Threat Intelligence Brief
Curated summary with source attribution
Source: businesspost.ng
Threat Risk: Medium
Victim: University of Lagos students
Incident: Unauthorized use of personal data to open bank accounts without a lawful basis.
Impact: Privacy violation and potential financial fraud via unauthorized account creation.
Attacker: Lotus Bank and Hackerbella Limited
Analysis: The Nigeria Data Protection Commission is investigating the unauthorized use of student data involving a university, a bank, and an IT solutions firm. This incident underscores the risks associated with improper data-sharing arrangements and the lack of transparency in automated processing. The probe focuses on compliance failures regarding the Nigeria Data Protection Act of 2023.
Recommendations: Audit third-party data-sharing agreements to ensure legal and regulatory compliance.; Implement strict data minimization and purpose limitation policies for student records.; Review automated account creation and profiling systems for transparency and consent.
Source: Business Post Nigeria
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source