Nigeria’s National Identity Management Commission (NIMC) has rejected claims that the National Identification Number (NIN) database was hacked, calling the allegations “false and unfounded.” The commission used the moment to spotlight NINAuth, a new identity verification platform it says will tighten data security going forward.
What sparked the claims
A video circulating on WhatsApp and X alleged that NIN and Bank Verification Number (BVN) details could be bought for as little as N100, and that some NIMC staff in Lagos were selling people’s NIN information for N1,000 outside the commission’s office. The clip stirred real public anxiety, given that the database holds biometric and personal records for more than 100 million registered Nigerians.
NIMC pushed back hard. In a statement issued through its Head of Corporate Communications, Kayode Adegoke, the commission said the video was not new. It described the footage as a recycled version of a claim first made in 2024, one it had already investigated and debunked at the time.
“The Commission wishes to state, categorically, that this claim is false and unfounded,” the statement read, adding that the National Identity Database (NIDB) “has not been breached or compromised at any point.”
NIMC’s security assurances
The commission said it maintains a multi-layered security framework built around international standards, and it urged Nigerians to get information about the identity system only from its official channels rather than social media. NIMC also said it would keep working with security agencies to strengthen its systems and to counter misinformation as it spreads.
Enter NINAuth
Alongside the denial, NIMC used the statement to promote NIN Authentication, or NINAuth, a verification service it recently rolled out across web, API, and mobile channels. The commission describes it as the official gateway for third parties to connect with its backend infrastructure, built to add a stronger layer of protection while giving individuals more say over how their data is used.
The core feature is consent. Under NINAuth, a NIN holder must explicitly authorise any sharing of their data before it can be used for Know Your Customer (KYC) checks or other verification purposes. NIMC says this lets people confirm their identity for things like SIM registration, immigration and passport processing, tax filing, and financial transactions, without exposing their raw NIN or other personal details in the process.
The commission tied the launch directly to its legal obligations, saying NINAuth reflects requirements under the newly signed NIMC Act 2026 and the Nigeria Data Protection Act (NDPA) 2023, both of which mandate fair, lawful, and transparent handling of citizens’ personal data.
Why it matters
Even with the breach claims dismissed as recycled misinformation, the episode lands at a sensitive moment. NIN has become deeply embedded in everyday digital life in Nigeria, tied to banking, telecoms, travel, and now tax administration, which means any whiff of a data leak spreads fast and lands hard. By pairing its denial with a concrete new product, NIMC appears to be betting that a functioning consent-based verification system will do more to reassure the public than a statement alone.
Whether NINAuth changes public trust in practice will depend on adoption by banks, telecom operators, and other agencies that rely on NIN verification, and on whether future incidents, real or rumoured, get handled with the same speed.



