Inside the New AI Economy Turning Ordinary Nigerians into Digital Targets

Artificial intelligence is transforming how people work, communicate and create. But behind its growing popularity lies a darker economy, one where personal data has become a valuable commodity and where cybercriminals are increasingly exploiting AI-powered tools to impersonate trusted contacts, clone voices, create deepfake videos and steal digital identities.

A Diamond Media investigation found that while millions of Nigerians willingly upload photographs, videos and voice recordings to social media and emerging “data-for-pay” platforms, many remain unaware that the same information can be used to train AI systems or, in the wrong hands, facilitate sophisticated fraud.

Interviews with cybersecurity experts, digital literacy specialists, lawyers and victims, alongside an examination of online marketplaces advertising deepfake software, voice-cloning tools and hacked social media accounts, reveal how the country’s rapidly expanding digital footprint is creating new opportunities for identity theft and financial crime.


By Collins Odigie Ojiehanor


When Nelson Bridget’s phone rang that afternoon, nothing about the conversation felt unusual.

The voice belonged to someone she knew and trusted. A close friend appeared on a video call, sounding distressed as she explained that a family emergency had left her desperately in need of money.

“I was on a WhatsApp video call with my friend, and she told me she needed some money to add to what she already had because there was a family emergency she needed to attend to,” Bridget recalled.

The request seemed genuine.

“She asked if I could loan her ₦300,000.”

Without hesitation, Bridget transferred the money.

“I actually sent the money because the voice was real and it was even a video call.”

Everything pointed to a normal conversation.

“Everything seemed normal. It sounded like her. It looked like her. There was no reason for me to think something was wrong.”

The truth emerged later.

“I was shocked when I found out that my friend’s phone had been stolen the day before.”

The person she believed she had spoken to was not her friend.

“She wasn’t the one on the call.”

That experience fundamentally changed how she responds to urgent requests for money.

“I learned that even when something looks real, sounds real, or appears to come from someone you know, you still have to verify before acting.”

Bridget’s experience is no longer an isolated case. As artificial intelligence becomes increasingly capable of cloning voices, generating realistic faces and producing convincing deepfake videos, cybercriminals are finding new ways to exploit trust itself.

Across Nigeria, where millions of people are coming online each day, cybersecurity experts emphasised that ordinary photographs, voice notes and videos are becoming valuable digital assets that can be harvested, copied and weaponised in a rapidly expanding underground AI economy.

The result is a fundamental shift in the nature of cybercrime. The battle is no longer focused only on protecting passwords, bank accounts or digital devices. Increasingly, it is about safeguarding human identity itself.

 

The New Face of Identity Theft

For decades, online fraud depended largely on persuasion. Scammers crafted convincing stories, impersonated bank officials, posed as relatives, or manipulated victims into revealing passwords and account details. Success often depended on patience and human ingenuity.

Today, AI is reshaping that equation. Instead of merely pretending to be someone else, fraudsters can now generate convincing synthetic voices, manipulate photographs, create realistic videos and produce highly personalised messages in seconds.

In March 2025, the Economic and Financial Crimes Commission (EFCC) announced that it secured 4,111 convictions in 2024, the highest annual total since the agency was established.

Alongside recovering billions of naira, millions of dollars and other currencies in criminal proceeds, the Commission warned that cybercriminals are increasingly incorporating emerging technologies, including artificial intelligence, deepfakes and advanced phishing techniques, into their operations.

The threat has continued to evolve. In a case that attracted national attention in Nigeria, the Nigeria Police Force arrested Ifechukwu Dennis in Benin City, Edo State, for allegedly creating and distributing a deepfake AI-generated audio clip falsely attributed to President Bola Tinubu.

The fabricated voice recording claimed the president deliberately allowed insecurity in the South-East and made controversial remarks about the 2023 general election.

Authorities said Dennis extracted footage from an original Instagram video posted by activist Martins Vincent Otse, popularly known as VeryDarkMan, superimposed an AI-generated imitation of the president’s voice and redistributed the altered video as authentic.

The scale of the broader cybercrime challenge is already imposing a significant cost on Nigeria. According to The Guardian Nigeria, the National Information Technology Development Agency (NITDA) estimates that the country loses more than $500 million (about ₦250 billion) annually to cybercrime, including social media-related fraud.

