You fit follow Dalu advice for midnight come go sleep. When you wake up for morning, alaye don dump the philosophy leave you inside gutter.
You’ll wake up like:
LAGOS NIGERIA!
I’m announcing my first ever headline shows here, and we have made sure this homecoming will be special. Sign up for early access here! https://t.co/6RTJy6ubeT
Three weeks ago, a threat actor called ByteToBreach walked through Nigeria’s financial infrastructure using a single unpatched vulnerability at Sterling Bank as the door.
What followed was nine days of undetected access with core banking data, sensitive customer information and employee records exfiltrated before the actor pivoted into Remita, Nigeria’s government payment backbone.
From Remita they took everything.
3TB of data.
Including sensitive and personal information of over a million Nigerians (across both breaches).
I spent the last week reconstructing the full attack chain from the artefacts the actor published.
I have now produced a narrative investigation on my new substack and a technical analysis on @WebSecurityLab covering the complete breach from the first CVE exploit to the published HSM key directory.
This was published in the hope that the lessons from these events prove more durable than the events themselves.
Security failures of this scale are painful.
They are also, when documented carefully and honestly, among the most valuable contributions one can make to an ecosystem that is still maturing.
Nigeria’s banking story is one of the most compelling in the world.
It deserves a security culture to match.
Read the full investigation here:
https://t.co/1YwFS7I6Eu