Nigeria’s digital identity reforms just delivered their first major counter-terrorism win. Seven suspected Boko Haram and ISWAP commanders were arrested at Katsina Airport last Thursday. They had just returned from the 2026 Hajj pilgrimage in Mecca. The breakthrough came through the National Identity Number database that is now linked to immigration and Interpol.
The Minister of Interior, Olubunmi Tunji-Ojo, disclosed the arrests on Friday. He spoke minutes after President Bola Tinubu signed the National Identity Management Commission Act 2026 into law. The new statute makes the NIN the single source of truth for every government transaction. It also forces all security agencies to share identity data in real time. Tunji-Ojo said the system flagged the seven commanders the moment their passports were scanned at the immigration desk.
The suspects were immediately handed over to the Department of State Services. No identities or charges have been released. The minister did not explain how the commanders obtained travel documents or who funded their pilgrimage. The question is now urgent: if the system can catch them on return, why did it not stop them from leaving?
The NIMC database has been live for less than eighteen months. It replaced a patchwork of independent registries that criminals routinely exploited. Before the reform, passports, driver licences and voter cards were issued without cross-checking against terror watchlists. Today every passport application is run against the NIN database. If the applicant is on any security watchlist, the system blocks the issuance and alerts the DSS.
The integration extends beyond Nigeria’s borders. The NIN database is now linked to Interpol’s 24-hour security network. This means any Nigerian passport used at any international airport is automatically checked against global terror and crime databases. The seven commanders were flagged because their names and biometrics matched entries on Interpol’s red notices. The arrest at Katsina Airport was the first operational test of this cross-border link.
The new NIMC Act 2026 tightens the legal framework. It mandates that every Nigerian must have a NIN before accessing any government service. It also imposes a five-year jail term for anyone who provides false identity information. The law eliminates the last data silos. From now on, the Federal Road Safety Corps, the Independent National Electoral Commission and the Central Bank must all pull identity data from the same source. This removes the gaps that terrorists and fraudsters have used for years.
The arrests expose a deeper institutional failure. The seven commanders travelled to Saudi Arabia on Nigerian passports. That means they must have passed through Nigerian immigration at least once before the Hajj. The fact that they were not flagged then suggests that the watchlist integration was either incomplete or ignored. The government has not explained whether the commanders were already on the terror watchlist before their departure. If they were, the system failed twice: once on exit, once on entry.
The case also raises questions about Saudi Arabia’s vetting of Hajj pilgrims. Nigeria sends over 95,000 pilgrims to Mecca every year. The Saudi authorities rely on the sending country to certify that each pilgrim is not a security risk. If seven known terror commanders were cleared, either Nigeria’s pre-departure screening is broken or Saudi Arabia’s oversight is lax. Neither explanation is reassuring for a country that hosts millions of religious tourists annually.
The government is already spinning the arrests as a success story. It is using them to justify the N23 billion spent on the NIN registration and database integration. But the real test is not how many terrorists are caught on return. It is how many are stopped from leaving in the first place. Until that happens, the system remains a reactive tool rather than a preventive shield.