NITDA had earlier disclosed that Nigeria lost approximately ₦129 billion to online identity theft between 2000 and 2013. The agency also reported that 2,175 websites were defaced, including 585 government websites, underscoring the growing sophistication and scale of cyber threats confronting the country.

As Nigerians move more of their financial and everyday activities online, reports from the Nigeria Inter-Bank Settlement System (NIBSS) and the Nigeria Cybersecurity Outlook 2025 point to a more sophisticated threat landscape, with identity theft, account takeovers, AI-generated phishing and deepfake scams evolving alongside the country’s digital economy.

 

The Growing AI-Data Economy

Every day, millions of Nigerians upload selfies to Instagram, send voice notes on WhatsApp, post videos on TikTok, join virtual meetings and grant mobile applications access to their cameras, microphones, contact lists and photo galleries.

To most users, these are ordinary digital activities. To AI developers, technology companies and, increasingly, cybercriminals, they represent something far more valuable.

The growing demand for human-generated data recently came into sharp focus after a consent-to-earn platform, which paid users to upload photographs, videos and voice recordings, withdrew its application from the Nigerian App Store and imposed an IP ban on users in the country.

The platform is among a growing number of data marketplaces designed to crowdsource human content for training AI systems, highlighting the increasing commercial value of personal data in the AI economy.

AI systems are trained using information generated by real people. They learn facial expressions, speech patterns, accents, emotions and behavioural habits by analysing vast quantities of photographs, audio recordings and videos.

That demand has fuelled a rapidly expanding global market in which human data is collected, processed and licensed for commercial and research purposes.

Some datasets are compiled from publicly available online content. Others come from users who unknowingly consent to extensive data collection through lengthy privacy agreements. Some find their way into the ecosystem through data breaches before circulating across poorly regulated digital marketplaces.

Once a person’s face, voice or behavioural profile enters that ecosystem, cybersecurity experts warn that it can be analysed, copied and reused in ways the original owner may never know.

According to penetration tester and cybersecurity analyst Engineer Odinaka Lucky, many people still underestimate the sensitivity of their biometric information.

He said the constant exposure of photographs, voices, irises and other personal information on social media is increasing people’s vulnerability to cyberattacks.

“Biometrics are a fundamental part of authentication and passwords. There is what you have, what you know, and who you are. Biometrics are the exact definition of who you are,” he said.

“Attackers are skilful. Attackers are coming up with new cunning ways to re-engineer biometrics now,” he warned.

He explained that biometric authentication relies on much more than a photograph or fingerprint.

“What most people do not know, and I know this will come as a shock, is that there is a mathematical template behind every biometric. There is a binary mathematical template behind every biometric, and each person has their unique mathematical template that the system assigns to them.”

According to him, cybercriminals are increasingly developing techniques capable of reconstructing those biometric templates.

“If you are a target, they can use your picture, your voice, your fingerprint. A picture of your palm can be enough because fingerprints can be extracted from a picture of your palm.”

In the AI era, faces have become biometric identifiers, voices have become authentication credentials, and the digital content people share every day can become the raw material for sophisticated identity theft and impersonation needed for digital and financial fraud.

 

Who Is Buying Human Data?

According to data and digital literacy expert John Lewis, the market for human data is growing globally as a result of AI, and the buyers extend far beyond technology companies.

“AI developers are among the biggest buyers of human data because they need enormous amounts of data to train their systems. But they are not the only buyers,” he said.

According to him, demand for human-generated data now cuts across multiple industries.

“You have IT companies, AI startups, academic researchers, marketing firms, advertising companies, facial-recognition developers, cybersecurity firms, healthcare researchers, and sometimes government agencies. All of them need data for different purposes.”

Lewis explained that the rapid growth of AI has made human data an increasingly valuable commodity because AI systems depend on vast amounts of real-world information to improve their accuracy.

“AI learns from examples. If you want an AI system to recognise faces, understand accents, detect emotions, or generate human speech, you need huge amounts of real human data to train it.”

He said many people fail to recognise the true economic value of the information they share online.

“The reality is that the data economy is worth billions of dollars globally. Individual pieces of data may appear inexpensive, but when millions of photos, videos, voice recordings, and behavioural patterns are combined, the value becomes enormous.”

According to Lewis, while personal data generates significant commercial value, those who supply it often receive the smallest share of the profits.

