Session 4: Phishing, Scams & Malware
The three attacks that cause almost all real losses in Nigeria: phishing and impersonation, the scams built on them, and the malware that arrives through both. This session teaches you to recognise each in seconds, respond correctly when you have already clicked, and remove an infection properly.
Learning objectives
By the end of this session you will be able to do each of these without prompting.
- Recognise phishing across email, SMS, WhatsApp and voice
- Identify the specific scams targeting Nigerians and what each asks for
- Explain how malware is delivered and what each family actually does
- Respond correctly in the minutes after a suspected compromise
- Remove malware properly and know when removal is not enough
- Build the habits that make these attacks fail
The taught content
Phishing across every channel
Phishing is a message designed to make you act before you think, and it arrives in every format. Email phishing uses urgency and impersonation — a bank warning, a delivery failure, an invoice. SMS phishing carries a link and a claim that something needs your attention. WhatsApp is where most Nigerian phishing actually happens, because it arrives from a number that looks plausible, often with a familiar name and photograph, and the medium itself signals trust.
The tells are consistent across all of them. Urgency — a deadline of minutes or hours, which exists only to suppress the checking you would normally do. An unexpected request — nobody was expecting this message, and that is precisely why it works. A request for a code, a payment or credentials, which are the only three things an attacker actually wants. A link whose destination differs from its text — hover or long-press to see where it really goes. And subtle sender errors: a domain one character off, a number that is not the organisation's, a display name that does not match the address.
Voice phishing deserves separate mention because it is under-recognised. A caller claiming to be from your bank, your network operator or the police, speaking confidently and creating urgency, is more persuasive than any email. The defence is identical and simple: hang up and call back on a number you obtained independently — from your card, your bill, or the organisation's official site. No legitimate caller has any objection to that.
The scams you will actually meet
SIM-swap fraud begins with an attacker gathering enough about you to convince your network to move your number to their SIM. Once they hold your number, every SMS one-time code goes to them, and account takeovers follow quickly. The defence is a port-out PIN or account PIN on your mobile account — most Nigerian networks offer one and most people have never set it. This is a five-minute action that closes a serious hole.
Fake payment alerts target businesses: a forged transfer notification arrives, apparently genuine, and goods are released before the money is checked. The rule is absolute — verify in your own banking app, never from a screenshot or an SMS, because both are trivially forged. One-time-code requests arrive posing as a bank, a network or a delivery firm; no legitimate organisation ever asks for a code, so treat any such request as an attack without analysis.
Impersonation of someone you know is the most effective, because it defeats suspicion entirely — a WhatsApp message from 'your sister' with her photograph asking for urgent help, or 'your boss' asking for a favour. The defence is verification through a second channel: call the person on the number you already have. And romance and investment scams run long, building trust over weeks before asking for money; the marker is not the story but that money is eventually requested, always urgently, always to an unfamiliar account.
Malware: how it arrives and what it does
In Nigeria, malware most often arrives through pirated software — a cracked activation tool, a 'free' licensed program, a modified installer. This is the dominant route and it is worth being blunt about with clients: the activation crack that saves a licence fee routinely carries a payload that costs far more. Attachments and downloaded files are the second route, and malicious browser extensions the third.
The families matter because the response differs. Ransomware encrypts your files and demands payment — the only real defence is a backup, because paying does not guarantee recovery and marks you as someone who pays. Infostealers silently harvest saved browser passwords, cookies and wallet keys, which is why a session token can be stolen without any password being guessed. Spyware and keyloggers record what you type. Banking trojans intercept and modify transactions. And cryptominers simply consume your machine, making it slow and hot — which is often how they are noticed.
The signs of infection are worth memorising: unexplained slowness, a fan running constantly at idle, browser redirects or a changed homepage, new toolbars or extensions you did not install, pop-ups, passwords that stop working, and contacts reporting strange messages from your accounts. Any of these is a reason to stop using the machine for anything sensitive until it is checked.
The first hour after a suspected compromise
The response in the first hour determines how bad the outcome is, and it has a fixed order. Disconnect — take the machine off the network, or if it is an account, stop using it. This limits what an active attacker can do. From a different, clean device, change the password on the affected account and on your primary email, because email resets everything else. Enable or reset two-factor, since an attacker may have added their own.
Then revoke active sessions — most email and social services list logged-in devices and let you sign all of them out, which defeats an attacker holding a stolen session token even after a password change. Check the recovery details, because changing the recovery email or phone number is one of the first things an attacker does and it locks you out later. Notify the bank immediately if money is involved, and report to the platform.
In Nigeria, report fraud to the relevant platform and to the police, and consider the EFCC for financial fraud. Reporting rarely recovers money on its own, but it creates a record, which matters for any bank claim, and it contributes to the data that makes these operations harder. Finally, tell the people who might be affected — if your social account was used to message your contacts, they need to know to ignore it.
Removing malware, honestly assessed
Run a full scan with Windows Defender and a reputable second-opinion scanner, in Safe Mode where possible so active malware is not running to defend itself. Remove what is found, then check the places persistence hides: startup entries, scheduled tasks, browser extensions, and recently installed programs sorted by date.
