NGNigeriaHowToNigeria services explained simply
Reference

Is BVN Safe to Share? — What to Give, What to Hold Back

The BVN by itself does not move money. But it is the identifier fraudsters need to weaponise a stolen phone number, a leaked password, or a captured OTP. Treat it the way you treat your account number, not the way you treat your NIN.

Written by NigeriaHowTo Editorial TeamEdited by Nikita Bystrykh, Founder & PublisherChecked against official sourcesUpdated July 2026Last reviewed 24 July 202610 min read

Quick answer

The BVN is safe to share with your bank, with CBN-licensed financial institutions during legitimate KYC, and with regulated fintechs that hold banking partnerships. It is not safe to share with unsolicited callers, in response to SMS or email links, or with any service that calls itself a 'BVN verifier' outside the bank's published channels. Treat the BVN the way you treat your account number rather than the way you treat your NIN — bank-side identifiers can be safely given to the bank, but they reach the systems that move your money, and that is what makes them load-bearing in fraud.

The three actors behind the BVN — and which one matters when

A reader trying to answer 'is this person allowed to ask me for my BVN?' needs the three-actor architecture in mind. Nothing in the answer makes sense without it.

Three institutions own different parts of the BVN: NIBSS (Nigeria Inter-Bank Settlement System) issues and holds the BVN record in the underlying database; the Central Bank of Nigeria (CBN) regulates the framework, sets KYC tiers, and issues policy circulars; the customer's bank is the public-facing point of enrolment and modification, submitting customer requests to NIBSS on the customer's behalf. A customer never deals with NIBSS or CBN directly — every BVN-related action surfaces at the bank counter.

The reader-facing implications:

  • The bank is always allowed to ask — they have your BVN on file already. They would not 'need' it from you in a normal transaction. The exception is during a KYC refresh or a new-product onboarding inside the bank, where confirming the BVN is part of the procedure. Even then, you should be inside the bank's own app, USSD platform, or at the branch — not on an inbound call you did not request.
  • NIBSS never talks to customers directly. NIBSS is institutional infrastructure. A caller claiming to be from NIBSS asking you to confirm your BVN is not telling the truth.
  • CBN never talks to customers directly about their BVN. CBN is the regulator. CBN issues circulars to banks; it does not ring account holders. A caller claiming to be from CBN asking for your BVN is also not telling the truth.

The bank is the only legitimate counter-party in your everyday life that asks for the BVN. Everyone else is either reading it through the bank (a regulated fintech with a NIBSS verification agreement, querying via the bank-of-record), or asking for something they are not entitled to.

For the verifier-side architecture of how the bank's BVN query reaches NIBSS — and the parallel NIN-side architecture at NIMC — see the cross-cluster NIN verification article. The NIBSS routing for BVN maps onto the bank-side path described there.

Third-party verification of a NIN passes through one of three paths. Banks query NIMC through the Nigeria Inter-Bank Settlement System (NIBSS), which is shared infrastructure owned by all licensed banks and the Central Bank of Nigeria. Telecommunications operators query NIMC directly through the NIMC Verification Service: MTN and Airtel run on the real-time path while Glo and 9mobile run batches. Government schemes (JAMB, NYSC, NIS passport processing) and large employers query through their own integration against the NIMC API. In every case NIMC holds the canonical record; verifiers maintain their own cached copies that refresh on different schedules.

Who you can safely share a BVN with

The list is shorter than most readers assume.

