Nigeria Ranks 38th Globally as 390,800 Accounts Leaked in H1 2026, Total Breaches Hit 24.3 Million
According to new data from cybersecurity firm Surfshark, Nigeria recorded 390,800 leaked accounts in the first half of 2026. This places it 38th globally among the most breached countries.
RELATED: INEC probes insider data leak: Fresh threat to electoral integrity and Nigeria’s data protection regime
Globally, a total of 313.4 million accounts were breached. The US ranks first and amounts to 29% of all breaches from January through June. France takes second place, while Brazil is third, followed by India and the UK.
ALSO READ: Data leak exposes 3 billion users: Is your data at risk?
Surfshark’s data also highlights a notable regional shift. Europe surpassed North America in the number of breached accounts during the previous quarter.
France leads Europe
In Q2 2026, 1 in 3 breached accounts worldwide came from Europe, and 58% of those within the region were linked to France.
In addition, 4 out of 5 countries with the highest breach density (number of leaked accounts per 1,000 residents) are also European. The 1st is France, then Poland, the US, Portugal, and Lithuania.
“Information taken in breaches years ago can remain in circulation for a long time, resurfacing in new fraud schemes, and used to target people long after the original incident. The same is true for data being stolen today: even if it is not abused immediately, it can still come back years later in the form of account takeovers, identity abuse, scams, and financial theft,” says Tomas Stamulis, Chief Security Officer at Surfshark.
Since 2004, Nigeria is the 3rd in Sub-Saharan Africa, with 24.3M compromised user accounts. A total of 7.5M unique emails were breached from Nigeria. 13M passwords were leaked together with Nigerian accounts, putting 54% of breached users in danger of account take over that might lead to identity theft, extortion or other cybercrimes. Statistically, 10 out of 100 Nigerian people has been affected by data breaches.
Tips to stay safee
In order to stay safe online and limit your exposure, Tomas Stamulis shares his tips :
- As a general rule, treat all your personal information as sensitive by default and disclose it only when absolutely required.
- Share your real personal details only when there is a genuine, necessary reason, such as completing official or legally required forms.
- For everything else, limit your exposure by using an alias, a secondary email address, or an email-masking service.

































