•  
  •  
 

Publication Date

2026

Abstract

SourceURL:file:///home/amaechi/Documents/ *Journal of Cybersecurity Education, Research and Practice (JCERP)*. **Title:** The Soft Target Curriculum: Using Nigeria's 2026 Cascading Breaches to Teach Foundational Cybersecurity Failures.docx

Background: Between March and April 2026, a single threat actor allegedly compromised four Nigerian institutions across banking, payment infrastructure, government registry, and power distribution sectors. The breaches exposed millions of records and disrupted critical services, yet all four exploited elementary vulnerabilities taught in introductory cybersecurity courses. Objective: This pedagogical case study analyzes the four breaches as a unified phenomenon of "normalized negligence" and provides ready-to-use teaching materials for cybersecurity educators. Methods: Using open-source intelligence analysis of actor-published artefacts, threat actor interviews (Odes, 2026a, 2026b, 2026c), and the validated Yusuf-Steyn framework for cybersecurity-compliant behavior (2024), we reconstructed each attack chain and mapped observed failures to foundational security principles. Results: All four breaches exploited five elementary vulnerabilities: unpatched software (CVE-2025-55182, CVSS 10.0), hardcoded credentials in source code, sequential user identifiers (e.g., 4705317) instead of random UUIDs, client-side validation only, and implicit trust corridors between institutions. The recurrence across sectors demonstrates that "normalized negligence"—the gradual acceptance of unsafe practices—is a human and organizational problem, not merely a technical one. Conclusion: This paper provides a ready-to-use teaching case study with five modular components: (1) Secure Coding, (2) Network Security & Zero Trust, (3) Access Control & Identity Management, (4) Incident Response, and (5) Policy & Governance. Discussion questions, in-class exercises, and assessment rubrics are included for immediate classroom use.

Share

COinS