NDPC Warns Public Against Malicious Messages Impersonating Public Institutions, Suggests Safeguards

Itunu Dosekun
Mr. Itunu Dosekun, Head, Media Unit, Nigeria Data Protection Commission
3 min read

The Nigeria Data Protection Commission (NDPC) has warned members of the public against malicious electronic messages falsely claiming that recipients have violated traffic rules or committed related offences and has outlined measures that can be taken to mitigate or avoid any potential harm from acting on such messages.

The Commission, in a General Data Protection Advisory issued on September 18, 2026, and signed by Mr. Itunu Dosekun, Head of its Media Unit, as a public safety message titled: “BEWARE OF MALICIOUS ELECTRONIC MESSAGES,” said it had observed an increase in malicious communications being used to deceive unsuspecting members of the public.

According to the advisory, the messages, which were previously transmitted largely through phishing emails but are now being disseminated through various electronic channels, are designed to create fear or a sense of urgency, with the aim of inducing recipients to click on malicious links, disclose personal information, or comply with harmful instructions.

The NDPC urged members of the public not to click links or follow instructions contained in messages that cannot be independently verified.

The Commission advised recipients of suspicious messages to first examine the sender’s address, domain name, and links before taking any action, adding that individuals should not click a link or follow an instruction unless they are “absolutely certain” that it originates from a legitimate authority or organisation.

It also advised members of the public to conduct independent verification by contacting the organisation or authority identified in a suspicious message through a known and trusted telephone number, website, or email address.

The NDPC specifically cautioned recipients against using contact details supplied in suspicious messages to verify their authenticity and urged members of the public to report suspicious messages and attempts at impersonation to the Commission, as well as the organisation or authority being impersonated.

It advised individuals, as an additional security measure, to use strong, unique passwords for their online accounts and avoid using the same password across multiple services.

In addition, the Commission recommended that passwords be changed promptly whenever there is a suspicion that an account may have been compromised and urged the public to activate multi-factor authentication (MFA) wherever it is available, describing the security measure as providing an additional layer of protection beyond passwords.

It stressed that members of the public should not allow fear, urgency, or the appearance of official authority to pressure them into clicking links or disclosing personal information, warning “If you cannot independently verify a message, do not act on it.”

The Commission emphasized that the protection of personal data is a shared responsibility.