[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"public-site-settings-request":3,"public-blog-article-how-nigerian-businesses-can-protect-against-phishing-and-account-takeovers":45},{"company":4,"website":17,"seoPages":23},{"companyName":5,"publicEmail":6,"phoneNumber":7,"whatsappNumber":7,"location":8,"address":9,"mapEmbedUrl":15,"description":16},"Tech Resonate","info@techresonate.com","+234 903 930 2155","GFJ8+4HV, Talba Road, Minna, Barako 920102, Niger",{"streetAddress":10,"addressLocality":11,"addressRegion":12,"postalCode":13,"addressCountry":14},"GFJ8+4HV, Talba Road, Barako","Minna","Niger","920102","NG","https:\u002F\u002Fwww.google.com\u002Fmaps\u002Fembed?pb=!1m18!1m12!1m3!1d3934.7514248934194!2d6.463862574206257!3d9.530312490552397!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x104c71e8e0f8a103%3A0x9a77d830d7532694!2sTech%20Resonate!5e0!3m2!1sen!2sng!4v1781885558393!5m2!1sen!2sng","Tech Resonate is a technology company in Minna, Nigeria, providing software, digital solutions, cybersecurity, AI, training, laptops and tech support.",{"linkedIn":18,"x":19,"instagram":20,"facebook":21,"websiteUrl":22},"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Ftech-resonate","https:\u002F\u002Fx.com\u002FTechResonate","https:\u002F\u002Fwww.instagram.com\u002Ftech_resonate","https:\u002F\u002Fwww.facebook.com\u002Fprofile.php?id=61573829664020","https:\u002F\u002Ftechresonate.com",{"home":24,"services":27,"academy":30,"labs":33,"about":36,"contact":39,"laptops":42},{"title":25,"description":26},"Tech Resonate | Software Development, Web Development & Tech Training","Tech Resonate delivers software development, web development, cybersecurity, AI solutions, laptop sales, and practical tech training.",{"title":28,"description":29},"Software Development & IT Services | Tech Resonate","Tech Resonate provides software development, cybersecurity, UI\u002FUX design, digital marketing, AI solutions, laptops and technology support in Nigeria.",{"title":31,"description":32},"Tech Resonate Academy | Technology Training & Skills","Tech Resonate Academy provides project-based technology training in programming, web development, UI\u002FUX, cybersecurity, digital marketing, Python, data and AI.",{"title":34,"description":35},"Tech Resonate Labs | AI, Software & Product Innovation","Tech Resonate Labs researches problems and develops software, AI, automation, data and digital products based on evidence and user needs.",{"title":37,"description":38},"About Tech Resonate | Software Development & Technology Company","Learn about Tech Resonate, a technology company providing software development, web development, cybersecurity, AI solutions, tech training, and digital service",{"title":40,"description":41},"Contact Tech Resonate | Software & IT Services in Minna","Contact Tech Resonate in Minna, Niger State for software development, web development, cybersecurity, AI solutions, laptop sales, tech training, and IT support.",{"title":43,"description":44},"UK Used Laptops in Nigeria | Tech Resonate","Shop quality UK used HP, Dell, Lenovo, and MacBook laptops for work, school, gaming, and business at Tech Resonate.",{"article":46,"relatedArticles":73,"relatedLaptops":119},{"id":47,"slug":48,"title":49,"summary":50,"contentMarkdown":51,"category":52,"publishedAt":56,"updatedAt":57,"readingMinutes":58,"cover":59,"seoTitle":64,"metaDescription":65,"socialImageUrl":63,"relatedArticleSlugs":66,"relatedLaptopIds":71,"ctaType":72},13,"how-nigerian-businesses-can-protect-against-phishing-and-account-takeovers","How Nigerian Businesses Can Protect Against Phishing and Account Takeovers","Practical ways Nigerian businesses can reduce phishing, business email compromise, and account takeover risks through stronger authentication, employee awareness, verification, backups, and incident-response practices.","# How Nigerian Businesses Can Protect Against Phishing and Account Takeovers\n\nCyberattacks do not always begin with sophisticated malware or complicated technical exploits. For many businesses, an attack can start with something much simpler: a convincing email, WhatsApp message, fake login page, or request for sensitive information.\n\nPhishing can trick employees into giving away passwords or authentication codes. Once an attacker obtains those credentials, they may take control of an email account, social-media account, business application, or other system.\n\nFor Nigerian businesses, reducing these risks requires more than installing antivirus software. Businesses need practical security controls, employee awareness, strong authentication, and clear procedures for handling suspicious messages and account compromises.