[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"public-site-settings-request":3,"public-blog-article-what-is-business-email-compromise-and-how-can-nigerian-businesses-prevent-it":45},{"company":4,"website":17,"seoPages":23},{"companyName":5,"publicEmail":6,"phoneNumber":7,"whatsappNumber":7,"location":8,"address":9,"mapEmbedUrl":15,"description":16},"Tech Resonate","info@techresonate.com","+234 903 930 2155","GFJ8+4HV, Talba Road, Minna, Barako 920102, Niger",{"streetAddress":10,"addressLocality":11,"addressRegion":12,"postalCode":13,"addressCountry":14},"GFJ8+4HV, Talba Road, Barako","Minna","Niger","920102","NG","https:\u002F\u002Fwww.google.com\u002Fmaps\u002Fembed?pb=!1m18!1m12!1m3!1d3934.7514248934194!2d6.463862574206257!3d9.530312490552397!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x104c71e8e0f8a103%3A0x9a77d830d7532694!2sTech%20Resonate!5e0!3m2!1sen!2sng!4v1781885558393!5m2!1sen!2sng","Tech Resonate is a technology company in Minna, Nigeria, providing software, digital solutions, cybersecurity, AI, training, laptops and tech support.",{"linkedIn":18,"x":19,"instagram":20,"facebook":21,"websiteUrl":22},"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Ftech-resonate","https:\u002F\u002Fx.com\u002FTechResonate","https:\u002F\u002Fwww.instagram.com\u002Ftech_resonate","https:\u002F\u002Fwww.facebook.com\u002Fprofile.php?id=61573829664020","https:\u002F\u002Ftechresonate.com",{"home":24,"services":27,"academy":30,"labs":33,"about":36,"contact":39,"laptops":42},{"title":25,"description":26},"Tech Resonate | Software Development, Web Development & Tech Training","Tech Resonate delivers software development, web development, cybersecurity, AI solutions, laptop sales, and practical tech training.",{"title":28,"description":29},"Software Development & IT Services | Tech Resonate","Tech Resonate provides software development, cybersecurity, UI\u002FUX design, digital marketing, AI solutions, laptops and technology support in Nigeria.",{"title":31,"description":32},"Tech Resonate Academy | Technology Training & Skills","Tech Resonate Academy provides project-based technology training in programming, web development, UI\u002FUX, cybersecurity, digital marketing, Python, data and AI.",{"title":34,"description":35},"Tech Resonate Labs | AI, Software & Product Innovation","Tech Resonate Labs researches problems and develops software, AI, automation, data and digital products based on evidence and user needs.",{"title":37,"description":38},"About Tech Resonate | Software Development & Technology Company","Learn about Tech Resonate, a technology company providing software development, web development, cybersecurity, AI solutions, tech training, and digital service",{"title":40,"description":41},"Contact Tech Resonate | Software & IT Services in Minna","Contact Tech Resonate in Minna, Niger State for software development, web development, cybersecurity, AI solutions, laptop sales, tech training, and IT support.",{"title":43,"description":44},"UK Used Laptops in Nigeria | Tech Resonate","Shop quality UK used HP, Dell, Lenovo, and MacBook laptops for work, school, gaming, and business at Tech Resonate.",{"article":46,"relatedArticles":74,"relatedLaptops":129},{"id":47,"slug":48,"title":49,"summary":50,"contentMarkdown":51,"category":52,"publishedAt":56,"updatedAt":57,"readingMinutes":58,"cover":59,"seoTitle":64,"metaDescription":65,"socialImageUrl":63,"relatedArticleSlugs":66,"relatedLaptopIds":72,"ctaType":73},14,"what-is-business-email-compromise-and-how-can-nigerian-businesses-prevent-it","What Is Business Email Compromise and How Can Nigerian Businesses Prevent It?","Learn what Business Email Compromise is, how attackers target Nigerian businesses, common warning signs, and practical steps to prevent payment fraud, impersonation, and account compromise.","#                What Is Business Email Compromise and How Can Nigerian Businesses Prevent It?\n\nA business can lose money or expose sensitive information without an attacker ever breaking into its main server.\n\nSometimes, the attack starts with a convincing email, message, or phone call that appears to come from a trusted person.\n\nThis is known as **Business Email Compromise (BEC)**.\n\nBEC attacks target business communication and processes. Attackers may impersonate executives, finance staff, suppliers, contractors, or other trusted people to trick employees into transferring money, changing payment details, sharing sensitive information, or carrying out unauthorised actions.