Showing posts with label digital rights. Show all posts
Showing posts with label digital rights. Show all posts

Wednesday, 25 March 2026

When Power Players Expose Mass Surveillance: The El-Rufai Wiretapping Saga and the Cybercrimes Paradox


A high-profile airport confrontation has pulled back the curtain on alleged warrantless surveillance apparatus, but who investigates the investigators?

The recent clash between former Kaduna State Governor Nasir El-Rufai and National Security Adviser Nuhu Ribadu has exposed a troubling double standard at the heart of the digital rights framework in Nigeria. While legal experts like Abuja-based lawyer Pelumi Olajengbesi correctly point out that phone tapping constitutes a serious criminal offense under the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, El-Rufai's counter-allegations raise a more fundamental question: what happens when the suspected perpetrator is the state itself?

The Accusations

Following his attempted arrest at Nnamdi Azikiwe International Airport in February, 2026, El-Rufai publicly admitted to listening to an intercepted phone conversation in which Ribadu allegedly ordered his detention. But he didn't stop there. In a revealing statement, the former governor declared: "The government thinks that they're the only ones that listen to calls...the government does it all the time. They listen to our calls all the time without a court order."

This isn't just political mudslinging. These words come from someone who has operated at the highest levels of governance; a former minister and two-term governor with intimate knowledge of state security operations. His allegations carry institutional weight precisely because of this is insider perspective.

The Legal Framework vs. Reality

The legal framework for electronic surveillance appears comprehensive on paper.  Section 37 of the 1999 Constitution (as amended) guarantees the right to privacy  of  citizens,  their  homes,  correspondence,  telephone conversations  and  telegraphic  communications.

Furthermore, Section 12(1) of the Cybercrimes Act, 2015 (as amended) is explicit: "Any person, who intentionally and without authorization, intercepts by technical means, non-public transmissions of computer data, content, or traffic data... commits an offence and shall be liable on conviction to imprisonment for a term of not more than 2 years or to a fine of not more than N5,000,000.00 or to both."

The law makes no exception for government officials. The prohibition applies to "any person", a deliberate choice of words that encompasses both private individuals and state actors.

The Warrant Requirement

Section 39 of the Cybercrimes Act and the Lawful Interception of Communications Regulations, 2018 establish strict conditions for lawful interception. A judge may only authorize interception "where there are reasonable grounds to suspect that the content of any electronic communication is reasonably required for the purposes of a criminal investigation or proceedings."

The Regulations further specify that a warrant is necessary except in narrowly defined emergency situations involving: immediate danger of death or serious injury, activities threatening national security and organized crime activities.

Even in these emergency circumstances, Regulation 12(4) mandates that the authorized agency "shall apply for a Warrant to the Judge within 48 hours after the interception has occurred... and where the application is not made, or denied within 48 hours, the interception shall terminate immediately and further interception shall be treated as unlawful."

Who Can Request Interception?

Under Regulation 12(1) the Office of the National Security Adviser (represented by the NSA or designee not below Assistant Commissioner rank) or the State Security Services (represented by the Director or designee of equivalent rank).

Notably, the NSA, Nuhu Ribadu himself, is one of only the few officials empowered to seek lawful interception orders. This makes El-Rufai's allegation that Ribadu ordered his surveillance particularly significant: if such interception occurred without judicial authorization, the very official charged with seeking warrants lawfully may have bypassed the legal process entirely.

The Reality: Systematic Circumvention?

Yet El-Rufai's claims that "The government does it all the time. They listen to our calls all the time without a court order", suggest a pattern of systematic circumvention, not by rogue actors, but by the very state apparatus charged with upholding these laws.

If true, this represents a fundamental breakdown of the rule of law. The regulations impose severe penalties for non-compliance: N5,000,000 fines for violations, plus N500,000 daily penalties for continuing offenses (Regulation 16). These penalties apply to "any person, Licensee or its officers" again, no carve-out for government agencies. Section 12 of the Cybercrimes Act also criminalizes unlawful interceptions of communications.

The legal framework is therefore, clear. The alleged practice, as described by a former governor with insider knowledge, appears to violate it systematically. This gap between law and practice transforms surveillance regulations from protective shields into paper tigers which are enforced against citizens while ignored by those in power.

The Expanding Surveillance Infrastructure

El-Rufai's allegations align disturbingly with documented evidence of growing surveillance capabilities in Nigeria. According to research from the Institute of Development Studies, Nigeria has spent billions of dollars acquiring sophisticated surveillance technology. The country has procured systems capable of monitoring communications, tracking locations, and conducting mass data collection, often with minimal transparency or oversight.

The Berkman Klein Center at Harvard University reports that Nigeria's surveillance ecosystem includes partnerships with international technology vendors and deployment of invasive monitoring tools. These systems operate in what researchers describe as a legal grey zone, where the technological capacity for surveillance far outpaces regulatory frameworks designed to protect citizens' privacy.