DocumentDetails
Your own bank — alwaysThe bank has your BVN on file from enrolment. They re-confirm it during KYC refresh, new-product onboarding, and certain compliance reviews. Share inside the bank's own channels (app, USSD, branch counter, authenticated customer-care line). Do not share through unauthenticated channels even with the bank — including SMS replies and unverified email.
Other Nigerian banks — at onboardingOpening a second or third account at a different bank requires the BVN. The new bank pulls the existing NIBSS record. Share at the bank's KYC desk, in the mobile app's onboarding flow, or through internet banking. The standard rules apply — verify the bank's identity through the formal channel before submitting.
Regulated Nigerian fintechs with banking partnershipsOpay, Kuda, Moniepoint, PalmPay, Carbon, FairMoney and similar fintechs operate under CBN regulatory oversight, hold banking partnerships or full banking licences, and have legitimate NIBSS verification agreements. Share through the fintech's official app or web portal (download from the official store, type the URL yourself rather than clicking a link). Be more cautious with newer apps you have not heard of.
The NRBVN platform — for diaspora usersThe Non-Resident BVN platform at nibss-plc.com.ng/nrbvn is the official online enrolment route for Nigerians in the diaspora. The platform is CBN- and NIBSS-operated and is the only legitimate online enrolment surface.
Government schemes with NIBSS verification agreementsSome federal schemes (employment programmes, scholarships, social-protection schemes) verify against the BVN. Confirm through the scheme's official communication channels — a government scheme will publish the BVN requirement on its own .gov.ng or official website, not through random social-media DMs.
Employers running payroll onboarding through the bankAn employer's payroll desk often asks for the BVN at salary-account setup. The BVN goes to the bank that will hold the salary account, not to the employer themselves. If the BVN never leaves the bank's onboarding form, the share is safe; if the employer asks you to email it, the channel has gone wrong.

The common feature across the list: every legitimate counter-party is either (a) the bank itself, or (b) a CBN-licensed institution holding the customer's data under regulated terms, or (c) a government scheme with a published NIBSS verification agreement. Anyone outside this set asking for your BVN is asking for something they are not entitled to.

Who you must never share a BVN with

The risk surface for unsolicited BVN sharing is well documented in Nigerian fraud reporting between 2022 and 2026.

  • Anyone who rings you about your account. No Nigerian bank rings a customer and asks them to confirm their BVN. They have it on file. A caller asking for the BVN, even one who quotes the last four digits or claims to be from the fraud desk, is running a social-engineering attack. Hang up and call the bank back on the number printed on the back of your debit card.
  • SMS or WhatsApp links claiming bank action. 'Your account has been flagged, confirm your BVN at this link' is a phishing template. Banks do not collect BVNs through SMS links. The link will lead to a fake bank login page that captures the BVN together with your account password.
  • 'BVN verification' websites or apps outside the bank's published channels. The 1 May 2026 CBN access-restriction amendment closed access to BVN data for non-CBN-licensed parties. Any third-party site still offering 'BVN verification' to consumers is either operating outside the legitimate framework or harvesting the data they receive.
  • Social-media DMs from accounts claiming to be the bank. Banks have a verified handle and a published customer-care number. A direct message from an unverified account asking you to confirm BVN details — even one that uses the bank's branding — is not the bank.
  • Loan-app onboarding flows that are not regulated. Some informal loan apps ask for the BVN as part of generic 'identity verification' without explaining what they will do with it. The legitimate fintechs in this space hold banking partnerships and are upfront about their NIBSS verification process; the rest are harvesting credentials at best and running theft operations at worst.
  • Anyone offering to 'fix' a BVN-related problem. A friend-of-a-friend or a Telegram contact who can 'help' you with a blocked account, a BVN-NIN mismatch, or a watchlist flag for a fee is running a scam. The legitimate route for every BVN-related fix runs through the bank — see BVN blocked account and our forthcoming BVN does not match NIN.

The pattern repeats: the legitimate counter-party either already has the BVN (the bank) or is asking inside a regulated KYC flow (other banks, regulated fintechs). Everything else is either fraud, or close enough to it that the safer answer is to assume so.

What the BVN actually exposes when it leaks

The reason 'is the BVN safe to share' is a non-trivial question is that the consequences of leakage are not obvious. The BVN by itself does not let a fraudster wire money out of your account; it is a passive identifier, not a credential like a PIN or an OTP. But the BVN is the load-bearing identifier in account-takeover fraud against Nigerian banks, and understanding why is what tells you when to worry.