\n\nNigeria's Computer Emergency Response Team (ngCERT) issued a high-risk advisory on August 27, 2026, warning organisations about BEC, phishing, impersonation, fraudulent payment requests, credential theft, and AI-assisted impersonation.\n\n## What Is Business Email Compromise?\n\nBusiness Email Compromise is a type of social engineering attack in which criminals use compromised, spoofed, or fraudulent accounts and identities to manipulate business processes.\n\nThe goal is often financial fraud, but attackers may also be trying to obtain credentials, sensitive information, or access to other systems.\n\nA typical attack might look like this:\n\n**Attacker → impersonates trusted person → sends urgent request → employee trusts request → money or information is transferred**\n\nThe request may appear to come from:\n\n* A company director\n* Finance manager\n* Supplier\n* Customer\n* Lawyer\n* Contractor\n* Business partner\n\nBecause the message may use real names, information, email conversations, and business terminology, it can be difficult to recognise immediately.\n\n## How Business Email Compromise Happens\n\nBEC does not always require an attacker to completely take over a business email account.\n\nAttackers may use several methods, including:\n\n### Compromised email accounts\n\nAn attacker obtains an employee's password and gains access to the real email account.\n\nThey can then read conversations and send messages that appear legitimate.\n\n### Email impersonation\n\nAttackers may create an address that looks similar to a real company or employee address.\n\nA small change in the domain or spelling can be easy to miss.\n\n### Phishing\n\nEmployees may receive a fake login page designed to steal their email credentials.\n\nOnce the attacker obtains the credentials, they can use the account for further fraud.\n\nFor more practical protection against phishing and account takeover, see our guide on [How Nigerian Businesses Can Protect Against Phishing and Account Takeovers](https:\u002F\u002Ftechresonate.com\u002Fblog\u002Fhow-nigerian-businesses-can-protect-against-phishing-and-account-takeovers).\n\n### Social engineering\n\nAttackers may research a business, its employees, suppliers, customers, and public information before contacting someone.\n\nThis information can make the fraudulent request appear more convincing.\n\n### AI-assisted impersonation\n\nModern attackers can also use publicly available information and AI-assisted techniques to create more convincing communications and impersonation attempts. ngCERT specifically included AI-assisted impersonation in its August 27, 2026 BEC advisory.\n\n## Common Examples of Business Email Compromise\n\n### Fake payment request\n\nAn attacker impersonates a manager and asks the finance team to make an urgent payment.\n\n### Supplier bank-detail change\n\nAn employee receives an email saying that a supplier has changed its bank account.\n\nThe employee updates the payment information without independently verifying the request.\n\n### Executive impersonation\n\nA message appears to come from a company director asking an employee to purchase something, send money, or provide confidential information.\n\n### Invoice fraud\n\nAn attacker modifies or creates an invoice and sends it through a compromised or fraudulent account.\n\n### Payroll fraud\n\nAn attacker attempts to change an employee's payment information so future payments go to an account controlled by the attacker.\n\n## Warning Signs Businesses Should Look For\n\nA suspicious request may contain one or more warning signs:\n\n* Unusual urgency\n* Unexpected payment instructions\n* Requests to change bank details\n* Requests for passwords or verification codes\n* Slightly different email addresses\n* Requests for secrecy\n* Unusual writing style or wording\n* Requests that bypass normal approval procedures\n* Unexpected attachments or links\n* A request that does not match established business processes\n\nOne warning sign does not automatically prove that a message is fraudulent, but unusual requests deserve additional verification.\n\n## How Nigerian Businesses Can Prevent BEC\n\n### 1. Independently Verify Payment Requests\n\nDo not rely on email alone when approving unusual payments or bank-detail changes.\n\nFor example, if a supplier sends new banking information by email, contact the supplier using a trusted phone number or previously verified communication channel.\n\nDo not use only the contact details provided in the suspicious message.\n\n### 2. Enable Multi-Factor Authentication\n\nMulti-factor authentication adds another layer of protection beyond the password.