But be honest about what cleaning achieves, because this is where technicians overclaim. Scanners remove what they detect; they cannot guarantee that everything is gone, and infostealers have already sent your credentials the moment they ran — removing the malware afterwards does not un-send them. So the correct sequence after any real infection is: remove it, then change every password stored in that browser and revoke sessions, because you must assume they were taken.
For a serious infection, and always for a machine used for banking or business, the honest recommendation is a clean reinstall — which session seven of Computer Repairs covers in full. A cleaned machine is probably fine; a reinstalled machine is known to be fine. Recover the data first, verify the copy, then install clean. Where the customer handles money, 'probably' is not an acceptable standard, and saying so is the responsible advice even though it is more work.
Instructor demonstration
The instructor examines real phishing messages across four channels, walks through the specific Nigerian scams, shows how malware arrives, then runs a full incident response on a simulated compromise and a proper malware removal.
- 01
Examine an email phish
Show a bank impersonation email and identify the urgency, the mismatched sender domain and the link destination. Hover to reveal where the link actually goes.
- 02
Examine an SMS phish
Show a delivery-failure message with a link. Explain that the claim of an expected parcel is what makes it persuasive, and that the domain gives it away.
- 03
Examine a WhatsApp impersonation
Show a message from a familiar name and photograph with a different number. Explain that the medium signals trust, which is why this is the most effective channel in Nigeria.
- 04
Demonstrate voice phishing defence
Role-play a confident caller claiming to be a bank. Then hang up and call the number on the card, explaining that no legitimate caller objects to that.
- 05
Walk the SIM-swap attack
Explain how an attacker moves your number and then receives every SMS code. Then set a port-out PIN on a mobile account and explain that most people have never done this.
- 06
Examine a fake payment alert
Show a forged transfer notification and verify it in the bank app, where it does not exist. Explain that screenshots and SMS are trivially forged and never evidence of payment.
- 07
Show how malware arrives
Examine a pirated-software installer and explain that the activation crack is the delivery mechanism. Be blunt that this is the dominant route in Nigeria.
- 08
Identify infection signs
List the symptoms on a live machine: unexplained slowness, a fan at idle, a changed homepage, an unknown extension. Explain that any one of these justifies stopping sensitive use.
- 09
Run the first-hour response
Disconnect, change the password and the primary email password from a clean device, reset two-factor, and revoke all active sessions. Explain why session revocation is essential.
- 10
Audit the recovery details
Check the recovery email and phone on the affected account and explain that attackers change these early, which locks the real owner out later.
- 11
Scan and remove malware
Boot to Safe Mode, run a full scan with two tools, then check startup entries, scheduled tasks and extensions where persistence hides.
- 12
Make the honest recommendation
Explain that infostealers have already transmitted any credentials, so every stored password must change, and that a banking machine should be reinstalled rather than cleaned.
Guided practice
Recognise, respond, and recover
You analyse real phishing attempts across four channels, set a port-out PIN on your mobile account, then run a complete incident response on a simulated compromise and a full malware removal — including the credential changes and session revocations that follow.
- 01Collect four real phishing messages: one email, one SMS, one WhatsApp, one voice attempt described.
- 02For each, identify the channel, the urgency mechanism and the specific tell that gives it away.
- 03For each, state the ask — a code, a payment or credentials.
- 04Write the three-ask rule as a single line you could teach a relative.
- 05Describe the SIM-swap attack and what it enables once your number is moved.
- 06Set a port-out or account PIN on your mobile account and confirm it is active.
- 07Describe the fake-payment-alert scam and the verification rule that defeats it.
- 08Write the first-hour response sequence in order, from disconnection onward.
- 09Practise revoking active sessions on your email and social accounts and note where the option lives.
- 10Audit the recovery email and phone number on your primary email and correct anything stale.
- 11Boot a test machine to Safe Mode and run a full scan with two tools.
- 12Check startup entries, scheduled tasks, browser extensions and recently installed programs.
- 13List every password stored in that machine's browser and change them all.
- 14State in writing when you would recommend a clean reinstall instead of a cleanup, and why.
The standard we hold you to
Four real attempts analysed by channel, urgency mechanism, tell and ask; a port-out PIN confirmed active; the first-hour response sequence written in correct order including session revocation and recovery-detail audit; a Safe Mode scan completed with persistence locations checked; and a written statement of when reinstall beats cleanup.
Common mistakes and how to fix them
You judged a message by its appearance
Fix: Judge it by the ask. Any message requesting a code, a payment or credentials is an attack however genuine it looks, because no legitimate organisation asks for those by message.
You clicked the link to see where it went
Fix: Hover or long-press to preview the destination without visiting it. Visiting can be enough to confirm your number is live or, in some cases, to begin an attack.
You trusted a payment screenshot or SMS
Fix: Verify in your own banking app, always. Both are trivially forged, and releasing goods against a fake alert is one of the most common losses Nigerian businesses suffer.