The BVN by itself is not an authentication credential — knowing an account holder's BVN does not let an attacker move money from the account. But the BVN is the load-bearing identifier in account-takeover fraud against Nigerian bank customers. The canonical attack pattern is SIM-swap-led: an attacker collects the victim's BVN together with name, date of birth, phone number and other personal data from phishing, social media, leaked databases or bank-staff insider routes, then convinces a telco to issue a SIM swap on the victim's number, then intercepts the bank-OTP messages routed to that number and authorises transfers from the account. NIBSS's 2023 Annual Fraud Landscape placed fraud-related losses across Nigerian financial institutions at ₦17.67 billion; ThisDay reported in 2025 that over 5,000 OPay accounts were compromised through SIM-swap and phishing scams in a two-stage attack that captured credentials first and then took control of the linked phone numbers to bypass SMS-based 2FA. The defensive implication: the BVN is shareable with the customer's own bank and with CBN-licensed financial institutions during legitimate KYC, but never with unsolicited callers, never in response to SMS or email links, and never with anyone offering 'BVN verification' outside the bank's published channels. The 1 May 2026 CBN amendments tightened the credential side by restricting BVN data access to licensed financial institutions and adding the one-device mobile-banking rule with a ₦20,000 first-day cap.

The canonical attack pattern is SIM-swap-led. The mechanics in detail.

Nigerian banks reported a sustained increase in SIM-swap-related fraud cases between 2022 and 2024. NIBSS data referenced by Nigerian press placed attempted fraud across financial institutions at around ₦17.67 billion in 2023, with mobile and digital channels accounting for the bulk of attacks. The fraud pattern: a malicious actor convinces a telco to issue a SIM swap on a victim's number using social engineering or insider collusion, intercepts the bank-OTP messages routed to that number, and authorises transfers from the victim's bank account. The NCC and CBN response has tightened SIM-swap KYC over 2024-2025: mandatory biometric reverification at the service-centre desk, more questions tied to the original SIM record, and the Telecom-Banking Integration and Risk Management System (TIRMS) that lets banks check in real time whether a phone number has recently been re-issued before authorising a high-value transfer.

Step by step from the attacker's side:

  1. Collect the victim's BVN, name, date of birth, phone number, and account information. Sources vary: phishing emails, social-media reconnaissance, leaked databases, bank-staff insider routes, fraudulent KYC services that harvest the data customers submit. The BVN is often the last piece collected because it is the credential that lets the attacker impersonate the customer to the bank's systems.
  2. Convince a telco to issue a SIM swap on the victim's number. This is the friction point. The telco's service desk should ask for security questions tied to the original SIM record (last recharge amount, frequently-dialled numbers, year of activation). An attacker with the BVN and biographic data can answer many of these from prior research; a corrupt or insufficiently-trained agent can be socially engineered.
  3. Intercept bank-OTP messages on the new SIM. Once the SIM swap clears, every OTP the bank sends to the customer's registered number arrives at the attacker's handset instead. The bank app's password-reset flow is now the attacker's, because it depends on the SMS OTP.
  4. Authorise transfers from the customer's bank account. With the bank-app password reset and the OTP channel captured, the attacker logs into the bank app, initiates transfers, and authorises them with the captured OTPs. The customer learns of the breach when they next try to use the line, or when the bank rings them on a number they cannot answer.

The BVN's role is the impersonation glue. Without the BVN, the attacker has data but no way to tie it to the customer's bank-side identity. With the BVN, the attacker can satisfy the bank's KYC questions, recover passwords, complete the SIM swap, and authorise the transfers as if they were the customer.

The 1 May 2026 CBN amendments include several layers explicitly aimed at this pattern.

