Skip to main content

Cybersecurity

Phishing Attacks on Nigerian Businesses: ngCERT Issues Warning

This page is editorial news. It is not treated as rewarded content unless backend metadata explicitly confirms otherwise.

Nigerian organisations are being warned about a continuing wave of phishing, business email compromise and social-engineering attacks that can trick employees into transferring money, changing payment information or revealing sensitive business credentials.

The Nigeria Computer Emergency Response Team, ngCERT, issued a high-risk advisory on August 27, 2026, warning government institutions and critical organisations about attackers using trusted identities, compromised accounts and legitimate business processes to make fraudulent requests appear genuine.

The warning highlights a growing cybersecurity problem for businesses that depend heavily on email, online banking, cloud services and digital communication.

Rather than breaking into a system through a sophisticated technical vulnerability, attackers can sometimes gain access by persuading an employee to trust a message, website, phone call or request that appears legitimate.

How the attacks work

Business email compromise, commonly known as BEC, involves attempts to manipulate an organisation’s communication or payment processes.

An attacker may impersonate a senior executive, supplier, employee or business partner and request an urgent payment.

Another tactic is to compromise a legitimate email account and use it to communicate with colleagues or customers. Because the message appears to come from a genuine account, recipients may be less likely to question it.

According to ngCERT, these attacks can also involve phishing, impersonation, fraudulent websites, credential harvesting, smishing and vishing. The advisory says threat actors are increasingly using AI-assisted impersonation as part of their social-engineering activity.

The objective can range from stealing login credentials to redirecting business payments or obtaining sensitive information.

Why phishing remains a major threat

Phishing works by exploiting human trust.

An email does not necessarily need to contain sophisticated malware to cause damage. A convincing message that leads an employee to a fake login page can be enough to expose a password.

The same principle can apply to payment instructions.

For example, an attacker impersonating a supplier could claim that the company’s bank account has changed and ask an accounts employee to use new payment details.

If the employee acts without independently confirming the request, money could be sent to an account controlled by the attacker.

ngCERT specifically warned that attackers can exploit legitimate business processes to deceive personnel into transferring funds, altering payment details, disclosing sensitive information or taking unauthorised actions.

Nigeria has seen repeated cybersecurity warnings

The latest alert is part of a wider series of cybersecurity warnings affecting Nigerian organisations.

In April, ngCERT warned of a significant rise in high-impact cyber incidents affecting organisations across several sectors in Nigeria. The agency identified phishing, ransomware, business email compromise and data breaches among the threats being observed.

The April advisory also said cybercrime-as-a-service models and AI-driven techniques were helping attackers scale their operations.

That means businesses do not necessarily have to be individually selected by a highly specialised attacker.

Criminal groups can increasingly obtain ready-made tools and services that lower the technical barrier for conducting phishing and credential-theft campaigns.

A phishing campaign can begin with a simple message

A phishing attack may begin with an email claiming to contain an invoice, account notification, password warning, delivery update or other routine business document.

The message may contain a link directing the recipient to a fake website.

The website can be designed to look similar to a legitimate banking, cloud-storage, email or business service login page.

Once the victim enters their credentials, the attacker can attempt to use the information to access the account.

Some campaigns also use additional authentication tricks to bypass traditional security controls.

ngCERT previously warned in June about the Tycoon2FA phishing campaign targeting Microsoft 365 accounts. The advisory said attackers were abusing the OAuth 2.0 device-authorisation process to persuade users to enter device codes, potentially allowing attackers to obtain persistent access to email, files and other sensitive resources.

Attackers are also moving beyond email

Phishing is no longer limited to conventional email messages.

The August ngCERT advisory says social-engineering attacks can extend to smishing, which uses text messages, and vishing, which uses voice communication.

Fraudulent websites and AI-assisted impersonation are also becoming part of the threat.

This makes traditional advice such as “do not open suspicious emails” less sufficient on its own.

A message can look professional and still be fraudulent.

An attacker may also have information about an organisation, its employees or its suppliers before contacting a target.

Recent warning about malicious messages

The Nigeria Data Protection Commission issued another warning on September 18, 2026, concerning malicious electronic messages falsely claiming that recipients had violated traffic rules or committed related offences.