The Harvard research notes that authorities have acquired tools for intercepting mobile communications, monitoring internet traffic, and collecting metadata on citizens' digital activities which is precisely the kind of warrantless surveillance El-Rufai now alleges is routine practice.

The Financial and Human Cost

The scale of investment in surveillance infrastructure is staggering. As the IDS study reveals, the country has channeled billions into surveillance technologies even as critical public services remain underfunded. This spending occurs largely outside public scrutiny, with procurement processes that lack transparency and accountability mechanisms.

More troubling still, these surveillance capabilities have allegedly been deployed not primarily for national security purposes, but for monitoring political opposition, civil society activists, and journalists. The Harvard analysis documents cases where surveillance tools have been used to target dissenting voices rather than genuine security threats. A pattern consistent with El-Rufai's claims about politically motivated monitoring.

The Accountability Vacuum

Lawyer Olajengbesi has called for security agencies to investigate El-Rufai's admission of listening to intercepted communications. But this raises the paradox at the heart of this affair: Who investigates allegations against the government when the government controls the investigative machinery?

The Harvard research highlights a critical gap in Nigeria's digital rights architecture: the absence of independent oversight bodies with real power to monitor and sanction state surveillance activities. While the Cybercrimes Act and the Lawful Interception of Communications Regulations, 2018 theoretically requires judicial authorization for interception, researchers found that compliance mechanisms are weak and enforcement is selective.

If El-Rufai's broader allegations are accurate, i.e., that warrantless mass surveillance of citizens' phone calls and online activities is routine government practice, then Nigerians face a surveillance state operating outside its own legal framework. The Cybercrimes Act and the Lawful Interception of Communications Regulations, 2018, becomes merely decorative legislation, enforced selectively against citizens while the state enjoys de facto immunity.

The Technology Behind the Surveillance

According to IDS findings, the government of Nigeria has acquired sophisticated interception systems capable of real-time monitoring of telecommunications networks. These systems can capture voice calls, text messages, and internet communications without leaving traces detectable to the targets. The infrastructure includes both passive collection systems and active interception capabilities and this makes El-Rufai's claim about routine, warrantless call monitoring technically plausible.

The Berkman Klein Center's investigation notes that telecommunications providers in Nigeria are often compelled to cooperate with security agencies, sometimes through informal pressure rather than legal process. This creates a system where lawful interception procedures can be bypassed entirely, with communications accessed directly through telecoms infrastructure.

What This Means for Digital Rights

This confrontation between political heavyweights inadvertently validates long-held suspicions within the digital rights community: that citizens' communications are subject to systematic, warrantless monitoring. Civil society organizations have raised these concerns for years, often dismissed as conspiracy theories. When someone of El-Rufai's stature; with decades navigating power corridors, makes such allegations, it demands serious attention.

The Harvard study emphasizes that unchecked surveillance powers fundamentally undermine democratic participation. When citizens cannot communicate privately, they cannot organize effectively, hold government accountable, or exercise their rights to free expression and assembly. The chilling effect of pervasive surveillance extends far beyond those directly targeted.

The Way Forward

1.   Independent oversight mechanisms for state surveillance activities with real enforcement power as recommended by researchers at IDS, including civilian oversight boards with subpoena power and security clearances to audit surveillance operations.

2. Transparency reports from telecommunications providers and security agencies about interception requests and warrants, a practice the Berkman Klein Center identifies as essential for accountability in democratic societies.

3. Judicial reforms ensuring that interception warrants are genuinely scrutinized, not rubber-stamped, with specialized courts trained in digital rights and surveillance law.

4. Legislative review of the Lawful Interception of Communications Regulations, 2018 to close loopholes enabling abuse and align the Regulation with international human rights standards.

5.  Equal application of cybercrime laws, whether the accused is a citizen or state actor.

6.  Public disclosure of surveillance procurement contracts and capabilities, as called for by civil society researchers, to enable informed democratic debate about surveillance powers.

Conclusion

The irony is stark: laws designed to protect electronic privacy may be routinely violated by those charged with enforcing it. While El-Rufai's own admission warrants investigation, his counter-allegations expose a potentially far graver systemic problem. The documented evidence of multi-billion dollar surveillance infrastructure in the country, combined with research showing weak oversight mechanisms, suggests El-Rufai may be revealing an open secret within the power elite.

Until the country establishes genuine accountability for state surveillance activities, the Cybercrimes Act and Lawful Interception of Communications Regulations, 2018 will remain what many fear they already are i.e., tools for controlling citizens rather than protecting their digital rights.

The question remains unanswered: In a democracy, when the government allegedly breaks the law on a mass scale, who investigates?