“In many cases, the people providing the data are receiving the smallest share of the value chain. The platform collects the data, packages it, processes it, and sells access to organisations that may generate significantly more revenue from it in the future.”

He emphasised the growing reality that in the AI era, personal information is no longer simply a by-product of online activity; it has become a valuable economic asset traded within a rapidly expanding global AI-data economy.

An infographic illustrating how ordinary online activities become valuable datasets used in the AI ecosystem.By Collins Ojiehanor

 

Why Nigerians Are Becoming Increasingly Vulnerable

While Bridget Nelson was deceived by what appeared to be a genuine video call, Jennifer Ibhafidon’s family came face-to-face with another tactic that relied on panic and urgency.

Jennifer recalled how fraudsters targeted her grandmother by pretending to be relatives involved in an emergency at a time when the family was genuinely expecting visitors.

“Someone called my grandmother claiming to be the brother of her soon-to-be sister-in-law,” she said.

The caller claimed they had been involved in an accident and were having problems with the police, sending her grandmother into panic.

“My grandmother was in such a hurry. She was scared.”

Believing her relatives were stranded, she rushed out to buy a recharge card and began looking for money to send.

“My grandmother was still running helter-skelter trying to look for money to send to these people so that they could go to the hospital and maybe resolve the issues they were having with the police on the roadside.”

The deception was uncovered only after other family members questioned the story, called the soon-to-be sister-in-law and realised no one had travelled that day.

“That was how they later discovered that it was a scam.”

Jennifer also recounted her own experience of being deceived online after trusting someone who promised to double any amount invested.

The scammer used videos of a woman living a lavish lifestyle, alongside screenshots of supposed successful transactions sent to people, to appear legitimate.

“The person was posing as a lady. This person would post videos of themselves on WhatsApp; I don’t know where the person got the videos of the lady. The person posted flashy cars, flashy everything.”

To reinforce the illusion, the scammer regularly uploaded screenshots that appeared to show people receiving payments.

“The person would be posting screenshots of transactions made to other people and the responses of the people saying, Thank you, I’ve seen it.”

Tempted by the promise of quick returns, Jennifer sent her last ₦2,000.

“That day it was ₦2,000 for one kind of amount, about ₦10,000 or something. I said to myself that if I got double the amount I sent to them, it would really make me happy. The person sent me a transaction receipt. I checked my account, and there was nothing. I didn’t receive any alert.”

She waited, believing the money might still arrive.

“I waited and waited, but I did not see any money.”

Her concern quickly turned into suspicion.

“This time around, the messages I was sending were only showing one tick instead of the normal two ticks.”

After waiting in vain and noticing her messages were no longer being delivered, she realised she had been blocked.

“I was able to confirm that the person had blocked me when I went ahead to message the same number with my other phone number on WhatsApp, and the message went through.”

“It was then it dawned on me. Ah, what just happened to me? Oh God, they just scammed me of my money.”

Looking back, Jennifer said the experience taught her how easily fraudsters can manipulate trust, create convincing online identities and exploit people’s hopes for financial gain before disappearing without a trace.

According to Lewis, these scams are thriving because several social, economic and technological factors are making Nigerians increasingly vulnerable.

He said worsening economic conditions are making many Nigerians more willing to exchange personal information for financial rewards on these consent-to-earn platforms.

“When people are unemployed or struggling financially, they naturally become more willing to participate in opportunities that promise quick income. If somebody tells you that all you need to do is upload your face, your voice, or some videos and you will get paid, many people are not thinking about the long-term implications. They are thinking about surviving today,” he said.

Lewis said the real value in those transactions is often overlooked.

“The problem is that people see the payment. They do not see the asset they are giving away.”

While smartphone ownership and internet access continue to grow, he said digital literacy has failed to keep pace.

“Nigeria has one of the largest populations in Africa, one of the largest youth populations in the world, and millions of people are coming online every day,” Lewis said.

“When you combine that with economic hardship and low levels of digital literacy, you create an environment where people become easier targets for both cybercriminals and data-harvesting platforms,” he added.

Inside the Underground Marketplace

In the course of this investigation, our reporter followed links shared through publicly accessible social media posts and was led to a Telegram channel where AI-powered tools were being openly advertised for sale.

Within hours, the channel revealed what appeared to be a thriving digital marketplace. Promotional videos, software demonstrations and price lists filled the feed as some members in the channel competed for customers by showcasing applications they claimed could clone voices, generate realistic AI video calls from a single photograph, alter voices in real time and facilitate digital impersonation.

