t need much more than a well-publicized breach story to conclude that staying undocumented is the safer bet, which would undermine the very financial-inclusion goal this entire infrastructure spend exists to achieve.

NIMC’s statement called this a recycled claim, and in one narrow sense, they’re right, and the specific allegation in this video does echo 2024. But “recycled” implies something stale, something already resolved. What the timeline actually shows is a pattern that hasn’t gone away long enough to be recycled from a 2021 dark web breach, a 2024 unauthorized reseller confirmed by researchers who bought a sitting minister’s own NIN slip for proof, a 2024 lawsuit still working through Nigeria’s courts, an EFCC investigation into 12,000 people harvesting and reselling identity data at an industrial scale, and now, in 2026, a new round of the same core allegation. That’s not a rumor resurfacing. That’s an unresolved problem being rediscovered.

The stakes go well past reputational damage. A $430 million World Bank investment, a national push toward 180 million enrolled citizens, and Nigeria’s own financial inclusion targets are all quietly betting that ordinary people will trust this system enough to keep showing up for it even as the evidence mounts that showing up carries real risk. NIMC can keep issuing denials each time a new version of this story surfaces. What it hasn’t yet done is explain why, five years and several confirmed incidents later, it keeps having to.

That’s the question worth leaving readers with, and it’s not one Business Verge needs to answer for them: is this a system that’s fundamentally sound and unlucky enough to keep making headlines for isolated incidents, or is it a system whose scale has outgrown its ability to actually secure what it collects? Both readings are still on the table. What isn’t in question anymore is whether NIMC has a documented history here. It does.