 

Thursday, 15 May 2025

A Decade of the Cybercrimes Act: Assessing the Nation’s Legal Framework Against Digital Threats (2015–2025)


Introduction

On May 15, 2015, the nation made a decisive move in addressing the growing threat of cybercrime by enacting the Cybercrimes (Prohibition, Prevention, etc.) Act. Ten years later, the law remains central to the country’s cybersecurity framework, offering legal definitions, prosecutorial mechanisms, and institutional frameworks to combat digital threats. As we mark this decade-long journey, it is time to assess the Act's major impacts, its 2024 amendments, its misuses, and what must change in the future to safeguard security and civil liberties.

1.     The Country’s First Comprehensive Legal Framework on Cybercrime

Prior to 2015, the legal environment addressing cybercrime in the nation was fragmented. Offenses were prosecuted under laws like the Advanced Fee Fraud Act, which did not fully capture the nature of modern digital threats. The 2015 Act changed that by clearly defining crimes such as hacking, identity theft, cyberterrorism, online fraud, and child pornography. It introduced penalties that enabled structured prosecution. The result has been a series of high-profile convictions, including notorious syndicates involved in ATM cards, phishing scams, etc.

2.     Creation of the Cybercrime Advisory Council

The Act provided for the establishment of the Cybercrime Advisory Council under the leadership of the National Security Adviser (NSA). Comprising stakeholders from public and private sectors, the Council was tasked with coordinating national cybersecurity policy. Although the Council has faced criticism for slow bureaucratic response, it has enabled strategic partnerships with international agencies like INTERPOL and the UK National Crime Agency.

3.     Protection of Critical National Infrastructure (CNII)

A notable provision of the Act was the designation of key sectors such as banking, energy, and telecommunications as Critical National Information Infrastructure (CNII). These sectors were mandated to implement enhanced cybersecurity protocols. Although large institutions have complied, enforcement remains inconsistent, especially among smaller banks and regional service providers.

4.     Reforming Section 24: From Overreach to Targeted Protection

Originally, Section 24 criminalized messages deemed "grossly offensive" or causing "needless anxiety." This provision was vague and became a tool for silencing journalists and critics. The 2024 amendment narrowed its scope, now targeting child pornography and false information likely to incite violence. This change followed the ECOWAS Court's 2020 judgment, which found the original section unconstitutional. Still, enforcement remains uneven and politically influenced.

Notable Misuse Cases:

·       Omoyele Sowore (January 2025). Charged with 16 counts under the Cybercrime Act based on his social media posts referring to the Inspector General of Police as an “illegal IGP.”

·         Agba Jalingo (2022): Prosecuted over Facebook posts alleging corruption.

The Erisco Tomato Paste Review Case – A Cautionary Tale

In 2023, Chioma Okoli, a national consumer, posted a Facebook review stating that she found Nagiko Tomato Mix, a product of Erisco Foods Limited, to be sugary. Erisco Foods Limited refuted her claim as untrue and unfounded. Subsequently, Okoli was arrested by the police following a petition by the company's President and CEO, Eric Umeofia. The police obtained an arrest warrant and remand order from a magistrate court in Masaka, Nasarawa State, leading to her detention. She was later arraigned at the Federal High Court in Abuja, where she pleaded not guilty to two counts of conspiracy and cyberstalking. Amid the legal proceedings, Okoli suffered a miscarriage. Her arrest and detention sparked public outrage, with many citizens calling for her release.

Displeased with the remand order, Okoli's counsel, Inibehe Effiong, petitioned the Nasarawa State Judicial Commission. He argued that it was improper for the magistrate to issue arrest and remand warrants against his client, who neither resided in Nasarawa State nor had ever visited it. Effiong contended that the alleged offences were not committed in Nasarawa State and that cybercrime is a federal offence under the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, which grants exclusive jurisdiction to the Federal High Court for such matters.

Following the petition, the Nasarawa State Judicial Commission investigated the matter and, in a letter dated January 6, 2025, informed Effiong that Chief Magistrate Emmanuel A. Jatau had been demoted from Chief Magistrate II (Grade Level 15) to Senior Magistrate I (Grade Level 14) and stripped of his magisterial duties. The commission cited misconduct in the handling of Okoli's case as the reason for the disciplinary action.

This case underscores the importance of adhering to proper jurisdictional procedures and the potential consequences of misapplying legal authority, particularly in matters involving federal offences such as cybercrime. It further highlights how cybercrime laws can be misapplied to suppress consumer rights and free expression, exemplifying a growing trend of using criminal prosecution to settle what are fundamentally civil disputes.

5.     International Collaboration and Extradition Challenges

The country’s endorsement of the Budapest Convention significantly improved its ability to cooperate on international cybercrime investigations. Countries such as the UK, South Africa, and Japan have partnered with the nation to track and extradite suspects. However, the process remains hampered by slow bureaucratic procedures and lack of mutual legal assistance frameworks with some jurisdictions.