One advertisement promoted what it described as a “Clone Full Body Video Call” application, claiming the software could be purchased and installed for ₦170,000.

Advertisement observed to be promoting a “Clone Full Body Video Call” application marketed for approximately ₦170,000. The software was advertised as enabling AI-generated video impersonation.Screenshot by Collins Ojiehanor.

Another advertised software that purportedly allowed users to generate convincing AI video calls using only a single photograph, while a separate post promoted live voice-changing software compatible with ordinary Windows laptops.

Several of the demonstrations showed what vendors claimed were realistic video conversations, suggesting the software could be used to imitate another person’s appearance during live calls.

Rather than being hidden on obscure corners of the internet, the services were presented like ordinary commercial products.

Posts featured promotional graphics, demonstration clips, customer testimonials, pricing information and contact details, giving the impression of a legitimate online marketplace.

Our reporter also found that the trade extended beyond AI software. Separate advertisements offered hacked Facebook accounts, TikTok profiles and other social media accounts for sale.

Some listings promoted monetised TikTok accounts with tens of thousands of followers for a price ranging from ₦220,000 to ₦470,000, while others displayed hacked Facebook profiles and digital accounts, with asking prices varying according to follower numbers, engagement metrics and monetisation status.

Advertisements offering hacked and monetised TikTok accounts for sale.Screenshot by Collins Ojiehanor.

The screenshots posted on the channel suggested that, for the right price, an individual could purchase not only tools capable of impersonating another person but also established online identities that already carried years of trust, relationships and digital history.

While our reporter did not purchase, test or independently verify the functionality of the advertised software or the authenticity of the hacked social media account offered for sale, cybersecurity experts interviewed for this investigation said the emergence of such marketplaces reflects the growing commercialisation and access to AI tools capable of defrauding people.

They warn that ready-made AI tools and compromised online accounts are lowering the technical barriers to digital fraud, allowing individuals with limited hacking expertise to acquire capabilities that were once associated only with sophisticated cybercriminal groups.

 

When a Stolen Account Becomes a Weapon

When Favour Rangbii opened Facebook that morning, she found herself locked out of her own identity.

Her profile photograph had changed. Her name had disappeared. And her contacts were already receiving messages from someone pretending to be her.

“It was just like a normal day,” she recalled. “Whenever I come online, I usually go straight to my Messenger to check messages and reply to the ones I can.”

Within moments, something caught her attention.

“I noticed that I had chatted with a few people, according to what was showing in the account, but I couldn’t remember sending those messages because it had been about two or three days since I last chatted on Facebook.”

At first, she doubted herself.

“I was like, ‘Okay, was I sleepy last night, and then I sent some messages?'” she said.

The confusion quickly turned to alarm.

When she opened her profile, she discovered that both her account name and profile photograph had been changed without her knowledge.

“That was when I knew something was wrong. Something was happening. Something fishy was going on in my account.”

Unknown to her, someone had taken control of her digital identity.

Before she was able to regain access, the compromised account had already been used to contact people on her friends list, attempting to exploit years of trust she had built online.

The possibility that family members, friends or colleagues could be deceived in her name left her deeply unsettled.

“It felt like I was going to lose something really big,” she said. “Imagine losing this account and having to start from scratch. How do you even begin? How do you get all these people back? These people already know about your presence.”

Although she eventually recovered the account, she changed her profile photograph, but she could not change the profile name due to user policy; she needed to wait for about thirty days before she could change the name.

The incident fundamentally changed her understanding of digital security. Her experience illustrates how hacked social media accounts have become valuable commodities in today’s digital economy.

Beyond serving as platforms for communication, they contain trusted identities, personal relationships and years of digital history that criminals can exploit to deceive unsuspecting victims.

Screenshot showing the victim’s Facebook account after it was taken over. The attackers changed the account name and profile information and began messaging the victim’s contacts before the account was eventually recovered.Screenshot by Favour Rangbii.

Frontend developer Richard Bamidele said cybercriminals are increasingly targeting social media and messaging accounts, which, once compromised, can be exploited to facilitate further fraud.

“Before, people may receive a message asking them to click a link or download something. Once they do that, their devices can become compromised. But now, with AI tools, attackers may gain access to passwords, login credentials, and other sensitive information stored on a device without you clicking a link,” he said.

