Saturday, September 5 Lagos newsroom Newsroom online
Edition: Africa
Cybersecurity

How Phishing Scams Work and How to Spot Them

Phishing uses a convincing message, page or call to make a person reveal information, send money, install software or approve an action that benefits the attacker.

A phone user checking a suspicious account message before responding
AI-generated realistic editorial image illustrating a phishing warning. It is not a documentary photograph.
Tech Embed AI-assisted realistic editorial image

Phishing uses a convincing message, page or call to make a person reveal information, send money, install software or approve an action that benefits the attacker.

A message arrives claiming to be your bank. It says there’s a problem with your account. Click here to fix it, right now, or lose access. That urgency is the entire attack — not the logo, not the spelling, not even the link itself.

Phishing works by borrowing trust. The attacker copies the look of a real organisation and manufactures a reason to act fast, before you’ve had time to check anything.

The Pattern Behind Almost Every Phishing Attempt

Strip away the specific story — delivery fee, frozen account, unpaid invoice — and four steps remain.

  1. Attention. Money, danger, or a missed opportunity gets your eyes on the message.
  2. Pressure. Act now, or something bad happens.
  3. Action. Click a link, call a number, send a code.
  4. Capture. A fake page or a patient voice on the phone takes what it needs.

Warning Signs Worth Slowing Down For

None of these alone proves a scam. Together, they’re a pattern worth trusting.

  • The sender’s address or number doesn’t quite match the organisation
  • Unusual urgency, or a threat of immediate loss
  • A link that opens a login page on an unfamiliar domain
  • A request for a password, PIN, or one-time code
  • An attachment you weren’t expecting
  • A prize, job, or refund that requires payment first
  • Pressure to move the conversation off the official app or line

A Convincing Message Is Not the Same as a Legitimate One

Correct spelling, a real logo, and knowledge of your name prove nothing on their own. Attackers copy designs, pull details from public profiles, and generate polished text. Even a compromised real account can send a fraudulent message — the account is genuine, the request isn’t.

How to Check Without Falling for It

  1. Skip the link or number in the message entirely.
  2. Open the organisation’s official app, or type the website address yourself.
  3. Check whether the alert also shows up inside the official account.
  4. Call a number you already had saved — not one from the message.
  5. Read the domain name character by character. Not the logo. The domain.

If You Clicked, But Didn’t Enter Anything

Close the page. Don’t download whatever it offered. Run a security check on the device, and clear any browser notification permission that popped up uninvited. Then just watch the relevant account for a few days.

If You Entered a Password or Code

Move fast here — speed matters more than anything else in this section.

  1. Change the affected password immediately, from a device you trust.
  2. Change any other account using that same password.
  3. Sign out other sessions and check which devices are connected.
  4. Turn on multifactor authentication or a passkey wherever it’s offered.
  5. If money or payment details were involved, call your bank now — not tomorrow.
  6. Save the message, the sender’s details, and any transaction reference. You’ll want them for the report.

Embarrassment Is Part of the Design

Phishing works partly because people delay reporting it out of embarrassment. That delay is exactly what benefits the attacker. A fast report gives your bank, employer, or platform a real chance to limit the damage — and to warn the next person before the same message reaches them.

Urgency belongs to the attacker. Verification belongs to you. Open the official service yourself, on your own terms, before you enter anything, approve anything, or send anything.

What it means for Nigeria and Africa

Nigeria

Common impersonation themes include banks, mobile operators, delivery services, employers, schools, government agencies and people asking for urgent transfers. The brand may change, but the pressure and credential theft pattern is similar.

Across Africa

Phishing adapts to local payment systems, languages and trusted institutions, so readers should verify the request through an independent official channel.

What Tech Embed adds

A message-by-message checking method and a clear response plan for people who already clicked or shared information.

Disclosure

This evergreen guide was prepared from the official sources listed below. The featured image is an AI-assisted editorial illustration in a realistic photographic style; it does not document a real person, event, product test or location.

Primary sources checked

Tech Embed Editorial

Tech Embed Editorial

Tech Embed Editorial Team

Tech Embed is written and verified by a newsroom process, not a single byline. Every article passes through research and verification, Nigerian and African context review, and editorial sign-off before publication. See our Editorial Team page for how this works.

Share a useful experience

Be specific. Do not post account numbers, phone numbers, passwords, OTPs or other private information.