\n\nNIST recommends enabling MFA for business accounts and using phishing-resistant authentication where appropriate.\n\nMFA can reduce the impact of stolen passwords, although businesses should still train employees to recognise phishing and protect authentication factors.\n\n### 3. Use Strong, Unique Passwords\n\nImportant business accounts should use unique passwords that are not reused across multiple services.\n\nIf one password is exposed, reusing it elsewhere can allow attackers to compromise additional accounts. ngCERT has warned that stolen credentials can contribute to account takeover and subsequent BEC attacks.\n\n### 4. Create Approval Procedures for Payments\n\nBusinesses should establish clear procedures for financial transactions.\n\nFor example:\n\n**Payment request → independent verification → approval → payment**\n\nThis is safer than allowing urgent email requests to bypass normal financial controls.\n\n### 5. Protect Administrator and Finance Accounts\n\nAccounts with access to financial systems, email administration, payment platforms, or sensitive information should receive stronger protection.\n\nBusinesses should limit privileged access and regularly review unused or unnecessary accounts.\n\n### 6. Train Employees\n\nEmployees should know that attackers may use email, WhatsApp, SMS, phone calls, social media, or other communication channels.\n\nTraining should cover:\n\n* Phishing\n* Impersonation\n* Payment fraud\n* Password security\n* MFA\n* Suspicious links\n* Verification procedures\n* Incident reporting\n\nNIST recommends teaching employees how to identify and report phishing attempts and recognising that phishing can occur through multiple communication channels.\n\n### 7. Review Email Account Activity\n\nBusinesses should periodically review important accounts for unusual activity.\n\nLook for:\n\n* Unexpected login activity\n* Unknown devices\n* Suspicious forwarding rules\n* New recovery addresses\n* Unfamiliar applications\n* Unauthorised permissions\n\nCompromised accounts may be used to monitor conversations or maintain access for future attacks. ngCERT specifically warns about malicious mailbox rules and persistence following account compromise.\n\n## What Should You Do If You Suspect BEC?\n\nAct quickly.\n\nIf an employee believes a business account has been compromised or a fraudulent payment request has been processed:\n\n1. Report the incident immediately.\n2. Secure the affected account.\n3. Change compromised passwords from a trusted device.\n4. Revoke active sessions where possible.\n5. Review MFA and recovery settings.\n6. Contact the bank immediately if money may have been transferred.\n7. Review recent account activity.\n8. Preserve relevant emails, messages, and other evidence.\n9. Check whether other accounts or employees were targeted.\n\nFast reporting can help limit the damage and prevent further fraudulent activity.\n\n## BEC Is Not Only an Email Problem\n\nAlthough Business Email Compromise often involves email, attackers may combine several communication channels.\n\nThey may start with an email and then follow up through:\n\n* WhatsApp\n* SMS\n* Phone calls\n* Social media\n* Fake websites\n* Other messaging platforms\n\nThis is why businesses should verify unusual requests based on **trusted processes**, not simply because a message appears to come from a familiar platform.\n\n## A Simple BEC Protection Checklist\n\nBusinesses can start with these basic controls:\n\n* Use strong, unique passwords.\n* Enable MFA.\n* Verify unusual payment requests independently.\n* Verify supplier bank-detail changes through a trusted channel.\n* Limit administrator access.\n* Train employees regularly.\n* Review important account activity.\n* Protect finance and executive accounts.\n* Maintain reliable backups.\n* Have a clear incident-reporting process.\n\nThese controls cannot guarantee that a business will never experience fraud, but they can reduce common opportunities for attackers and make suspicious activity easier to detect.\n\n## How Tech Resonate Can Help\n\nTech Resonate provides [cybersecurity awareness and safe digital practices](https:\u002F\u002Ftechresonate.com\u002Fservices) for businesses and organisations alongside software development, AI and data solutions, digital marketing, technology training, laptops, and technology support.\n\nBusinesses can also use [Tech Resonate Academy](https:\u002F\u002Ftechresonate.com\u002Facademy) to develop practical technology and digital skills.\n\nCybersecurity is most effective when technology, people, and business processes work together.\n\nNeed help improving your organisation's digital security? [Contact Tech Resonate](https:\u002F\u002Ftechresonate.com\u002Fcontact) to discuss your requirements.\n\n## Sources\n\n* [Nigeria Computer Emergency Response Team (ngCERT) — Business Email Compromise and Social Engineering Attacks](https:\u002F\u002Fcert.gov.ng\u002Fadvisories\u002Fbusiness-email-compromise-and-social-engineering-attacks-targeting-government-and-critical-institutions)\n* [ngCERT — Associated Risks of Stolen Email Passwords and Credentials](https:\u002F\u002Fcert.gov.ng\u002Fadvisories\u002Fassociated-risks-of-stolen-email-passwords-and-credentials-resulting-from-data-breaches)\n* [NIST — Phishing](https:\u002F\u002Fwww. nist.gov\u002Fitl\u002Fsmallbusinesscyber\u002Fguidance-topic\u002Fphishing)\n* [NIST — Multi-Factor Authentication](https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fsmallbusinesscyber\u002Fguidance-topic\u002Fmulti-factor-authentication)",{"id":53,"name":54,"slug":55},4,"Digital Safety","digital-safety","2026-09-06 20:52:00","2026-09-06 20:53:21",7,{"kind":60,"svg":61,"imageUrl":62,"imageAlt":63},"svg","editorial-signal",null,"","Business Email Compromise: How Nigerian Businesses Can Prevent It","Learn how Nigerian businesses can prevent Business Email Compromise, payment fraud, impersonation and account takeovers with practical security controls.",[67,68,69,70,71],"practical-ways-to-use-ai-in-daily-work","best-laptop-for-programming-in-nigeria-2026-complete-buyers-guide","custom-software-vs-off-the-shelf-software-which-is-right-for-your-business","digital-safety-basics-everyone-should-know","how-much-does-custom-software-development-cost-in-nigeria",[],"services",[75,87,100,112,120],{"id":76,"slug":67,"title":77,"summary":78,"category":79,"publishedAt":83,"updatedAt":84,"readingMinutes":76,"cover":85},6,"5 ways to use AI in your daily work","Ideas for reducing repeated work, organising information and improving first drafts.",{"id":80,"name":81,"slug":82},5,"AI & Technology","ai-technology","2024-04-12 09:00:00","2026-07-31 13:43:18",{"kind":60,"svg":61,"imageUrl":62,"imageAlt":86},"Abstract AI editorial signal in Tech Resonate colours",{"id":88,"slug":68,"title":89,"summary":90,"category":91,"publishedAt":95,"updatedAt":96,"readingMinutes":76,"cover":97},8,"Best Laptop for Programming in Nigeria (2026): Complete Buyer's Guide","Looking for the best laptop for programming in Nigeria? This guide compares the best UK used laptops for coding, software development, web development, and computer science students.",{"id":92,"name":93,"slug":94},1,"Laptop Guides","laptop-guides","2026-08-03 12:16:00","2026-08-28 00:01:32",{"kind":98,"svg":62,"imageUrl":99,"imageAlt":89},"image","\u002Fapi\u002Fblog-images\u002Fblog_3ea703377eba4cddb0a10ddbca9212bb\u002Fbest-laptop-for-programming-in-nigeria-2026-complete-buyers-guide-cover.jpg",{"id":101,"slug":69,"title":102,"summary":103,"category":104,"publishedAt":108,"updatedAt":109,"readingMinutes":76,"cover":110},11,"Custom Software vs Off-the-Shelf Software: Which Is Right for Your Business?","Compare custom software and off-the-shelf software to understand their differences in cost, flexibility, scalability, integrations, maintenance, and suitability for different business needs.",{"id":105,"name":106,"slug":107},2,"Software & Business","software-business","2026-08-15 10:48:00","2026-08-27 23:55:29",{"kind":60,"svg":111,"imageUrl":62,"imageAlt":63},"editorial-code",{"id":53,"slug":70,"title":113,"summary":114,"category":115,"publishedAt":116,"updatedAt":116,"readingMinutes":80,"cover":117},"Digital safety basics everyone should know","Simple steps to protect your data, privacy, and devices online.",{"id":53,"name":54,"slug":55},"2024-04-20 10:00:00",{"kind":60,"svg":118,"imageUrl":62,"imageAlt":119},"editorial-shield","Shield-inspired editorial pattern in Tech Resonate colours",{"id":121,"slug":71,"title":122,"summary":123,"category":124,"publishedAt":125,"updatedAt":126,"readingMinutes":53,"cover":127},9,"How Much Does Custom Software Development Cost in Nigeria?","Discover what affects the cost of custom software development in Nigeria, the key factors that influence pricing, and how businesses can choose the right software solution for long-term growth.",{"id":105,"name":106,"slug":107},"2026-08-07 02:10:00","2026-08-07 01:18:26",{"kind":98,"svg":62,"imageUrl":128,"imageAlt":122},"\u002Fapi\u002Fblog-images\u002Fblog_1ddf7467b88a4c3a85e3e851c2e5bc72\u002Fhow-much-does-custom-software-development-cost-in-nigeria-cover.jpg",[]]