Bamidele explained that once criminals gain control of an account, their objectives vary.

“Some sell the account; others may start messaging contacts, claiming the person has been involved in an accident or is stranded somewhere or urgently needs money for an emergency. Because the messages come from a familiar account, many people trust them and send money without verifying the information first,” he explained.

He said the success of such schemes depends less on technical sophistication than on exploiting human behaviour.

“Cybercriminals understand that people are more likely to respond quickly when they believe someone they know is in trouble. In many cases, they are not hacking technology as much as they are hacking human trust,” he added.

 

Why This Wave of Fraud Is Different

The scams that deceived Bridget Nelson and Jennifer Ibhafidon and continue to ensnare countless others are no longer simply updated versions of familiar fraud schemes. They signal a deeper shift in cybercrime.

The target is no longer just the device, the password or the bank account. Increasingly, it is the person behind them and the trust that makes them vulnerable.

According to Lucky, modern attacks are carefully designed to trigger fear, urgency and emotional reactions before victims have time to question what they are seeing or hearing.

“These are different ways that criminals try to get into the heads of people, create panic, and get information. It is really a thing in Nigeria now, and everybody just needs to be careful.”

He said phishing attacks have also evolved beyond fraudulent emails to include SMS-based attacks, commonly known as “smishing”.

“You get a message asking you to download something. And it looks genuine. If you download that thing, your system becomes compromised, and all your data, passwords, and information saved on your device can end up in the hands of the wrong person.”

According to him, many Nigerians have unknowingly encountered voice phishing, commonly known as vishing.

“Criminals are already using voice cloning to target victims in Nigeria, and everybody needs to be careful. Have you ever gotten a call from an unknown number claiming to be a pastor or a doctor, saying that a member of your family is in an emergency and you need to do something immediately? I got the call. A lot of my family members got the call. I had to settle down and educate them on the dangers.”

He said such attacks succeed because they exploit instinct rather than technology.

“When people hear a familiar voice or believe a loved one is in danger, they are more likely to react immediately than stop to verify the information.”

Olajumoke said the shift is also changing the nature of financial fraud, with criminals increasingly exploiting human behaviour and trust through AI-powered tools, rather than relying solely on technical vulnerabilities.

“Fraudsters know that many banking applications are now heavily secured; some banks require ATM card verification, facial recognition or other layers of authentication. Instead of trying to break those systems, criminals are increasingly targeting the people using them,” she said.

She explained that the technique, commonly known as social engineering, relies on persuading victims to voluntarily surrender the information criminals need. The strategy, she said, is to create enough fear, urgency or emotion to make victims act before they stop to verify the request.

“They want you to act before you verify. They know that once people become emotional, frightened or hurried, they are less likely to question what they are seeing or hearing.”

To illustrate how quickly such attacks can unfold, Olajumoke recounted the experience of a customer who had just reactivated his bank account and deposited ₦100,000. Minutes after leaving the banking hall, he received a phone call from people claiming to be bank officials.

They told him there was one final step required to complete the process and asked him to read aloud a verification code that had just been sent to his phone.

“He called out the code for them, and the money in his account was gone.”

According to Olajumoke, the attack succeeded not because the bank’s security systems were breached, but because the victim was deceived into trusting the caller.

Olajumoke also rejected the assumption that fraud victims are simply careless. With AI, their approach is becoming more convincing.

“It can happen to anybody,” she said.

According to her, fraudsters are not necessarily looking for unintelligent people. Instead, they look for moments when potential victims are distracted or under pressure.

“They don’t need you to be smart or not smart. They just need someone who is busy and distracted.”

She explained that with AI, fraudsters increasingly send messages that appear to come from legitimate financial institutions but contain malicious links designed to harvest personal information, and because victims are contacted when they are preoccupied, they are less likely to stop and question what they are being told or see.

“You receive a call or an SMS claiming to be from your bank while you are busy doing something else. You see your bank’s logo and everything. At that moment, you may not even stop to think whether it is truly from your bank. And then you read out the code or send the message, and that’s all they need.”

Olajumoke further warned that even routine financial transactions can expose consumers to risk, noting that some Point of Sale (POS) terminals may compromise bank card information without users immediately realising it.

“That’s why I prefer making transfers instead of using my ATM card on unfamiliar POS terminals. Anybody can be a scammer,” she said.