\n\n## Why Phishing Is a Serious Business Risk\n\nPhishing is a form of social engineering in which an attacker attempts to deceive someone into revealing information, clicking a malicious link, opening a harmful attachment, or performing an action that benefits the attacker.\n\nThe message may appear to come from:\n\n* A manager or business owner\n* A bank or financial service\n* A supplier or customer\n* A technology provider\n* A government organisation\n* A colleague\n* A familiar social-media or cloud service\n\nAttackers can also use information about a business, its employees, customers, and suppliers to make fraudulent messages appear more believable.\n\nNigeria's national Computer Emergency Response Team, [ngCERT](https:\u002F\u002Fcert.gov.ng\u002F), has warned organisations about phishing, business email compromise, stolen credentials, ransomware, and other cyber threats targeting organisations in the country.\n\n## What Is Business Email Compromise?\n\nBusiness Email Compromise (BEC) occurs when attackers use compromised or fraudulent email accounts to deceive employees into transferring money, changing payment details, sharing sensitive information, or carrying out another unauthorised action.\n\nA common example is an attacker compromising an employee's email account and then sending a message that appears to come from a director or finance manager.\n\nThe message might say:\n\n> “Please process this payment urgently.”\n\nOr:\n\n> “Our bank account has changed. Use the new account for today's payment.”\n\nThe request may look genuine because the attacker has information from previous conversations.\n\n### A Simple Verification Rule\n\nBusinesses should avoid approving sensitive financial or account changes based only on email instructions.\n\nFor example, before changing a supplier's bank details, an employee could independently contact the supplier using a trusted phone number or previously verified communication channel.\n\nThis adds a second verification step that can help prevent a fraudulent request from becoming a financial loss.\n\n## How Account Takeovers Happen\n\nAn account takeover occurs when someone gains unauthorised control of an online account.\n\nThis can happen after:\n\n* A password is stolen through phishing\n* The same password is reused on multiple services\n* Malware captures credentials\n* An attacker obtains a session or authentication token\n* An employee shares a verification code\n* An account has weak security settings\n\nThe consequences can be serious.\n\nAn attacker who gains access to a business email account may use it to impersonate employees, reset other passwords, target customers or suppliers, access confidential information, or launch further attacks.\n\n## How Nigerian Businesses Can Reduce the Risk\n\n### 1. Use Strong, Unique Passwords\n\nBusiness accounts should not rely on simple or reused passwords.\n\nEach important account should have a strong, unique password. Password managers can help employees create and store unique credentials without having to remember every password.\n\nA compromised password should not automatically provide access to multiple systems.\n\n### 2. Enable Multi-Factor Authentication\n\nMulti-factor authentication (MFA) adds another verification factor beyond the password.\n\nDepending on the service, this might involve an authenticator application, security key, or another approved authentication method.\n\nMFA can reduce the impact of password theft because knowing the password alone may not be enough to access the account. [NIST](https:\u002F\u002Fwww.nist.gov\u002F) recommends stronger, phishing-resistant authentication methods where appropriate.\n\n### 3. Train Employees to Recognise Suspicious Messages\n\nTechnology cannot solve every phishing problem by itself.\n\nEmployees should know how to recognise warning signs such as:\n\n* Unexpected urgency\n* Requests for passwords or verification codes\n* Suspicious links\n* Unexpected attachments\n* Slightly altered sender addresses\n* Requests to change payment information\n* Messages that do not match normal business procedures\n\nTraining should use realistic examples relevant to the business rather than relying only on theoretical explanations.\n\n### 4. Verify Unusual Financial Requests\n\nA request involving money should receive additional verification.