How Nigerian Businesses Can Protect Against Phishing and Account Takeovers
Cyberattacks do not always begin with sophisticated malware or complicated technical exploits. For many businesses, an attack can start with something much simpler: a convincing email, WhatsApp message, fake login page, or request for sensitive information.
Phishing can trick employees into giving away passwords or authentication codes. Once an attacker obtains those credentials, they may take control of an email account, social-media account, business application, or other system.
For Nigerian businesses, reducing these risks requires more than installing antivirus software. Businesses need practical security controls, employee awareness, strong authentication, and clear procedures for handling suspicious messages and account compromises.
Why Phishing Is a Serious Business Risk
Phishing is a form of social engineering in which an attacker attempts to deceive someone into revealing information, clicking a malicious link, opening a harmful attachment, or performing an action that benefits the attacker.
The message may appear to come from:
- A manager or business owner
- A bank or financial service
- A supplier or customer
- A technology provider
- A government organisation
- A colleague
- A familiar social-media or cloud service
Attackers can also use information about a business, its employees, customers, and suppliers to make fraudulent messages appear more believable.
Nigeria's national Computer Emergency Response Team, ngCERT, has warned organisations about phishing, business email compromise, stolen credentials, ransomware, and other cyber threats targeting organisations in the country.
What Is Business Email Compromise?
Business Email Compromise (BEC) occurs when attackers use compromised or fraudulent email accounts to deceive employees into transferring money, changing payment details, sharing sensitive information, or carrying out another unauthorised action.
A common example is an attacker compromising an employee's email account and then sending a message that appears to come from a director or finance manager.
The message might say:
“Please process this payment urgently.”
Or:
“Our bank account has changed. Use the new account for today's payment.”
The request may look genuine because the attacker has information from previous conversations.
A Simple Verification Rule
Businesses should avoid approving sensitive financial or account changes based only on email instructions.
For example, before changing a supplier's bank details, an employee could independently contact the supplier using a trusted phone number or previously verified communication channel.
This adds a second verification step that can help prevent a fraudulent request from becoming a financial loss.
How Account Takeovers Happen
An account takeover occurs when someone gains unauthorised control of an online account.
This can happen after:
- A password is stolen through phishing
- The same password is reused on multiple services
- Malware captures credentials
- An attacker obtains a session or authentication token
- An employee shares a verification code
- An account has weak security settings
The consequences can be serious.
An attacker who gains access to a business email account may use it to impersonate employees, reset other passwords, target customers or suppliers, access confidential information, or launch further attacks.
How Nigerian Businesses Can Reduce the Risk
1. Use Strong, Unique Passwords
Business accounts should not rely on simple or reused passwords.
Each important account should have a strong, unique password. Password managers can help employees create and store unique credentials without having to remember every password.
A compromised password should not automatically provide access to multiple systems.
2. Enable Multi-Factor Authentication
Multi-factor authentication (MFA) adds another verification factor beyond the password.
Depending on the service, this might involve an authenticator application, security key, or another approved authentication method.
MFA can reduce the impact of password theft because knowing the password alone may not be enough to access the account. NIST recommends stronger, phishing-resistant authentication methods where appropriate.
3. Train Employees to Recognise Suspicious Messages
Technology cannot solve every phishing problem by itself.
Employees should know how to recognise warning signs such as:
- Unexpected urgency
- Requests for passwords or verification codes
- Suspicious links
- Unexpected attachments
- Slightly altered sender addresses
- Requests to change payment information
- Messages that do not match normal business procedures
Training should use realistic examples relevant to the business rather than relying only on theoretical explanations.
4. Verify Unusual Financial Requests
A request involving money should receive additional verification.
For example:
Email request → independent phone verification → payment
is safer than:
Email request → immediate payment
The same principle can apply to changes involving supplier accounts, payroll details, passwords, administrator access, or sensitive customer information.
5. Protect Administrator Accounts
Administrator accounts have greater privileges and therefore require stronger protection.
