Nigeria’s Company Registry Breached: ByteToBreach Drops 25 Million Documents – And the Proof Is in the Screenshots
Very recently, a threat actor plaguing the Nigerian scene by the name, ByteToBreach claimed that they have now published 3TB of breached sensitive data.
Taking a back to the 14th of April 2026, the X account @DarkWebInformer posted a stark warning that instantly lit up cybersecurity timelines. The post (the exact screenshot you shared) claimed that a threat actor going by the same ByteToBreach had exfiltrated approximately 25 million documents from Nigeria’s Corporate Affairs Commission (CAC) – the government body that registers every company, business name, and incorporated trustee in the country.
No hype, no walls of text. Just a clean headline, key facts, and seven sequentially named proof screenshots labelled:
1_BREAKTHROUGH | 2_ESCALATION | 3_TAKEOVER | 4_PORTALS | 5_FULL_ACCESS| 6_GOV_BETRAYAL | 7_EXFIL_TIME
And a note that 750 GB of the data was being offered for free download.
It’s the kind of post that stops you scrolling. Why? Because it doesn’t just claim a breach, it hands you a ready-made story of how it happened.
What the Proof Screenshots Actually Show
ByteToBreach didn’t dump raw internal files or vague directory listings. Instead, the seven images form a crystal-clear timeline of the intrusion stages, from first foothold to full data exfiltration. This staged, labelled approach is rare in dark-web leaks. It turns an allegation into something journalists, researchers, and even casual readers can instantly understand and share. The actor has used a similar visual style before, but the CAC post feels more polished, almost like a mini case study dropped straight into the public domain.
The Data at Stake
The claimed haul: ~25 million documents totalling 750 GB. According to the actor, about a quarter are basic corporate signatures; the rest are substantive records, incorporation papers, director and shareholder details, addresses, ownership structures, and regulatory filings.
In plain English: the central database that holds the legal “DNA” of virtually every registered business in Nigeria is now potentially floating in the wild. The free-download strategy means copies are already spreading fast and will be almost impossible to pull back.
How This Fits the Pattern: A Quick Look at The Affected Bank
This isn’t ByteToBreach’s first rodeo in Nigeria. In late March 2026, the same actor claimed responsibility for a breach at one of the Nigerian Banks (and linked payment systems).
The similarities are striking:
- Same solo operator
- Same “simple access → full takeover → exfil” playbook
- Same high-visibility proof style
- Same rapid spread on X and threat-intel channels
The difference? The affected Bank exposed personal banking data; BVN numbers, transaction histories, and customer PII. The CAC breach hits the corporate backbone of the entire economy. One feels like a targeted financial sting; the other feels systemic.
Why This Story Matters Right Now
We’re still in the very early days. As of 16 April, CAC has acknowledged unauthorised access to parts of its systems and activated its incident response, but official confirmation of the 25-million-document scale is still pending. No full technical details have been released yet and that’s exactly why the story feels electric. The proof screenshots have done the heavy lifting while everyone waits for the other shoe to drop.
For anyone running a business in Nigeria, updating passwords and watching for suspicious director changes feels like basic hygiene today. For the rest of us, it’s a live demonstration of how visibility + volume can turn one breach into national headlines overnight.
Going Deeper: Beyond the Headlines
While the first part of this post focuses on what we can see publicly, there’s a deeper technical and strategic layer behind incidents like this.
At Zero Day Africa, we break down cases like ByteToBreach beyond the screenshots, looking at attacker behaviour, likely entry points, privilege escalation patterns, and what defenders consistently miss. In this pictograph, we expand on a few key areas:
- Why these attacks often succeed with low-to-moderate sophistication
- Common weaknesses in government and enterprise-facing portals
- How attackers move from initial access to full system control
- Practical defensive priorities that organisations tend to overlook
It’s less about the breach itself and more about the repeatable playbook behind it.