From 1 May 2026 a Nigerian customer's mobile banking app may be active on only one device at a time. Activating the bank's app on a new device automatically deactivates the previous device and triggers additional authentication. For the first 24 hours after a new-device activation the app is capped at a ₦20,000 transaction ceiling. The cap is intended to limit damage where a stolen or fraudulently-obtained device tries to drain the account before the customer detects the change.

The amendments also restrict BVN data access to CBN-licensed financial institutions, reducing the surface through which fraudsters can collect the BVN at scale; and require banks to flag any BVN linked to suspicious transactions for up to 24 hours pending account-holder contact.

From 1 May 2026 the Central Bank of Nigeria has tightened the BVN framework. Headline changes: BVN-linked phone number can be changed only once in a lifetime; minimum age for an independent BVN is set at 18; access to BVN data is restricted to CBN-licensed financial institutions; banks must flag any BVN linked to suspicious transactions for up to 24 hours pending account-holder contact; mobile banking apps may only be linked to one device at a time with a temporary ₦20,000 transaction cap on the first 24 hours after a new-device activation.

None of these layers makes the BVN safe to share with arbitrary parties. They reduce the damage when a multi-credential attack succeeds, but the defensive primary line is still 'do not give the BVN to anyone outside the legitimate counter-parties above'.

Concrete examples — safe versus unsafe, in everyday language

Abstract rules are easy to forget at the moment of decision. Concrete patterns are harder to forget.

DocumentDetails
Safe — at the bank counter opening a new accountYou walk into a bank branch with ID and ask to open an account. The KYC desk asks for the BVN. Share. The bank holds your existing record at NIBSS and is the legitimate next-bank counter-party.
Safe — on a regulated fintech's official app at onboardingYou downloaded Opay or Kuda or Moniepoint from the official Apple App Store or Google Play. The onboarding flow asks for the BVN as part of KYC. Share. The fintech holds a banking partnership and is querying NIBSS through legitimate channels.
Safe — when transferring a Tier-2 or Tier-3 KYC profile to a new bankYour existing bank has the BVN already. The new bank asks for it at second-account onboarding. Share inside the new bank's KYC flow. The two banks both query the same NIBSS record.
Unsafe — to a 'support agent' who rang you about a transaction you did not makeReal banks do not collect BVNs over the phone. The pattern is a fraud-line impersonation: the attacker creates urgency, asks for the BVN to 'verify your identity', and the BVN together with other data they already hold is what they use to run the SIM swap. Hang up; ring the bank back on the number on your card.
Unsafe — at a link in an SMS or WhatsApp message about your accountThe link leads to a fake bank login page. Pasting the BVN there hands it to the attacker. If the message references an actual transaction, ring the bank through their published number — do not click the link.
Unsafe — to a 'BVN check' website you found through a search resultEspecially after May 2026. Legitimate BVN reading happens through the bank's app, USSD *565*0#, or the branch. A third-party website asking you to type the BVN to 'check' or 'validate' is either harvesting it or running an outdated service that may already be unauthorised.
Unsafe — to an employer's HR who asks you to email the BVNThe BVN should reach the bank that will hold the salary account, not the employer's email server. If the employer's payroll onboarding goes through a bank, the BVN goes into the bank's onboarding form — not into an email attachment. Push back on the channel before sharing the value.
Unsafe — to a friend who 'has a way' to lift a BVN restrictionRestrictions lift through the bank's compliance process. A third party offering to 'help' for a fee is either running a scam or, more dangerously, trying to collect more data to deepen the impersonation. See [BVN blocked account](/bvn/bvn-blocked-account/) for the legitimate route.

The pattern reduces to one question: did I initiate this contact through a channel the bank publishes? If yes, the share is usually safe. If the contact came to you — and especially if it came with urgency — the share is almost always unsafe.

The 1 May 2026 amendments — what they mean for sharing

The CBN BVN framework amendments effective 1 May 2026 do not change the everyday share decision, but they do change the post-share environment in ways the customer should know.

