Cyber Threat of the Week is a weekly cybersecurity awareness series designed to highlight a current or emerging cyber threat and explain how individuals and businesses can protect themselves.
This week’s threat is AI-powered phishing and credential theft—a growing problem that combines traditional social engineering with increasingly convincing artificial intelligence-generated messages, websites and impersonation attempts.
For Nigerian internet users and businesses, this threat deserves particular attention. Nigeria’s national computer emergency response team, ngCERT, warned in April 2026 that organisations were facing phishing campaigns, credential harvesting, ransomware deployment and attacks exploiting unpatched systems.
Recent reporting also indicates that Nigeria experienced approximately 1.6 million online cyberattack attempts during the first half of 2026, according to data attributed to Kaspersky.
What Is AI-Powered Phishing?
Phishing is a form of cyberattack in which criminals impersonate a trusted person, company or service to trick victims into revealing information or performing an action.
Traditional phishing messages often contain obvious warning signs such as:
- Poor grammar
- Strange formatting
- Suspicious links
- Unrealistic promises
- Generic greetings
Artificial intelligence is making some phishing campaigns much more convincing.
Attackers can use AI to help create:
- Professional-looking emails
- Convincing WhatsApp messages
- Fake customer-service conversations
- Fake login pages
- Personalized scam messages
- Impersonation scripts
- Messages in local languages
- Social-media content designed to build trust
This means poor grammar is no longer a reliable way to identify a scam.
How the Attack Works
A typical credential-theft campaign may follow a simple sequence.
Step 1: The attacker creates a convincing message
You may receive an SMS, email, WhatsApp message or social-media message claiming to come from:
- Your bank
- Your employer
- A delivery company
- A telecommunications provider
- A government agency
- A social-media platform
- A colleague
- A friend
- A business partner
Step 2: The message creates urgency
The attacker may claim:
“Your account will be suspended today.”
Or:
“Your payment has failed. Confirm your details immediately.”
The goal is to make you react before thinking.
Step 3: You are directed to a fake website
The link may lead to a website that looks almost identical to the legitimate service.
You may be asked to enter:
- Username
- Password
- Email address
- Card information
- PIN
- One-time password
- Security questions
Step 4: The attacker captures the information
Once submitted, your credentials may be sent directly to the criminal.
The attacker can then attempt to access your account or use the information in further attacks.
Why This Threat Is Dangerous
Credential theft can be the beginning of a much larger attack.
A stolen password could potentially give an attacker access to:
- Social-media accounts
- Cloud storage
- Business systems
- Online shopping accounts
- Financial services
- Corporate applications
If the same password is reused across multiple services, compromising one account can make other accounts vulnerable.
Deloitte’s Nigeria Cybersecurity Outlook 2026 identifies AI-powered scams, ransomware and identity fraud among the evolving risks accompanying Nigeria’s rapidly expanding digital economy.
The WhatsApp Problem
WhatsApp and other messaging platforms can be particularly attractive to scammers because people naturally trust messages from familiar contacts.
Imagine receiving:
“Good afternoon. Please send me the OTP you just received. It’s for the transaction.”
The message appears to come from someone you know.
But their account may have been compromised.
Never share an OTP
Banks, legitimate companies and reputable service providers should not require you to send your authentication code to another person through WhatsApp.
Your OTP is private.
Treat it like a password.
Watch Out for Fake Bank Messages
Financial institutions are common targets for impersonation scams.
A message may claim:
- Your account needs verification.
- Your ATM card is expiring.
- Your account has been blocked.
- You have received a transfer.
- Your BVN needs updating.
- Your NIN information needs confirmation.
- Your account will be suspended.
- You need to activate a new security feature.
Instead of clicking the link, open your bank’s official application or manually enter its official website address.
Never use a link supplied by an unexpected message to access your financial account.
Warning Signs of a Phishing Message
Even sophisticated phishing attacks can leave clues.
Look for:
1. Unexpected requests
Were you suddenly asked to provide sensitive information?
Stop and verify.
2. Urgency
Messages demanding immediate action should receive extra scrutiny.
3. Suspicious links
Hover over links on a computer before clicking them.
On a phone, don’t automatically trust a link simply because the message looks professional.
4. Requests for passwords or OTPs
Treat these as major warning signs.
5. Unusual payment instructions
If someone suddenly asks you to transfer money to a different account, verify the request using another communication channel.
