CSIDB logo
Threat actor

Nigerian Cyber Army

Attribution profile

Type
Activist
Location
Nigeria
Known incidents
3 incidents
First seen
2014-01-30
Last seen
2015-03-28
Updated
2026-08-01 07:26
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as the Nigerian Cyber Army, also operating under the aliases Nigerian Cyber Hunters and NCH, is based in Nigeria and has conducted a series of website defacements targeting governmental and political entities. Their activities have been observed in Nigeria, Bangladesh, and Pakistan, focusing on sectors such as electoral commissions, police ministries, airport security forces, and political party websites. The actor’s actions appear driven by hacktivist motives, using defacements to voice criticism of perceived corruption, inadequate remuneration, and security shortcomings rather than pursuing financial gain or espionage. No public reporting links the group to a state sponsor or a larger criminal consortium, and their affiliations remain unspecified in the available sources.

The actor’s tactics are limited to compromising web servers and replacing site content with messages that range from mocking taunts to protest statements, as seen in the INEC defacement that read “Sorry xD Your Site has been STAMPED by Team Nigerian Cyber Army. FEEL SOME SHAME ADMIN!!,” the Bangladesh Airport Armed Police incident that declared “We are all over the News Bitches… Security 0%…. Fix Ya ASS,” and the Ministry of Police Affairs protest that condemned bribery and government failure. These operations demonstrate a consistent pattern of gaining unauthorized access to web platforms, removing legitimate content, and inserting messages intended to embarrass administrators or highlight grievances. The three publicly reported incidents—the 2015 INEC website hack, the 2014 Bangladesh Airport Armed Police defacement, and the 2014 Nigeria Ministry of Police Affairs breach—serve as representative examples of their activity. No details regarding malware families, specific initial access vectors, or specialized tooling are disclosed in the referenced material, so further technical specifics cannot be confirmed. The actor’s known activity remains confined to website defacement as a means of delivering political or social commentary.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB