Phishing Attacks in Nigeria: Real Cases, Common Scams, and How to Stay Safe

Phishing attacks in Nigeria: Learn about scams and secure your online safety.

Phishing Attacks in Nigeria: Real Incidents and Practical Ways to Stay Protected

Phishing is one of the fastest-growing cybersecurity threats facing individuals and businesses in Nigeria, and the attacks are changing shape faster than most awareness programmes can keep up with. As Nigeria’s digital economy expands, criminals are exploiting the same channels businesses and consumers rely on: banking apps, email, WhatsApp, and, increasingly, AI-generated voice and video.

The 2025 figures tell a more nuanced story than the headline number suggests. According to the Nigeria Inter-Bank Settlement System (NIBSS), digital payment fraud losses fell 51% to ₦25.85 billion in 2025, down from ₦52.26 billion in 2024. On the surface, that reads as progress.

But NIBSS data also shows that social engineering, including phishing, impersonation, and account takeovers, now accounts for nearly half of all fraud cases. Fraudsters are carrying out fewer, more targeted, and more damaging attacks than before.

Phishing succeeds because it exploits human decision-making under pressure as much as technical weaknesses. Understanding how these attacks unfold, and what has changed about them recently, is the first step toward recognising and avoiding them.

The Scale of the Problem

YearFraud IncidentsDigital Payment Fraud Losses
2023N/A₦17.67 billion
202470,111₦52.26 billion
202567,518₦25.85 billion

The pattern matters more than any single figure. Incident counts have stayed roughly flat, but 2024’s spike was driven largely by one anomalous ₦31.1 billion case, and losses dropped once that outlier cleared the system.

Lagos accounted for 63.43% of reported fraud activity in 2025, reflecting its position as Nigeria’s commercial hub, with Abuja, Ogun, Rivers, and Delta States making up most of the remainder. E-commerce and internet banking remain the most affected channels, followed by point-of-sale, mobile, and web platforms.

Nigeria’s vulnerability to phishing stems from rapid fintech adoption without matching security awareness, a persistent shortage of cybersecurity professionals, and economic conditions that create both victims and opportunistic perpetrators.

A separate industry report, “The Compliance Reckoning”, found that fraud enhanced by artificial intelligence is roughly 4.5 times more profitable than conventional methods.

AI lets criminals automate campaigns, generate convincing fake identities, and bypass verification systems far more easily than even two years ago. For Nigerian businesses, that means phishing is becoming harder to spot while requiring less effort from criminals to pull off.

Real Cases Behind the Statistics

Individuals and businesses across Nigeria have lost billions to phishing attacks in recent years, and the pattern across cases is consistent: attackers create urgency, exploit trust, and move funds before the victim or the institution can react. (For more examples, see the Nigerian data breach case studies collection.)

The Major Banking Phishing Campaign (2023)

In 2023, industry reports described one of the largest phishing campaigns yet to target customers of several major Nigerian banks. Fraudulent emails and texts directed victims to fake websites nearly identical to real banking portals. Once entered, credentials gave fraudsters access to accounts and a path to transfer funds into mule accounts.

The affected banks strengthened monitoring, blocked compromised accounts, and expanded authentication measures while warning customers about the campaign, but millions of naira had already disappeared by the time it was contained. The incident demonstrated how convincing a cloned website can be, and how easily fear of losing account access can override caution.

Fintech Unauthorised Transactions (2024)

In April 2024, a major payment platform reported unauthorised transactions totalling between ₦11 billion and ₦20 billion, discovered through unusual account activity flagged by monitoring systems.

Funds moved through accounts at five financial institutions to avoid detection. The platform issued refunds where appropriate and maintained that no customer funds were directly compromised, but the incident showed that even well-resourced platforms can be breached through defences that slip past standard monitoring.

Digital Wallet Compromises (2024/2025)

According to media reports, more than 5,000 OPay accounts were compromised through a combination of phishing and SIM-swap fraud. The two-stage attack worked by first capturing credentials through phishing messages, then using SIM-swapping to intercept the SMS-based two-factor authentication codes users believed were their strongest layer of protection.

OPay issued refunds, but the incident damaged user confidence and reinforced concerns about the safety of digital wallets more broadly.

Business Email Compromise Goes International

A Nigerian national was sentenced to 10 years in U.S. federal prison for a $20 million business email compromise scheme targeting real estate transactions. The group sent phishing emails with malicious attachments to title companies, real estate agents, and attorneys, prompting employees to enter their email credentials.

With access to legitimate accounts, the group monitored conversations about pending transactions and sent fraudulent payment instructions at the right moment to redirect funds. The scheme involved collaborators in Nigeria and the UAE, some still at large, and demonstrates how organised and patient these operations have become.

Insider-Enabled Fraud (2023)

In 2023, First Bank uncovered an employee-led ring that had siphoned ₦40 billion through proxy accounts and shadow beneficiaries. Phishing was not the primary attack vector here, but incidents like this show how stolen credentials, social engineering, and insider abuse often reinforce one another in larger fraud operations.

The case is a reminder that some of the biggest threats originate inside an organisation, and that external defences are not enough without internal controls and continuous monitoring. (See the guide on insider threats in Nigeria for more.)

How Phishing Attacks Work in Nigeria

Obvious scams with poor grammar and clumsy formatting still exist, but professional criminals now deploy well-crafted, personalised messages, cloned WhatsApp accounts built from stolen profile photos, and, increasingly, synthetic voice and video.

Common Tactics Targeting Nigerians

The most effective phishing messages exploit specific aspects of Nigerian life: claims that a Bank Verification Number or Permanent Voter Card has expired, fake electricity bill warnings referencing legacy or current distributors, and fraudulent student loan portal messages.

Other common variants include job offers requiring upfront fees, romance scams that build trust before requesting money, fake crypto investment platforms, cloned Central Bank of Nigeria or Nigeria Data Protection Commission communications, and urgent messages impersonating family members.

These attacks work because they tap into basic instincts: urgency overrides caution, apparent authority discourages questioning, and trust lowers defences. Criminals also piggyback on current events, promising voter confirmations during elections or demanding “information updates” during policy changes.

AI Voice Cloning and Deepfake Impersonation

The clearest shift in the past year is the move from text-based deception to voice and video. Nigerian financial institutions are now dealing with fraudsters using AI-generated or cloned voices and deepfake video to bypass liveness checks during remote onboarding and to impersonate bank staff, executives, or trusted contacts on live calls.

These attacks typically begin with stolen identity information, such as names, phone numbers, national IDs, or banking credentials, often harvested through earlier phishing campaigns or data breaches. They then use AI tools to build a synthetic voice or facial video matching that identity.

In early 2026, threat actors were advertising large datasets of stolen identity material from West Africa on criminal forums to fuel exactly this kind of attack.

Voice cloning has reportedly crossed a threshold where listeners can no longer reliably distinguish a cloned voice from a real one, so a recognisable voice on a call can no longer be trusted as proof of identity on its own, whether it claims to come from a bank, an employer, or a family member.

The Business Threat: Email Compromise

Business Email Compromise (BEC) remains among the costliest and most targeted forms of phishing in Nigeria. Unlike mass phishing, BEC is preceded by weeks of reconnaissance, with attackers studying company structures, vendor relationships, and communication patterns, sometimes after compromising a low-level employee’s email first.

Most BEC attacks follow four stages. Reconnaissance involves harvesting employee names, roles, and workflows from LinkedIn, company websites, or prior data leaks. Initial access is gained through a phishing email disguised as an invoice, contract, or HR update.

Persistence and monitoring follow, with attackers remaining undetected while tracking email threads for payment-related discussions. Execution involves a spoofed or compromised email requesting a last-minute change to bank details, often timed to coincide with high-pressure deal closings.

Average losses per BEC incident in Nigeria range from ₦40 million to ₦200 million. The damage extends beyond finances: contracts are delayed or cancelled, client trust erodes, and regulatory scrutiny intensifies under the Nigeria Data Protection Act, which holds organisations accountable for failing to secure personal data.

Warning signs include sudden email address changes from known vendors, requests to expedite payments outside normal channels, use of free email domains for supposedly official business, and payment instructions sent only by email with no verbal or in-person confirmation.

Effective prevention requires layered controls: email authentication through DMARC, SPF, and DKIM, mandatory dual approval for payments, and out-of-band verification through a pre-registered phone number or secure messaging app. The guide to ransomware protection for Nigerian businesses covers BEC mitigation strategies in more depth.

How to Spot a Phishing Attempt

Red flags include sender address variations that resemble legitimate domains at a glance, generic greetings, urgent threats or impossible offers, and mismatched URLs visible only when hovering over a link. Grammar mistakes are no longer a reliable indicator, since modern phishing content is often flawlessly written.

The most reliable rule is to never act on a link from an unexpected message. Closing the message and opening a banking app directly, or calling an organisation using a number from its official website rather than one supplied in the message, removes most of the risk in a single step.

Prevention: What Works

For Individuals

A short set of habits closes most of the exposure individuals face day to day:

  • Use unique, strong passwords for each account, ideally through a password manager
  • Enable multi-factor authentication on every banking and email account
  • Never share OTPs, PINs, or card details with anyone, regardless of who is asking
  • Protect the SIM with a PIN to reduce the risk of SIM-swap attacks
  • Download apps only from legitimate stores and keep them updated
  • Treat urgency as a reason to pause and verify rather than comply; legitimate banks do not threaten immediate account closure by text
  • Check URLs carefully, limit personal information shared on social media, and avoid public Wi-Fi for banking

If an Account Has Been Compromised

The immediate priority is disconnecting from the internet and changing passwords from another trusted device. Calling the bank, enabling fraud alerts, and taking screenshots of evidence should follow quickly.

Incidents can be reported to the EFCC and ngCERT, and accounts should be monitored closely for three to six months afterwards. Reporting an incident, even one that feels embarrassing, helps protect others from the same scheme. The guide to responding to data breaches in Nigeria covers the fuller response process.

For Businesses

Technical defences include email security, endpoint protection, regular vulnerability assessments, network segmentation, and tested backup systems. The guide to email security for Nigerian businesses covers these email-specific controls in more depth.

Nigerian SMEs and startups face distinct constraints that call for tailored approaches rather than enterprise-scale solutions applied wholesale.

The human element matters just as much as the technical layer. Regular security awareness training, simulated phishing tests, and clear no-blame reporting procedures all reduce the odds that a single convincing message turns into a six-figure loss.

NDPA Compliance

Organisations that process personal data of more than 2,000 data subjects within a 12-month period are required to engage a data protection compliance organisation for an annual audit.

More broadly, every organisation handling personal data must implement appropriate security measures, report breaches to the NDPC within 72 hours, train employees on data protection, and maintain access controls, encryption, and documented incident response procedures.

Penalties for non-compliance now reach ₦10 million or 2% of an organisation’s annual gross revenue, whichever is higher, reflecting a marked shift toward active enforcement.

That shift is not theoretical. In April 2026, a wave of breaches hit several major Nigerian institutions within weeks of each other, including the Corporate Affairs Commission, Sterling Bank, the government payment platform Remita, and the EFCC. The NDPC opened an investigation into the Corporate Affairs Commission breach the same day it was confirmed.

The federal government has since established a coordination council bringing NITDA, the Nigerian Communications Commission, and the NDPC together to respond to threats across sectors.

The guide on data protection officers in Nigeria and the practical guide to the Nigeria Data Protection Act cover the requirements in full.

Free Resources

The National Information Technology Development Agency (NITDA), working with ONSA and the UK Foreign, Commonwealth & Development Office, offers a free cybersecurity toolkit for SMEs covering phishing, ransomware, and incident response.

NITDA also provides free vulnerability testing for MDAs, and ngCERT offers incident response support to affected organisations and individuals.

Quick Reference: Is This Message Legitimate?

A quick checklist before clicking any link or downloading any attachment can prevent most successful phishing attempts:

  • Does the sender’s address exactly match the organisation’s official domain?
  • Was this message expected, or does it arrive out of nowhere?
  • Is there urgent pressure to act immediately?
  • Is the message asking for sensitive information such as passwords, PINs, OTPs, or card numbers?
  • Does the link’s actual URL match the legitimate website when you hover over it?
  • Would this bank, employer, or family member realistically make contact this way?

A “no” or “not sure” answer to any of these questions is a reason to stop and verify independently through the organisation’s official contact information rather than anything provided in the message itself.

How PlanetWeb Can Help

Phishing works by exploiting the gap between what technology can protect and how people make decisions under pressure. No email filter or firewall stops someone from entering a password on a convincing fake website, and no policy document stops an employee from trusting a familiar-sounding voice on an urgent call.

Technical controls alone are not enough. Policies, staff awareness, and practical verification procedures matter just as much.

PlanetWeb works with Nigerian organisations to assess phishing risks, strengthen technical controls, and improve staff awareness before an incident occurs. If your organisation needs a clearer picture of where its exposure sits, get in touch.

Frequently Asked Questions

Can I get a refund if I fall victim to a phishing attack?
It depends. Quick reporting to a bank may allow transaction reversal, and some platforms, including OPay in past mass incidents, have issued refunds. Once funds leave the system entirely, recovery becomes unlikely, which makes prevention the more reliable defence.
Is two-factor authentication still secure if SIM swaps can bypass it?
SMS-based two-factor authentication is better than nothing but remains vulnerable to SIM swaps. Authenticator apps or hardware security keys provide stronger protection than SMS codes.
What should I do if I receive a suspicious message from what looks like my bank?
Links or numbers in the message should not be used. The safer path is to close it and contact the bank through the official number on its website or debit card. Banks never ask for OTPs, PINs, or full card details.
Are Nigerian banks and fintechs doing enough to protect customers?
Institutions are investing in stronger monitoring and authentication, but no system is complete. Individual awareness remains the strongest defence against social engineering specifically, since it targets the person rather than the system.
How can I verify an urgent payment request that appears to come from a CEO?
Calling the CEO on a known, pre-established number rather than one provided in the message or call is the reliable check. Dual approval for large transfers and independent verification of payment requests close most of the remaining risk.
What is the penalty for phishing under Nigerian law?
Nigeria’s Cybercrimes (Prohibition, Prevention, etc.) Act, strengthened by the 2024 Amendment, treats phishing-related conduct as computer fraud, identity theft, or unauthorised access, with fines and prison terms that vary by the specific offence charged.

Organisations carry a separate obligation to report qualifying incidents to the NDPC within 72 hours, with penalties for non-compliance running into millions of naira. Cross-border enforcement remains difficult, which is part of why prevention matters more than pursuing recovery after the fact.

Share this article:

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top