According to the commission, the messages were designed to create fear and urgency and encourage recipients to click links, disclose personal information or follow harmful instructions. The commission advised people to independently verify suspicious messages and carefully examine sender addresses, domain names and links before clicking.

Although the NDPC warning was directed at the public rather than specifically at businesses, the same social-engineering techniques can affect employees using corporate email accounts and devices.

What Nigerian businesses should do

Businesses can reduce their exposure by making verification part of normal financial and administrative procedures.

Employees responsible for payments should independently confirm unexpected changes to supplier bank details.

A request from a senior executive should also be verified through a separate communication channel when it involves an unusual transfer, confidential information or a change to payment instructions.

Organisations should also consider stronger authentication for important accounts.

ngCERT has repeatedly recommended measures such as multi-factor authentication, stronger identity and access controls, monitoring and employee awareness as part of the response to credential-based attacks.

For organisations using Microsoft 365 or similar cloud services, administrators should pay particular attention to unusual login activity, new authentication methods and unexpected changes to account settings.

Employees remain an important line of defence

Technology can detect many malicious messages, but employees remain an important part of an organisation’s security system.

Regular cybersecurity training can help staff recognise suspicious requests before they result in financial loss or account compromise.

Training should cover more than obvious spelling mistakes or strange-looking emails.

Employees should learn to question unexpected urgency, requests for secrecy, changes to payment details, unusual login prompts and requests for authentication codes.

They should also know how to report suspicious messages without fear of punishment for raising a genuine concern.

Businesses should prepare for compromised accounts

Prevention is only one part of cybersecurity.

Organisations should also have a response plan for situations where an employee’s credentials have already been stolen.

The plan should identify who is responsible for disabling compromised accounts, resetting credentials, reviewing recent activity, contacting financial institutions and preserving relevant evidence.

Early reporting can also help authorities understand whether several incidents are connected.

Nigeria’s National Cybersecurity Coordination Centre says ngCERT receives reports of cyber incidents affecting Nigerian organisations and individuals, coordinates technical responses and publishes national advisories on active threats and vulnerabilities.

The financial risk can be significant

For a small business, a single successful phishing attack can have consequences beyond the loss of a password.

A compromised email account can potentially expose invoices, customer information, contracts and internal communications.

If attackers gain control of an account used for financial transactions, the consequences can include fraudulent payments or disruption to normal business operations.

For larger organisations, a compromised account can potentially provide attackers with a starting point for further intrusion.

This is why business email compromise should be treated as an operational and financial risk, not simply an IT problem.

Cybersecurity is becoming a business responsibility

The latest Nigerian warnings show how cybersecurity threats increasingly overlap with ordinary business activities.

Attackers do not always need to discover a new software vulnerability. They can exploit familiar processes such as email communication, supplier payments, employee logins and customer notifications.

For Nigerian businesses, protecting against phishing therefore requires a combination of technology, staff awareness, financial controls and clear procedures for verifying unusual requests.

The immediate lesson from the latest ngCERT and NDPC warnings is straightforward: a message that creates urgency should not automatically create action.

Businesses should verify unexpected requests independently, protect important accounts with stronger authentication and report suspected incidents quickly.

As Nigerian organisations become more dependent on digital payments, cloud services and online communication, the ability to recognise and respond to social-engineering attacks will remain an important part of business security.

Community

Comments

Keep discussion respectful and relevant. Comments never affect rewards.

No comments yet. Start a respectful conversation.

Join the conversation

Your email address will not be published. Required fields are marked.

More updates

Related news

International Affairs Mountain

UK and US Launch AI Defence Partnership

The UK and United States have launched a new partnership on artificial intelligence and autonomous technologies for defence and critical infrastructure.

Global Economy Mountain

Global Investors Remain Exposed to US-China AI Competition

Investors remain financially exposed to both US and Chinese AI ecosystems as technology restrictions and geopolitical competition reshape global investment.

International Politics Mountain

Trump Uses UN Speech to Outline US Foreign-Policy Priorities

US President Donald Trump used his 2026 UN General Assembly address to defend his foreign-policy approach and outline positions on Iran, Ukraine, artificial intelligence, UN reform…