AI-Powered DeepLoad Malware Targets Nigerian Institutions

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Nigeria's National Information Technology Development Agency (NITDA) has warned of an active AI-powered malware, DeepLoad, targeting government agencies, banks, businesses, and individuals. The malware uses social engineering to infiltrate systems, steal sensitive data, evade antivirus detection, and enable financial fraud and operational disruptions across Nigeria.[AI generated]

Why's our monitor labelling this an incident or hazard?

The DeepLoad malware explicitly incorporates AI-generated code to evade antivirus detection and maintain persistence, qualifying it as an AI system. The malware's active infections have caused direct harms including credential theft, financial fraud, system compromise, and risks to national security, fulfilling the criteria for an AI Incident. The advisory details realized harms and ongoing attacks, not just potential risks, confirming this classification.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Government, security, and defenceFinancial and insurance services

Affected stakeholders
GovernmentBusiness

Harm types
Economic/PropertyHuman or fundamental rights

Severity
AI incident

AI system task:
Content generationEvent/anomaly detection


Articles about this incident or hazard

Thumbnail Image

"Deepload" Malware Steals Passwords, Targets Nigerians - NITDA - Computers - Nigeria

2026-05-07
Nairaland
Why's our monitor labelling this an incident or hazard?
The DeepLoad malware explicitly incorporates AI-generated code to evade antivirus detection and maintain persistence, qualifying it as an AI system. The malware's active infections have caused direct harms including credential theft, financial fraud, system compromise, and risks to national security, fulfilling the criteria for an AI Incident. The advisory details realized harms and ongoing attacks, not just potential risks, confirming this classification.
Thumbnail Image

NITDA warns of AI malware targeting Nigerian institutions

2026-05-07
Punch Newspapers
Why's our monitor labelling this an incident or hazard?
The malware DeepLoad explicitly uses AI techniques to evade detection and maintain persistence, which directly leads to harms including theft of sensitive data, identity theft, operational disruptions, and risks to national security infrastructure. The event involves the use and active deployment of an AI system (the malware) causing direct harm to individuals, organizations, and government entities. The harms described fall under injury to persons (identity theft), harm to property and communities (operational disruptions), and violations of rights (privacy breaches). Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

NITDA raises alarm over deadly AI malware targeting Nigerian government agencies, banks, businesses

2026-05-07
Legit.ng - Nigeria news.
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI-powered malware (DeepLoad) that is actively causing harm by stealing sensitive data, evading detection, and disrupting operations in Nigerian institutions. The harms described include financial fraud, identity theft, and disruption of critical infrastructure (government networks), which align with the definitions of AI Incident. The AI system's role in enabling the malware's stealth and persistence is pivotal to the harm. Hence, this is not merely a potential hazard or complementary information but a realized AI Incident.
Thumbnail Image

NITDA raises alarm on DeepLoad AI malware attacks, proffers solutions

2026-05-07
Premium Times Nigeria
Why's our monitor labelling this an incident or hazard?
The article explicitly states that DeepLoad is an AI-enhanced malware actively causing harm by stealing credentials, enabling unauthorized access to financial accounts, and threatening national security. These harms fall under injury to persons (identity fraud), harm to communities and organizations (disruption and data breaches), and violations of rights (privacy breaches). The AI system's use in evading detection and facilitating these attacks directly leads to these harms, qualifying this as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

NITDA raises fresh cyber alert over AI-powered DeepLoad malware

2026-05-07
Nairametrics
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system integrated into malware (DeepLoad) that is actively causing harm by stealing sensitive information, enabling financial fraud, disrupting operations, and threatening national security. These harms fall under injury to persons (identity fraud), harm to communities and organizations (operational disruptions), and violations of rights (unauthorized data access). Since the AI system's use has directly led to realized harms, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

NITDA Raises Alarm Over DeepLoad AI Malware Targeting Nigerian Organisations

2026-05-07
Channels Television
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (DeepLoad AI-powered malware) whose use has directly led to harms including theft of sensitive data, financial fraud risks, operational disruptions, and threats to national security. These harms fall under injury to persons (identity fraud), harm to property and communities (operational disruptions), and violations of rights (privacy breaches). Since the malware is actively attacking and causing harm, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

NITDA Raises Alarm Over AI-Powered Malware Targeting Banks, Govt Agencies

2026-05-07
TVC News Nigeria
Why's our monitor labelling this an incident or hazard?
The malware DeepLoad is explicitly described as AI-powered, using artificial intelligence to evade detection and maintain persistence. It is actively targeting and infecting systems, leading to direct harms such as financial theft, identity fraud, and operational disruptions. These harms fall under injury to persons (financial and identity harm), harm to communities and organizations (operational shutdowns and breaches), and violations of rights (privacy and confidentiality breaches). Therefore, this event qualifies as an AI Incident because the AI system's use has directly led to significant harms.
Thumbnail Image

NITDA Raises Alarm Over AI-Powered DeepLoad Malware Targeting Nigerian Banks, Government Agencies

2026-05-07
arise.tv
Why's our monitor labelling this an incident or hazard?
The DeepLoad malware is explicitly described as AI-powered and actively causing harm by infiltrating systems, stealing sensitive data, and evading detection. The harms include unauthorized access to bank accounts, identity fraud, operational disruptions, and risks to national security, which fall under injury or harm to persons, harm to communities, and disruption of critical infrastructure. Since the AI system's use in the malware directly leads to these harms, this qualifies as an AI Incident.
Thumbnail Image

NITDA lists protection steps as DeepLoad malware targets Nigerian users

2026-05-07
The Sun Nigeria
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (the AI-driven malware DeepLoad) whose use has directly led to harm, including theft of sensitive information and potential breaches of financial and personal security. This constitutes harm to individuals and organizations, fitting the definition of an AI Incident. The advisory's focus on active harm and ongoing infections confirms this classification rather than a mere potential risk or complementary information.
Thumbnail Image

Tech Regulator Issues Warning Over New AI-powered Cyberattack on Nigerians

2026-05-07
Techloy
Why's our monitor labelling this an incident or hazard?
The malware is an AI system (AI-powered malware) whose use has directly led to harms including financial loss, identity fraud, and potential compromise of classified government information. These harms fall under injury or harm to persons and harm to property or communities. Since the AI system's use has already caused realized harm, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

NITDA raises alarm over AI-powered malware targeting banks, agencies, others

2026-05-07
Peoples Gazette Nigeria
Why's our monitor labelling this an incident or hazard?
The malware is explicitly described as AI-powered, indicating the involvement of an AI system. Its use has directly led to harms such as unauthorized access to bank accounts and disruption of critical infrastructure workflows, which fall under harms to property, communities, and critical infrastructure. Therefore, this event qualifies as an AI Incident because the AI system's use has directly caused significant harm.