Screenshot of another advertisement claiming users can generate AI-powered video calls from a single photograph and offering voice-changing features.Screenshot by Collins Ojiehanor.

 

Recognising the Red Flags Before It Is Too Late

For Okusanya Bukola Christiana, cybercriminals have come knocking more than once.

Each encounter was different. But looking back, she realised they all relied on the same strategy of creating enough urgency to stop victims from thinking.

One of the closest calls began with a phone call from someone claiming to be a representative of her bank.

“One experience was when I received a phone call from someone who claimed to be calling from my bank,” she recalled.

The caller sounded professional and convincing, warning that her account could be blocked unless she immediately provided her Bank Verification Number (BVN).

“The caller sounded very convincing and told me I needed to provide my BVN details so they could update my information and prevent my account from being blocked.”

For a brief moment, she almost complied.

“The situation felt urgent and real, and I almost fell for it. I remembered that my bank would not request such sensitive information over a phone call.”

That single moment of hesitation saved her.

“That realisation made me pause, and I immediately understood it was a scam. I ended the call and confronted the caller.”

It was not the last attempt.

On another occasion, she received a message informing her that she had supposedly won a large cash prize.

“Another experience was when I received a message saying I had won a huge amount of money.”

The message instructed her to click a link and call a number to claim the reward.

“The message instructed me to click a link and call a number to claim the prize. Although it sounded tempting, I was cautious enough not to click the link or contact the number, knowing that such offers are often fraudulent.”

A third encounter came disguised as an investment opportunity promising extraordinary returns within a short period.

“I also encountered a situation where I was encouraged to invest in a scheme that promised very high returns within a short time.”

Although the offer appeared attractive, the promised profits immediately raised her suspicions.

“The offer seemed attractive, but I recognised it as suspicious because of the profit I was told I would get in return, so I chose not to engage.”

After experiencing repeated attempts, Okusanya said her approach to digital interactions has fundamentally changed.

“These experiences taught me very important lessons about digital security and trust. Now I know that any message or call that pressures me to act immediately is a red flag.”

She said she has also become far more protective of her personal information.

“I realised that sensitive information like BVN, bank details, or personal data should never be shared.”

Verification, she added, has become a personal rule rather than an afterthought.

“I learnt to always verify before trusting. Even when something looks real. Also, I became more cautious about links and unknown contacts. I avoid clicking suspicious links or calling unfamiliar numbers because they can be used to steal information or scam people.”

For her, the most important lesson is simple.

“These experiences taught me that if something sounds too good to be true, like winning a huge amount of money or getting very high returns on investment, it is most likely a scam.”

Her experiences reinforce what cybersecurity experts repeatedly emphasised throughout this investigation, that while artificial intelligence and other emerging technologies are making scams more sophisticated, many attacks still succeed by exploiting familiar human emotions like fear, urgency, excitement and trust.

Recognising those warning signs, they say, may be the difference between identifying a scam in time and becoming its next victim.

 

Can Nigerian Law Keep Up?

On that Wednesday morning, the WhatsApp message seemed impossible to ignore.

A close friend claimed she had been knocked down by a motorcycle and urgently needed money for medical treatment. Believing she was helping someone in distress, Ese Imade transferred ₦50,000 without hesitation.

Only afterwards did she try calling her friend directly. The calls would not connect. Worried, she contacted her friend’s roommate instead.

That conversation exposed the deception.

Her friend’s WhatsApp account had been hacked. There had been no accident, no medical emergency, only a scammer exploiting the trust built into a familiar identity.

“The hacker had gained access to her WhatsApp and was sending messages to people on her contact list asking for money,” Imade recalled.

The fraud had already spread beyond her.

“Some of her other contacts had already sent money too because they believed the messages were really coming from her.”

The incident permanently changed how she responds to urgent requests for financial assistance.

“Everything looked genuine because the message came from my friend’s WhatsApp. There was nothing that immediately made me think it was a scam,” she said.

As artificial intelligence makes digital impersonation increasingly convincing through deepfakes, cloned voices and synthetic identities, legal experts say Nigeria’s existing laws provide important safeguards for personal data but are yet to fully address the emerging challenges posed by AI-enabled identity fraud.

Legal practitioner Barrister Ivie Omorogieva said the Nigeria Data Protection Act (NDPA) 2023 gives Nigerians extensive rights over how their personal information is collected, stored, shared and processed.