You never set a port-out PIN on your mobile account
Fix: Set it today. SIM-swap fraud defeats every SMS one-time code you have, and this five-minute action closes the hole. Most people have never done it.
You changed the password but did not revoke sessions
Fix: An attacker holding a session token keeps access after a password change. Sign out all active sessions from a clean device — it is the step most people miss.
You cleaned the malware and considered it resolved
Fix: An infostealer already transmitted whatever it harvested. Change every password stored in that browser and revoke sessions, because you must assume they were taken.
You installed software from a pirated source
Fix: The activation crack is the dominant malware route in Nigeria. The licence fee it saves is far smaller than what the payload costs, and telling clients this plainly is part of the service.
Expert notes
The habits that separate someone who can do this from someone who does it well.
- Judge every unsolicited message by what it asks for, not by how it looks. The three asks — a code, a payment, credentials — are the whole game, and this rule requires no technical knowledge to apply under pressure.
- Set a port-out PIN on your mobile account and on every client's and relative's you can reach. It is the highest-value five-minute action available against SIM-swap fraud, and almost nobody has done it.
- Revoke active sessions after any password change, from a clean device. It is the step most people omit, and without it an attacker holding a stolen session keeps working regardless of your new password.
- Assume credentials were taken after any real infection, and change everything stored in that browser. Cleaning the machine does not un-send what an infostealer already transmitted, and pretending otherwise is how a technician gets called back.
Key terms
- Phishing
- A message engineered to prompt action before thought. Judged by what it asks for, not how it looks.
- SIM-swap
- Fraud moving your number to an attacker's SIM, capturing every SMS code. Defeated by a port-out PIN.
- Port-out PIN
- A PIN on your mobile account required before your number can be moved. The key control against SIM-swap.
- Fake payment alert
- A forged transfer notification. Verified only in your own banking app, never from a screenshot or SMS.
- Ransomware
- Malware encrypting files for payment. Backups are the only reliable defence; paying does not guarantee recovery.
- Infostealer
- Malware harvesting saved passwords and cookies. Removal does not un-send what it already transmitted.
- Session revocation
- Signing out all logged-in devices. Essential after a password change, because a stolen token survives it.
- Persistence
- Where malware survives a restart: startup entries, scheduled tasks, extensions. Checked during removal.
Homework before the next session
Set a port-out PIN today
On your own mobile account, then help two family members set theirs. It is the single highest-value action in this session and it takes five minutes each.
Collect and analyse four real attempts
One each from email, SMS, WhatsApp and voice. Identify the urgency mechanism, the tell and the ask for each.
Write the first-hour response card
Disconnect, change passwords from a clean device, reset two-factor, revoke sessions, audit recovery details, notify the bank, report. Keep it where you can reach it fast.
Teach the three-ask rule
Explain to one non-technical person that any message asking for a code, a payment or credentials is an attack. If they cannot repeat it, simplify it.
Assessment rubric
How this session is marked. The certificate for Cybersecurity is awarded on the deliverable, not on attendance.
| Criterion | Passing | Excellent |
|---|---|---|
| Recognition | Is suspicious of odd messages. | Identifies urgency, the mismatched sender and the link destination across all four channels, and judges by the ask rather than the appearance. |
| Scam knowledge | Knows scams exist. | Explains SIM-swap, fake payment alerts, code requests and impersonation, with the specific control that defeats each. |
| Preventive action | Is generally careful. | Port-out PIN set and confirmed, verification-in-app as an absolute rule, and no software from pirated sources. |
| Incident response | Would change a password. | Follows the full first-hour sequence in order from a clean device, including session revocation and a recovery-detail audit. |
| Malware handling | Runs a scan. | Scans in Safe Mode, checks persistence locations, changes every stored password, and states clearly when a reinstall is the correct answer. |
Session questions
I clicked a phishing link but entered nothing. Am I compromised?+
Usually not, if you entered no credentials and downloaded nothing. Change any password you may have used there as a precaution, run a scan, and check your accounts for unusual activity. The real risk begins when you enter something or download a file.
How do I stop SIM-swap fraud?+
Set a port-out or account PIN with your network today, limit how much personal detail you publish, and prefer authenticator apps over SMS codes for important accounts. If your phone suddenly loses signal unexpectedly, treat it as a possible swap and act immediately.
Someone sent me a payment screenshot but my app shows nothing. What do I do?+
Do not release anything. Verify only in your own banking app — screenshots and SMS alerts are trivially forged and are the basis of one of the most common frauds against Nigerian businesses. If it is not in your app, you have not been paid.
My machine has malware. Is a scan enough?+
A scan removes what it detects but cannot guarantee the machine is clean, and any infostealer has already transmitted what it harvested. Change every stored password, revoke sessions, and for a machine used for banking or business, do a clean reinstall rather than a cleanup.
Should I pay a ransomware demand?+
Generally no. Payment does not guarantee recovery, it funds the operation, and it marks you as someone who pays. Restore from your backup — which is why backups are the first control in this entire course. If there is no backup, seek specialist advice before deciding.
This session is part of
Cybersecurity
4 weeks · 8 sessions · ₦50,000 · you leave with a security assessment report