\n\nFor example:\n\n**Email request → independent phone verification → payment**\n\nis safer than:\n\n**Email request → immediate payment**\n\nThe same principle can apply to changes involving supplier accounts, payroll details, passwords, administrator access, or sensitive customer information.\n\n### 5. Protect Administrator Accounts\n\nAdministrator accounts have greater privileges and therefore require stronger protection.\n\nBusinesses should limit administrative access to people who actually need it and avoid using administrator accounts for ordinary daily activities where possible.\n\nInactive accounts and former employees' access should also be removed promptly.\n\n### 6. Keep Software and Devices Updated\n\nSecurity updates often address vulnerabilities that attackers may otherwise exploit.\n\nBusinesses should keep operating systems, browsers, applications, plugins, routers, and other internet-connected technology updated according to the vendor's security guidance.\n\nUpdates alone will not prevent phishing, but outdated software can create additional opportunities for attackers.\n\n### 7. Back Up Important Business Information\n\nBusinesses should maintain reliable backups of important data and make sure backups cannot easily be destroyed by the same attack that affects the primary systems.\n\nBackups are particularly important for recovering from ransomware, accidental deletion, hardware failures, and other incidents.\n\nA backup strategy should also include periodic testing to make sure data can actually be restored.\n\n### 8. Create a Simple Incident-Response Procedure\n\nEmployees should know what to do when something suspicious happens.\n\nFor example, if an employee enters a password into a fake login page, the response should not be:\n\n> “Let's wait and see what happens.”\n\nA better process may include:\n\n1. Report the incident immediately.\n2. Change the affected password from a trusted device.\n3. Revoke active sessions where the service allows it.\n4. Review MFA and account-recovery settings.\n5. Check for suspicious account activity.\n6. Escalate the incident to the person responsible for security.\n\nThe faster a compromised account is identified and secured, the more opportunity the business has to limit further damage.\n\n## Businesses Should Pay Attention to WhatsApp and Other Messaging Channels Too\n\nPhishing is not limited to email.\n\nAttackers may use WhatsApp, SMS, social media, messaging platforms, or phone calls to impersonate employees, customers, suppliers, or service providers.\n\nFor Nigerian businesses, this matters because many organisations use messaging applications as part of everyday communication.\n\nEmployees should therefore verify unusual requests regardless of which platform they arrive through.\n\nA message being received through WhatsApp does not automatically make it trustworthy.\n\n## What Should Businesses Do If an Account Is Hacked?\n\nIf a business suspects that an account has been compromised, act quickly.\n\nStart by securing the account and changing the password from a trusted device. Enable or reset MFA where necessary, sign out other sessions if the platform supports that option, and review recent activity.\n\nBusinesses should also check whether the attacker changed:\n\n* Recovery email addresses\n* Phone numbers\n* MFA settings\n* Forwarding rules\n* Administrator permissions\n* Payment information\n* Connected applications\n\nFor a business email account, suspicious forwarding rules are particularly important because attackers may use them to secretly receive future messages.\n\nWhere financial fraud or significant data exposure is suspected, the business should preserve relevant evidence and consider appropriate professional and legal assistance.\n\n## A Practical Phishing Protection Checklist\n\nA small business can start with a simple checklist:\n\n* Use unique passwords for important accounts.\n* Enable MFA.\n* Train staff to recognise phishing.\n* Verify unusual payment requests independently.\n* Keep software and devices updated.\n* Limit administrator access.\n* Remove access for former employees.\n* Maintain tested backups.\n* Have a clear incident-reporting procedure.\n* Review important accounts regularly.\n\nThese measures are not a guarantee that an organisation will never experience a cyberattack, but they can reduce common opportunities for attackers and improve the organisation's ability to respond.\n\n## Cybersecurity Is a Business Responsibility\n\nCybersecurity should not be treated only as an IT problem.\n\nA phishing attack can affect finance, customer relationships, operations, reputation, and business continuity.