  • BVN data access restricted to CBN-licensed institutions. Before May 2026, a wider set of third-party verifiers could query the BVN database. After, only CBN-licensed financial institutions retain access. The reader-facing implication: 'verification services' that previously sat outside the bank are no longer part of the legitimate process. If a non-bank counter-party asks for the BVN to 'verify' you in 2026, ask which CBN-licensed institution they are querying through and verify independently.
  • One-lifetime BVN phone-number change. A customer who has already shared their BVN with the wrong party and whose phone number subsequently gets swapped cannot 'reset' by changing the BVN-linked number more than once. The single change is irreversible. Plan around it; do not spend it lightly.
  • 24-hour suspicious-transaction hold. If a BVN has been shared with a fraudster and the attempted transfer pattern-matches against fraud signals, the bank now flags and pauses for up to 24 hours pending account-holder contact. This is the post-share recovery window. Answer the bank's call.
  • One-device mobile-banking rule with ₦20,000 first-day cap. A stolen-device attack that follows a BVN exposure is now capped at ₦20,000 in the first 24 hours after a new-device activation. The cap does not stop the attack but it limits the loss while the customer detects and reports.

None of these layers is a replacement for the share discipline above. They are the institutional belt-and-braces. The reader-facing primary defence is still not sharing the BVN with anyone outside the legitimate counter-parties.

If you have already shared the BVN with the wrong party

A reader who arrived at this article after sharing the BVN with someone they should not have needs the recovery sequence in the right order. The window between 'BVN leaked' and 'money moved' is usually hours, not days, when the attacker has the full credential set.

  1. 1
    Ring the bank's fraud line immediatelyRead the number off the back of your debit card or from the bank's app — not from any SMS or email message about the incident, those are also likely fraudulent. Ask the fraud desk to place a hold on outgoing transactions pending a review. The 24-hour suspicious-transaction hold under the 1 May 2026 amendments is a defensive layer, but a customer-initiated hold is faster.
  2. 2
    Watch for a SIM-swap notificationIf the BVN was leaked together with your phone number, the canonical follow-on attack is the SIM swap. A notification from your telco about a SIM activation you did not initiate is the urgent signal. Ring the telco's fraud line immediately if you see one — MTN 180 from an MTN line or 0803 100 0180 from another; Airtel 300 from Airtel or 0802 150 0111; Glo 300 from Glo or 0805 002 0121; 9mobile/T2 200 from T2 or 0809 000 0200.
  3. 3
    Change every password that shares biographic data with the BVNBank-app password, email password, fintech-app passwords. Use a fresh password the attacker would not guess from the data they hold. Where the bank supports authenticator-app 2FA instead of SMS OTPs, switch to it — SIM-swap fraud beats SMS OTPs but does not beat authenticator-app tokens.
  4. 4
    Audit recent account activity across every BVN-linked bankA BVN-level attack often probes multiple banks against the same BVN. Log into every bank where you hold an account, review recent transactions, and report anything you do not recognise. Quote the BVN-leak incident as the context.
  5. 5
    File a report with the bank's compliance deskBeyond the customer-care call, ask for a formal incident reference. The bank's compliance officer should be aware that the BVN may be in circulation; this informs their fraud-watchlist logic for the next 30 to 60 days against your specific BVN.
  6. 6
    Do not change the BVN-linked phone number unnecessarilyFrom 1 May 2026 each customer has one lifetime BVN phone-number change. If the SIM has not been swapped and the existing number is still yours, do not spend the change on the recovery; spend it only if the original line is genuinely lost or compromised. See [BVN phone number update](/bvn/bvn-phone-number-update/) for the change framework.

A clean recovery from a BVN leak usually does not result in a financial loss when the bank and the customer move quickly together. The 24-hour suspicious-transaction hold, the one-device rule, and the ₦20,000 first-day cap are all designed to keep the window narrow enough for a vigilant customer-and-bank pair to close.