6. Unexpected attachments
Don’t open suspicious documents or executable files simply because they appear to come from someone you know.
AI Makes Impersonation Harder to Detect
One of the biggest challenges in 2026 is that criminals can use AI to improve the quality and scale of social engineering.
A scammer doesn’t necessarily need perfect writing skills anymore.
AI tools can help criminals produce convincing messages and adapt them to different audiences.
This makes the traditional advice of “look for spelling mistakes” less effective.
Instead, focus on behaviour and verification.
Ask:
Was I expecting this message?
Is the sender really who they claim to be?
Why are they asking for this information?
Can I independently verify the request?
How to Protect Yourself
1. Enable Multi-Factor Authentication
MFA adds another layer of protection beyond your password.
Where possible, use an authenticator app or phishing-resistant authentication method rather than relying exclusively on SMS codes.
CISA recommends multi-factor authentication as an important defense against account compromise and phishing-related attacks.
2. Use Unique Passwords
Don’t use the same password for:
- Gmail
- Banking
- Work accounts
If one password is stolen, attackers can try it elsewhere.
A password manager can help you generate and store unique passwords.
3. Don’t Click Under Pressure
One of the simplest cybersecurity rules is:
Stop. Think. Verify.
If a message says you must act within five minutes, don’t let the deadline make the decision for you.
Take a moment to verify the request independently.
4. Verify Through a Different Channel
If your boss sends you a WhatsApp message requesting an urgent payment, call them directly.
If a friend asks for money through a new bank account, call them.
If a company sends you a suspicious link, visit its official website manually.
Don’t verify a suspicious request using the same channel that delivered it.
5. Keep Your Devices Updated
Install security updates for:
- Windows
- Android
- iOS
- macOS
- Browsers
- Applications
- Routers
- Antivirus software
ngCERT has specifically warned Nigerian organisations about attackers exploiting unpatched systems.
6. Back Up Important Data
Phishing can sometimes lead to ransomware or wider account compromise.
Maintain backups of important files, preferably with at least one copy isolated from your normal network.
CISA recommends maintaining backups and testing restoration procedures as part of ransomware preparedness.
What Businesses Should Do
Businesses should not rely entirely on employees to identify every phishing attempt.
Organisations should consider implementing:
- Multi-factor authentication
- Email filtering
- Endpoint protection
- Regular security updates
- Security awareness training
- Password managers
- Network monitoring
- Regular backups
- Access controls
- Incident-response procedures
Employees should also know exactly where to report suspicious emails and messages.
A successful phishing attack against one employee can potentially become a business-wide security incident.
What If You Already Clicked the Link?
Don’t panic.
If you clicked a suspicious link but did not enter any information, close the page and run a security check.
If you entered a password:
- Change the password immediately.
- Change it anywhere else you reused it.
- Enable MFA.
- Review recent account activity.
- Sign out of suspicious sessions where possible.
- Notify your IT/security team if it is a work account.
If financial information was submitted, contact the relevant financial institution through its official channel immediately.
If you downloaded or installed suspicious software, disconnect the affected device from the network and seek technical/security assistance.
Cyber Threat of the Week: Quick Safety Checklist
Before responding to an unexpected message, remember:
- STOP — Don’t act immediately.
- CHECK — Examine the sender and request.
- VERIFY — Contact the person or organisation independently.
- DON’T SHARE — Never give away passwords, PINs or OTPs.
- DON’T CLICK — Avoid suspicious links and attachments.
- ENABLE MFA — Add another layer of account protection.
- UPDATE — Keep your software patched.
- BACK UP — Protect important data.
The Bottom Line
Cybercriminals don’t always need sophisticated malware to compromise a victim. Sometimes, convincing the victim to hand over the keys is enough.
AI is making phishing and impersonation campaigns more convincing, while Nigeria’s rapidly expanding digital economy continues to attract cybercriminal activity. Recent threat reporting has highlighted phishing, credential theft, ransomware and AI-assisted attacks as significant concerns.
The best defense is not simply having antivirus software installed.
It is developing a habit of verification.
Whenever a message asks you to click a link, provide sensitive information, transfer money or urgently change an account setting, stop and verify it through an independent channel.
Remember:
Think before you click. Verify before you trust. Protect before you regret.
Cybersecurity Tip of the Week
No legitimate urgency is more important than your security.
If a message pressures you to act immediately, slow down. Taking 60 seconds to verify a request could prevent hours, days or even weeks of dealing with a compromised account.