\n\nThe strongest approach combines technology with good processes and informed employees.\n\nBusinesses do not need to implement every advanced security technology at once. They can start with the fundamentals: strong authentication, secure account practices, employee awareness, software updates, backups, and clear procedures for suspicious requests.\n\nFor growing organisations, those foundations can provide a practical starting point for a broader cybersecurity programme.\n\n## How Tech Resonate Can Help\n\nTech Resonate provides [cybersecurity awareness and safe digital practices](https:\u002F\u002Ftechresonate.com\u002Fservices) alongside software development, AI and data solutions, digital marketing, technology training, laptop sales, and technology support.\n\n[Tech Resonate Academy](https:\u002F\u002Ftechresonate.com\u002Facademy) also provides practical technology training for students and young professionals.\n\nFor businesses that need help improving their everyday technology practices, the focus should be on practical measures that make systems, accounts, and people safer.\n\nNeed help with a technology or cybersecurity problem? [Contact Tech Resonate](https:\u002F\u002Ftechresonate.com\u002Fcontact) to discuss your situation.\n\n## Sources\n\n* [Nigeria Computer Emergency Response Team (ngCERT)](https:\u002F\u002Fcert.gov.ng\u002F)\n* [National Institute of Standards and Technology (NIST)](https:\u002F\u002Fwww.nist.gov\u002F)\n* [Federal Trade Commission (FTC): How to Recognize and Avoid Phishing Scams](https:\u002F\u002Fconsumer.ftc.gov\u002Farticles\u002Fhow-recognize-and-avoid-phishing-scams)",{"id":53,"name":54,"slug":55},4,"Digital Safety","digital-safety","2026-08-23 21:43:00","2026-08-27 23:56:33",7,{"kind":60,"svg":61,"imageUrl":62,"imageAlt":63},"svg","editorial-signal",null,"","How Nigerian Businesses Can Prevent Phishing & Account Takeovers","Learn how Nigerian businesses can prevent phishing and account takeovers with MFA, secure passwords, employee awareness, verification, backups, and response plans.",[67,68,69,70],"practical-ways-to-use-ai-in-daily-work","best-laptop-for-programming-in-nigeria-2026-complete-buyers-guide","custom-software-vs-off-the-shelf-software-which-is-right-for-your-business","digital-safety-basics-everyone-should-know",[],"services",[74,86,99,111],{"id":75,"slug":67,"title":76,"summary":77,"category":78,"publishedAt":82,"updatedAt":83,"readingMinutes":75,"cover":84},6,"5 ways to use AI in your daily work","Ideas for reducing repeated work, organising information and improving first drafts.",{"id":79,"name":80,"slug":81},5,"AI & Technology","ai-technology","2024-04-12 09:00:00","2026-07-31 13:43:18",{"kind":60,"svg":61,"imageUrl":62,"imageAlt":85},"Abstract AI editorial signal in Tech Resonate colours",{"id":87,"slug":68,"title":88,"summary":89,"category":90,"publishedAt":94,"updatedAt":95,"readingMinutes":75,"cover":96},8,"Best Laptop for Programming in Nigeria (2026): Complete Buyer's Guide","Looking for the best laptop for programming in Nigeria? This guide compares the best UK used laptops for coding, software development, web development, and computer science students.",{"id":91,"name":92,"slug":93},1,"Laptop Guides","laptop-guides","2026-08-03 12:16:00","2026-08-28 00:01:32",{"kind":97,"svg":62,"imageUrl":98,"imageAlt":88},"image","\u002Fapi\u002Fblog-images\u002Fblog_3ea703377eba4cddb0a10ddbca9212bb\u002Fbest-laptop-for-programming-in-nigeria-2026-complete-buyers-guide-cover.jpg",{"id":100,"slug":69,"title":101,"summary":102,"category":103,"publishedAt":107,"updatedAt":108,"readingMinutes":75,"cover":109},11,"Custom Software vs Off-the-Shelf Software: Which Is Right for Your Business?","Compare custom software and off-the-shelf software to understand their differences in cost, flexibility, scalability, integrations, maintenance, and suitability for different business needs.",{"id":104,"name":105,"slug":106},2,"Software & Business","software-business","2026-08-15 10:48:00","2026-08-27 23:55:29",{"kind":60,"svg":110,"imageUrl":62,"imageAlt":63},"editorial-code",{"id":53,"slug":70,"title":112,"summary":113,"category":114,"publishedAt":115,"updatedAt":115,"readingMinutes":79,"cover":116},"Digital safety basics everyone should know","Simple steps to protect your data, privacy, and devices online.",{"id":53,"name":54,"slug":55},"2024-04-20 10:00:00",{"kind":60,"svg":117,"imageUrl":62,"imageAlt":118},"editorial-shield","Shield-inspired editorial pattern in Tech Resonate colours",[]]