Saturday, October 10 Lagos newsroom Newsroom online
Edition: Africa

Cybersecurity in Nigeria: A Practical Online Safety Guide

A practical guide to phishing, account security, passwords, impersonation scams, device safety and safer online decisions.

Updated October 3, 2026 · 3 min read

Cybersecurity is the protection of accounts, devices, information and services from unauthorised access, manipulation, disruption or theft. Most people do not need complicated equipment to become safer. They need repeatable habits that reduce common risks.

The most common risks

  • Phishing links and false login pages.
  • Reused or weak passwords.
  • Fake customer-care and company accounts.
  • Stolen devices and unprotected sessions.
  • Malicious downloads and remote-access requests.
  • Payment and employment impersonation scams.

Protect important accounts first

Begin with email, banking, messaging, cloud storage and social accounts. Use unique passwords or passkeys, turn on multifactor authentication and keep account-recovery information current.

How to recognise phishing

Phishing creates urgency and directs the target toward a link, attachment, call or payment. Verify the request through an official application, saved number or website that the message did not provide.

Safer phone and computer habits

Install updates, use screen locks, back up important information and remove applications that are no longer needed. Do not give an unknown caller remote control of a device.

What to do after a suspected compromise

  1. Use a trusted device to change the affected password.
  2. Sign out other sessions.
  3. Contact the financial institution when money is involved.
  4. Preserve messages, addresses, transaction details and complaint references.
  5. Warn affected contacts through a separate channel.

Explore Tech Embed’s security guides

Use these guides for common account, device and fraud risks affecting Nigerian users.

Your security priority order

Protect the email account used for password resets first, then banking and payment accounts, messaging apps, cloud storage and social accounts. A compromise of the recovery email can make otherwise strong passwords on other services much less useful.

Build security around account recovery

Security is not only about preventing the first login attempt. Check what happens when a password is forgotten, a SIM is replaced, a phone is stolen or an employee leaves. Protect the email address and phone number used for recovery, keep backup codes away from the device they protect, and review active sessions after any suspicious event.

Respond in the right order

When an incident is active, contain access first: secure the recovery email, block a compromised SIM or device where appropriate, contact affected financial institutions through verified channels, change exposed credentials and preserve evidence. Investigation and cleanup come after the attacker’s easiest routes back into the account have been closed.

Frequently asked questions

Is a verified-looking account always genuine?

No. Compare the exact username and find the account through the organisation’s official website.

Are long passwords enough?

Length helps, but every important account should have a unique password and stronger authentication.

Should I feel embarrassed after a scam?

No. Fast reporting can reduce damage and protect other people.