Business Email Compromise (BEC) remains the single most costly attack pattern hitting Nigerian organisations. In a typical BEC incident, an attacker either compromises a legitimate email account or registers a domain that looks nearly identical to a real vendor or executive address - a single letter swapped, a hyphen added. The email arrives, often on a Friday afternoon, requesting an urgent payment change or salary redirect. Because the request mirrors normal business language and comes from a trusted-looking address, finance teams approve it before the weekend. The Nigerian Financial Intelligence Unit reported a significant rise in BEC-related losses in 2025, with mid-size firms in Lagos and Abuja most frequently targeted.
The second pattern is WhatsApp and Telegram impersonation of senior leaders. Attackers create accounts using a CEO or director's photo and display name, then message employees directly - often targeting executive assistants, finance officers, or IT staff. The message creates urgency: a wire transfer needs to happen now, a phone number needs to be changed on the banking portal, or a confidential project requires the employee to buy gift cards. Because the message appears on a personal device and feels like a direct line to leadership, employees bypass normal approval chains. Training teams to verify any out-of-channel financial instruction by calling the person directly - using a known number, not one provided in the message - breaks this attack every time.
Fake NITDA and FIRS compliance notices are a rising threat specific to the Nigerian regulatory environment. Attackers craft official-looking emails or PDF letters claiming that the recipient's organisation has failed a compliance audit and must submit sensitive data, pay a penalty via a provided link, or install a 'compliance verification tool.' The letter often cites real regulation numbers and copies the visual style of official government communications. When an employee forwards it to the IT or legal team, the damage may already be done - a link clicked, a credential entered. Organisations should establish a single intake process for any regulatory communication, verifying directly with the agency before taking any action.

Vendor and supply chain impersonation is increasingly sophisticated. Rather than impersonating an unknown entity, attackers research a company's actual suppliers - often via LinkedIn, public procurement records, or company websites - and then impersonate those specific vendors. They send invoice updates, request changes to banking details, or ask for access to shared project environments. The intimacy of the impersonation makes it persuasive. A new supplier onboarding checklist that independently verifies bank account details via a confirmed phone number before any payment is made is one of the simplest and most effective controls available.
Social media reconnaissance feeds all of these attacks. Attackers spend time on LinkedIn, Instagram, and company websites to understand org charts, identify who approves payments, learn upcoming projects, and map personal relationships. A simple operational security policy - limiting what employees share publicly about internal projects, travel, and financial processes - reduces the intelligence available to attackers. This is not about restricting employees; it is about being intentional. Sharing a product milestone publicly is fine. Sharing the name of your finance director, her travel schedule, and the bank you use is a different matter.
The common thread across all five patterns is urgency and authority. Every social engineering attack manufactures a reason why normal verification steps must be skipped - the CEO is unreachable, the audit deadline is today, the vendor will cancel the contract if payment is not made now. Building a verification culture means explicitly telling employees that slowing down to verify is always the right call, that leadership will never punish someone for asking a confirming question, and that a brief delay is far less costly than a fraudulent transfer. This culture shift requires more than a policy document - it requires regular training with realistic scenarios that make the decision feel familiar before it happens in real life.

Forvention's threat simulation modules replicate each of these patterns in a controlled environment, letting your team experience the pressure of a realistic BEC request, a WhatsApp impersonation, or a fake compliance notice and practice the correct response. Completion data and scenario outcomes feed directly into your compliance dashboard, giving security leads evidence of readiness and a clear view of which departments and individuals need additional coaching. The goal is not to catch employees - it is to build the muscle memory that makes the right response automatic.
The strongest anti-fraud habit is simple: urgency never overrides verification.