“The law gives every data subject the right to know whether their personal data is being processed, the purpose for which it is being processed, who it has been shared with, how long it will be retained, and to request access to that information,” she explained.

She added that the Act also allows individuals to request the correction or deletion of inaccurate information, withdraw consent, and challenge decisions based solely on automated processing or profiling.

Omorogieva further explained that the NDPA contains additional safeguards for children and other vulnerable persons, warning that organisations found to have violated the law could face substantial regulatory sanctions, including financial penalties running into millions of naira.

Highlighting recent enforcement actions, she cited the ₦766 million penalty imposed on MultiChoice, the ₦555.8 million sanction against Fidelity Bank, and the $220 million administrative penalty imposed on Meta Platforms and WhatsApp over alleged breaches of Nigeria’s data protection laws.

But as growing numbers of Nigerians upload photographs, videos and voice recordings to emerging “data-for-pay” platforms, legal practitioner Barrister Samuel Adebisi cautioned that while existing legislation can address data misuse and privacy violations, it was not specifically designed to regulate AI-generated impersonation.

“Where biometric data or facial images are processed for identification, artificial intelligence training or profiling, the platforms must comply with the stricter requirements applicable to sensitive personal data under the NDPA,” he said.

According to Adebisi, Nigeria’s legal framework has yet to catch up with the rapid evolution of synthetic media.

“The NDPA protects personal data against unlawful processing, but it was not designed specifically to regulate AI-generated synthetic media or digital impersonation,” he said.

He noted that victims of deepfakes, AI-generated voice cloning and synthetic identity fraud currently rely on existing cybercrime laws, criminal statutes and civil remedies because Nigeria has no dedicated legislation governing such technologies.

“There is a growing need for sector-specific regulations, AI governance frameworks and supplementary legislation that directly addresses these emerging technologies while complementing the NDPA’s general principles,” he added.

For Adebisi, the challenge extends beyond artificial intelligence itself.

“The law generally responds to technological problems after they have emerged instead of anticipating and regulating them before they become widespread.”

Screenshot of another advertisement claiming users can install a video calling tool on any laptop, with a live voice changer also available.Screenshot by Collins Ojiehanor.

 

The New Rules of Trust

Although millions of Nigerians use smartphones, social media platforms and AI-powered applications every day, experts warn that many still do not fully understand the implications of digital consent.

Users routinely accept privacy policies without reading them, grant applications access to cameras, microphones and contact lists without questioning why those permissions are needed, and share personal information without considering how it could be used long after it has been uploaded.

Lucky held that public awareness remains one of the strongest safeguards against emerging AI-driven identity threats.

“People need to be very careful. People need to learn to protect their data. But with the level of social media frenzy, nobody really cares. If we can educate people on the dangers, they can begin to limit themselves a little bit on their level of exposure.”

His caution comes as advances in AI continue to outpace public understanding of how personal information can be harvested, replicated and exploited.

Olajumoke said that despite the emergence of AI-powered scams, many cybercriminals continue to rely on familiar tactics such as phishing attacks, social engineering and deceptive phone calls because they remain highly effective.

“In this country, our names and phone numbers are already public. You see random people calling you to take loans and you wonder how they got your number and your name.”

She urged Nigerians, particularly older people, never to disclose verification codes, one-time passwords (OTPs), bank verification numbers (BVNs) or other confidential information over the telephone, regardless of who the caller claims to be.

“If anyone asks for those details over the phone, end the conversation and contact your bank through its official channels. No bank will call or chat to ask for any code even if you just left the bank. No matter how busy or distracted you are, if anybody asks you to read out any code over the phone, do not do it,” she warned.

Independent verification, whether by calling a known number, confirming through another communication channel or using pre-agreed family verification codes and phrases, has become one of the most effective defences against a new generation of digital deception.

But the challenge goes beyond recognising individual scam tactics. As AI makes voices easier to clone, faces easier to replicate and identities easier to fabricate, the assumptions people have traditionally used to establish trust are becoming less reliable.

A familiar voice may no longer prove who is calling. A recognisable face may no longer prove who is on the other side of a screen. Even a message arriving from a trusted account may have been sent by someone else.

In the AI era, experts say, the safest response to anything that demands immediate action is no longer to trust what appears real but to stop, question and verify before acting.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.