Why the BVN is not 'just like a NIN'

Readers sometimes treat the BVN and the NIN as interchangeable on the safety axis because they are both 11-digit national identifiers. The fraud-exposure profile is different and the difference matters.

The NIN identifies you to the Nigerian state generally — passports, JAMB, NYSC, FRSC, FIRS, NPower, state schemes. A leaked NIN is dangerous in an identity-theft sense (false applications in your name, fraudulent enrolment for benefits) but it does not directly reach the systems that authorise money transfers.

The BVN identifies you to the systems that authorise money transfers — Nigerian banks, fintechs with banking partnerships, NIBSS-mediated verifiers. A leaked BVN, combined with the other ingredients in a SIM-swap attack, reaches the bank's transaction-authorisation layer directly. The damage path is shorter and the time-to-loss is faster.

The practical reframing: treat the BVN the way you treat your account number. Both are identifiers, neither is an authentication credential on its own, but both reach systems that move your money when combined with the rest of the credential set. The NIN, by contrast, is closer to your driver's licence number in everyday risk terms — annoying if leaked, but not immediately money-relevant.

For the full BVN-versus-NIN comparison, the BVN vs NIN cluster article walks the regulator, issuer, age floor, and primary use side by side.

Three-actor summary — keep this list in your head

The summary that resolves most everyday share decisions in two seconds.

DocumentDetails
BankCustomer-facing. Holds your BVN already, asks for it during KYC refresh and new-product onboarding. Share inside the bank's own channels (app, USSD, branch, authenticated customer-care). Never share through unsolicited inbound contact.
NIBSSInstitutional. Issues and holds the BVN. Does not talk to customers directly. A caller claiming to be from NIBSS asking for your BVN is not from NIBSS.
CBNRegulator. Issues circulars to banks and to NIBSS. Does not talk to customers directly about their BVN. A caller claiming to be from CBN asking for your BVN is not from CBN.
CBN-licensed fintechs and other banksOperate under the same KYC framework as banks; legitimate counter-parties at onboarding through their own apps or websites you typed into the browser yourself.
Everyone elseNot entitled to your BVN. If they need to verify you, they verify through one of the above. If they ask you for the BVN directly, the answer is no.
  • Do NOT give your BVN to anyone who calls you. Banks do not collect BVNs over unsolicited calls; CBN and NIBSS do not call customers at all. End the call and ring the bank back on the number printed on your debit card.
  • Do NOT type your BVN into a website you arrived at through an SMS or email link. Even when the page looks like your bank's login, the typical fraud route is a clone page that captures the BVN and the account password together.
  • Do NOT post a screenshot of the bank's profile screen that shows your BVN alongside your account number. The pair is more dangerous together than either alone.
  • Do NOT pay an agent for 'BVN protection' or 'BVN insurance'. There is no such product; the institutional fraud-control layers (the 1 May 2026 access restriction, the 24-hour watchlist, the one-device rule) sit at the bank and at NIBSS without customer payment.

Account already restricted after a BVN exposure?

If a SIM-swap attempt or a suspicious-transaction flag has produced an account hold, the recovery flow runs through the bank's fraud desk and the compliance officer.

Read BVN blocked account — restoring service →

Frequently asked questions

Is it safe to share my BVN?

It depends entirely on who is asking. The BVN is safe to share with your bank, with CBN-licensed financial institutions during onboarding or KYC refresh, and with regulated government schemes that have NIBSS verification agreements. It is never safe to share with unsolicited callers, with SMS or email links, or with anyone offering 'BVN verification services' outside the bank's published channels.

Why did the CBN restrict access to BVN data in May 2026?

To close the loophole through which non-bank third parties were querying BVN data without the controls CBN-licensed institutions are subject to. The 1 May 2026 amendments restrict access to CBN-licensed financial institutions, tighten the modification framework, and add fraud-control layers including the 24-hour suspicious-transaction hold and the one-device mobile-banking rule with a ₦20,000 first-day cap.