Businesses should limit administrative access to people who actually need it and avoid using administrator accounts for ordinary daily activities where possible.
Inactive accounts and former employees' access should also be removed promptly.
6. Keep Software and Devices Updated
Security updates often address vulnerabilities that attackers may otherwise exploit.
Businesses should keep operating systems, browsers, applications, plugins, routers, and other internet-connected technology updated according to the vendor's security guidance.
Updates alone will not prevent phishing, but outdated software can create additional opportunities for attackers.
7. Back Up Important Business Information
Businesses should maintain reliable backups of important data and make sure backups cannot easily be destroyed by the same attack that affects the primary systems.
Backups are particularly important for recovering from ransomware, accidental deletion, hardware failures, and other incidents.
A backup strategy should also include periodic testing to make sure data can actually be restored.
8. Create a Simple Incident-Response Procedure
Employees should know what to do when something suspicious happens.
For example, if an employee enters a password into a fake login page, the response should not be:
“Let's wait and see what happens.”
A better process may include:
- Report the incident immediately.
- Change the affected password from a trusted device.
- Revoke active sessions where the service allows it.
- Review MFA and account-recovery settings.
- Check for suspicious account activity.
- Escalate the incident to the person responsible for security.
The faster a compromised account is identified and secured, the more opportunity the business has to limit further damage.
Businesses Should Pay Attention to WhatsApp and Other Messaging Channels Too
Phishing is not limited to email.
Attackers may use WhatsApp, SMS, social media, messaging platforms, or phone calls to impersonate employees, customers, suppliers, or service providers.
For Nigerian businesses, this matters because many organisations use messaging applications as part of everyday communication.
Employees should therefore verify unusual requests regardless of which platform they arrive through.
A message being received through WhatsApp does not automatically make it trustworthy.
What Should Businesses Do If an Account Is Hacked?
If a business suspects that an account has been compromised, act quickly.
Start by securing the account and changing the password from a trusted device. Enable or reset MFA where necessary, sign out other sessions if the platform supports that option, and review recent activity.
Businesses should also check whether the attacker changed:
- Recovery email addresses
- Phone numbers
- MFA settings
- Forwarding rules
- Administrator permissions
- Payment information
- Connected applications
For a business email account, suspicious forwarding rules are particularly important because attackers may use them to secretly receive future messages.
Where financial fraud or significant data exposure is suspected, the business should preserve relevant evidence and consider appropriate professional and legal assistance.
A Practical Phishing Protection Checklist
A small business can start with a simple checklist:
- Use unique passwords for important accounts.
- Enable MFA.
- Train staff to recognise phishing.
- Verify unusual payment requests independently.
- Keep software and devices updated.
- Limit administrator access.
- Remove access for former employees.
- Maintain tested backups.
- Have a clear incident-reporting procedure.
- Review important accounts regularly.
These measures are not a guarantee that an organisation will never experience a cyberattack, but they can reduce common opportunities for attackers and improve the organisation's ability to respond.
Cybersecurity Is a Business Responsibility
Cybersecurity should not be treated only as an IT problem.
A phishing attack can affect finance, customer relationships, operations, reputation, and business continuity.
The strongest approach combines technology with good processes and informed employees.
Businesses do not need to implement every advanced security technology at once. They can start with the fundamentals: strong authentication, secure account practices, employee awareness, software updates, backups, and clear procedures for suspicious requests.
For growing organisations, those foundations can provide a practical starting point for a broader cybersecurity programme.
How Tech Resonate Can Help
Tech Resonate provides cybersecurity awareness and safe digital practices alongside software development, AI and data solutions, digital marketing, technology training, laptop sales, and technology support.
Tech Resonate Academy also provides practical technology training for students and young professionals.
For businesses that need help improving their everyday technology practices, the focus should be on practical measures that make systems, accounts, and people safer.
Need help with a technology or cybersecurity problem? Contact Tech Resonate to discuss your situation.