6.     Introduction of the Cybersecurity Levy

A major provision in the 2024 amendment was the introduction of a 0.5% cybersecurity levy on electronic transactions, administered by the NSA. While aimed at funding national cyber defense infrastructure, the policy attracted strong public opposition, prompting government reviews and clarifications. Critics argue the levy disproportionately affects small businesses and low-income earners.

7.     Law Enforcement and Free Speech: A Fragile Balance

Even after the amendment, Section 24 continues to be used against journalists and whistleblowers. In 2024, journalist Daniel Ojukwu was detained for publishing corruption-related stories. In 2023, lawyer Chike Ibezim was charged over tweets criticizing a politician. Legal advocacy groups like SERAP and the Nigerian Union of Journalists (NUJ) have consistently called for more robust protections for free speech.

8.     Sectoral CERTs and Faster Incident Reporting

The 2024 reforms also created Sectoral Computer Emergency Response Teams (CERTs) to improve the handling of cyber incidents. Financial institutions, for example, must now report security breaches within 72 hours, a significant improvement over the previous 7-day period. This has improved real-time threat analysis and response mechanisms.

9.     Mandatory NIN for Electronic Transactions

To combat identity fraud, the amendment now mandates the use of National Identity Numbers (NIN) for all electronic transactions. While this policy has had a positive impact in reducing the number of fraudulent accounts, implementation remains difficult due to infrastructure gaps in the National Identity Management Commission (NIMC).

10.    Strengthening Law Enforcement Capacity

The Act led to the establishment of cybercrime units within agencies like the EFCC, the Nigeria Police Force, and the Nigerian Financial Intelligence Unit (NFIU). These units have recorded success in cracking complex cyber fraudcases. However, underfunding, skill shortages and accessibility outside Abuja and Lagos still limit their effectiveness. 

Judicial Warning Against Misuse of Criminal Law for Civil Disputes

The Supreme Court of the country, in Aviomoh v. C.O.P & Anor (2021) LPELR-55203(SC), offered a stark warning. Justice Helen Moronkeji Ogunwumiju held:

"My Lords, the misuse of the criminal law machinery for getting reliefs in disputes that are civil in nature, by using the instruments of State has become dangerously rampant in recent times... Criminal Courts should ensure that proceedings before it are not used for settling scores or to pressurize parties to settle civil disputes."

This principle must guide the application of the Cybercrimes Act, particularly Section 24, to prevent the criminalization of civil disagreements or dissenting opinions.

The Way Forward

1. Judicial Training:

Introduce mandatory training on digital rights and cybercrime legislation for magistrates and judges. The mishandling of the Erisco case underscores the urgent need for judicial officers to understand jurisdictional limits and the civil liberties at stake in cybercrime prosecutions.

2. Expansion of Forensic Infrastructure:

Establish well-equipped cybercrime forensic laboratories in each of the six geopolitical zones to improve digital evidence collection and analysis.

Deploy Cybercrime Units of the Nigeria Police Force across all 36 state commands. These units should be equipped with modern tools, including digital forensic software and blockchain analysis systems. Replicating such capacity nationwide will help reduce investigative delays, particularly in underserved rural areas.

3. Capacity Building:

Invest in the continuous training of law enforcement personnel in areas such as ethical hacking, cryptocurrency tracking, and dark web surveillance. Partnerships with institutions like the UK's National Cyber Security Centre (NCSC)  will ensure officers remain adept at handling sophisticated cyber threats.

4. Whistleblower Protection:

Enact legal safeguards to protect journalists, whistleblowers, and concerned citizens from retaliatory prosecutions under the Act. Such protection is crucial to fostering accountability and trust in public institutions.

5. Transparency and Accountability:

Mandate the publication of annual reports on cybercrime-related arrests, charges, and convictions. These reports should include disaggregated data to help identify patterns of misuse and support evidence-based reform.

Conclusion

In its first decade, the Cybercrimes Act has become a vital component of the national security framework. Yet, high-profile cases like Erisco and the detention of journalist Daniel Ojukwu expose persistent vulnerabilities in its application. As Justice Helen Ogunwumiju cautioned in Aviomoh v. C.O.P, criminal law must not be wielded as a tool for settling civil grievances or suppressing legitimate dissent.

To uphold both security and civil liberties in the digital age, the next phase must focus on legislative precision, institutional accountability, and infrastructural development. Decentralizing cybercrime units, expanding forensic capabilities, and ensuring judicial understanding of digital rights will help realign the Act with its original purpose: to protect citizens from genuine digital threats—not to punish lawful expression.

Without equipping all regions of the country to detect and respond to cybercrime effectively, the nation risks falling behind in its fight against increasingly complex digital criminality. Reform is no longer optional—it is imperative.