Can the BVN alone be used to drain my account?

Not directly. The BVN is an identifier, not an authentication credential. The danger is not the BVN in isolation but the BVN as one ingredient in a multi-credential attack: SIM-swap to capture OTPs, phishing to capture passwords, and the BVN to identify the customer to the bank's systems for impersonation. The 1 May 2026 ₦20,000 first-day cap on new-device activations is one of several layers designed to limit damage when a multi-credential attack succeeds.

What is the difference between the BVN and the NIN for fraud exposure?

The BVN identifies the customer to systems that move money — Nigerian banks, fintechs with banking partnerships, NIBSS-mediated verifiers. The NIN identifies the customer to the Nigerian state generally. Both are 11-digit credentials, but the BVN is the more directly weaponisable of the two in account-takeover fraud because the BVN reaches the bank's transaction-authorisation systems. The NIN is broader; the BVN is sharper. See [BVN vs NIN](/bvn/bvn-vs-nin/).

I shared my BVN with someone I should not have — what now?

Ring your bank's fraud line immediately on a number you read from the back of your debit card, not from any SMS or email message about the incident. Place a hold on outgoing transactions until the bank's fraud desk can review. Change your bank-app password and any account passwords that share the BVN's biographic details. Watch for an SMS confirming a SIM swap on your phone number — that is the canonical follow-on attack pattern.

Is it safe to give my BVN to a fintech app at onboarding?

Safe at fintechs that hold a banking partnership and are operating under CBN's regulated KYC framework. Most large Nigerian fintechs (Opay, Kuda, Moniepoint, PalmPay, Carbon, FairMoney) are in this group and have legitimate NIBSS verification agreements. Be more cautious with newer apps that have no clear regulator and ask for the BVN as part of a generic 'verify your identity' flow without explaining what they will do with it.

Should I use the Virtual NIN or any equivalent for the BVN?

There is no direct BVN equivalent of the Virtual NIN tokenisation route. NIMC issues vNINs for NIN privacy; NIBSS does not currently issue a customer-side BVN token. The fraud-control layers built into the BVN side instead are institutional — the May 2026 access restriction, the one-device rule, the suspicious-transaction watchlist — rather than tokenisation-based.

Sources

Independent guide, not affiliated with any government agency. The facts, fees and steps above are checked against the primary sources below — government, regulator and agency material first, reputable press second.

  1. 1.Central Bank of Nigeria — Bank Verification Number
  2. 2.NIBSS — Bank Verification Number (BVN) page
  3. 3.Times Nigeria — CBN Tightens BVN Rules from May 1 (2026)
  4. 4.BusinessDay — Major BVN Update: CBN tightening the screws on Nigeria's banking identity system
  5. 5.Ecofin Agency — Nigeria Links Banks to Telecom Grid to Catch Fraud (TIRMS)
  6. 6.BusinessDay — Why SIM swap scams are Nigeria's silent cyber war
  7. 7.Daily Trust — SIM-related Frauds On The Rise In Nigeria
  8. 8.Profiled Nigeria — How Identity Theft and SIM Swap Are Ruining Lives in Nigeria
  9. 9.Dubawa — 5 New BVN rules Nigerians must know before May 1
  10. 10.ThisDay — Nigeria and Digital Fraud (Oct 2025, on the OPay 5,000-account SIM-swap compromise)

Facts verified against the NigeriaHowTo facts registry.

About the author

NigeriaHowTo Editorial Team

Editorial Research Team

The NigeriaHowTo Editorial Team researches and maintains practical guides about Nigerian documents, online portals, government-related procedures, and everyday administrative services. The team focuses on plain-English explanations, clear structure, official-source references, practical checklists, and user safety. The team is not a government authority, legal adviser, immigration practitioner, banking professional, tax expert, education official, or medical professional — independent subject-matter review is added separately when qualified reviewers are engaged.

View full profile →