By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

This article is based on a realistic fraud scenario inspired by common scam techniques. The purpose is to educate readers about cybersecurity awareness and fraud prevention.”
It Started Like Any Other Tuesday
It was around 11:30 a.m.
I had just finished reviewing a penetration testing report for a client when my phone vibrated.
The notification looked ordinary.
It appeared to be from my bank.
The message was calm and professional:
“We’ve detected unusual activity on your account. For your protection, some services have been temporarily restricted. Please verify your account immediately to restore full access.”
There was also a link.
At first glance, nothing looked suspicious.
There were no spelling mistakes.
No grammatical errors.
No unrealistic promises.
No threats.
Everything looked exactly like the kind of security notification you would expect from a financial institution.
As someone who works in cybersecurity, I should have ignored it immediately.
Instead…
I clicked the link.
The Website Looked Perfect
The page opened instantly.
The logo looked familiar.
The colours matched.
The design was professional.
Even the login page looked authentic.
If someone had asked me to compare it with a legitimate banking website, I might not have noticed the difference immediately.
That is exactly why modern phishing attacks are so dangerous.
Cybercriminals no longer rely on poorly designed fake websites.
Many now build convincing copies designed to create a false sense of trust.
Something Didn’t Feel Right
As I prepared to enter my username, something caught my attention.
I looked carefully at the website address.
It wasn’t the organisation’s official domain.
It was similar.
Very similar.
But not identical.
Instead of using the institution’s genuine web address, the criminals had registered a domain that looked almost the same.
One extra word.
One small change.
One mistake that many people would never notice.
I immediately closed the browser.
At that moment, I realised how close I had come to handing over my login credentials.
Why Even Cybersecurity Professionals Can Be Targeted
People often assume cybersecurity professionals never fall for scams.
The truth is different.
Cybercriminals don’t rely only on technical attacks.
They rely on psychology.
They exploit:
- Fear
- Urgency
- Curiosity
- Trust
- Distraction
When someone believes their bank account may be at risk, they are more likely to react quickly instead of thinking critically.
That emotional response is exactly what scammers want.
The Scam Didn’t End There
About twenty minutes later, my phone rang.
The caller introduced himself as a member of the bank’s “security department.”
His voice was calm.
Professional.
Confident.
He already knew my full name.
He claimed someone had attempted to access my account.
Then he asked me to “confirm my identity.”
At first, the conversation sounded legitimate.
But then came the warning sign.
He asked me to provide a one-time password (OTP) that had just been sent to my phone.
That was the moment I ended the call.
No legitimate bank representative should ask you to disclose your OTP or security code.
The Tricks Criminals Use
Modern banking scams have evolved far beyond poorly written emails.
Today, scammers may use:
- Professional-looking websites.
- Fake SMS alerts.
- Email phishing.
- Fraudulent phone calls.
- QR codes.
- Social media advertisements.
- Messaging apps.
- Artificial Intelligence to write convincing messages.
Some even study their victims through publicly available information to make their stories appear more believable.
The Biggest Lesson I Learned
Technology wasn’t what protected me.
It was one simple habit.
I stopped.
Instead of reacting emotionally, I paused and verified the information independently.
Rather than clicking the link again, I opened my banking app directly and checked my account.
Everything was normal.
There had never been any suspicious activity.
The message was fraudulent.
How to Verify Banking Messages Safely
Whenever you receive an unexpected security notification:
Never panic.
Instead:
Open your banking app directly.
Type the bank’s official website yourself instead of clicking links.
Call the customer service number published on the bank’s official website or printed on your bank card.
If the notification is genuine, you will usually see it inside your secure banking application.
Why Phishing Still Works
People often ask:
“If phishing is so common, why do criminals still use it?”
The answer is simple.
Because it still works.
Attackers don’t need to fool everyone.
If only a few people respond, the campaign may still be profitable.
That’s why awareness remains one of the strongest cybersecurity defences.
Warning Signs You Should Never Ignore
When you receive a banking message, ask yourself:
Did I expect this message?
Does the website address exactly match the official domain?
Is the sender creating unnecessary urgency?
Am I being asked to click a link?
Am I being asked to reveal my password, PIN, or OTP?
If the answer to any of these questions makes you uncomfortable, pause and verify independently.
Five Habits That Can Protect Your Money
1. Enable Multi-Factor Authentication
Additional verification can help protect your accounts if your password is compromised.
2. Never Share Your OTP
One-time passwords are intended only for you.
Legitimate organisations generally do not ask customers to disclose them over the phone or through messaging apps.
3. Verify Before You Trust
Do not rely solely on messages or phone calls.
Always verify using official communication channels.
4. Keep Your Devices Updated
Install security updates for your operating system and applications regularly.
Updates often include important security fixes.
5. Learn Common Scam Techniques
Awareness remains one of the most effective security controls.
Understanding how scams work makes them easier to recognise.
The Human Side of Cybersecurity
Many people think cybersecurity is about expensive software.
Firewalls.
Encryption.
Artificial Intelligence.
Those technologies are important.
But every day, criminals continue to exploit something much simpler.
Human trust.
That is why cybersecurity is not only about protecting computers.
It is about protecting people.
If I Had Ignored the Warning Sign…
Had I entered my credentials into the fake website, the consequences could have included:
- Unauthorized access to my account.
- Attempts to reset passwords.
- Exposure of personal information.
- Time spent securing accounts and recovering access.
Fortunately, taking a moment to inspect the website address changed the outcome.
Cybersecurity Starts With You
Banks invest heavily in security technologies.
But no system can completely protect customers who unknowingly hand over their own credentials.
Every user plays an important role.
The next phishing message may not contain spelling mistakes.
It may not look suspicious.
It may even appear to come from someone you trust.
That is why verification should become a habit—not an afterthought.
Final Thoughts
Scammers are becoming more sophisticated, but the principles of staying safe remain the same: slow down, verify independently, and never share sensitive authentication information. Even experienced technology users can encounter convincing scams, which is why ongoing awareness is essential.
The few seconds you spend checking a message before acting could prevent hours—or even days—of financial and emotional stress. Staying informed is one of the best investments you can make in your digital security.
About the Author
Jackson Godwin is a Cybersecurity Consultant specializing in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), Cloud Security, Enterprise Security, AI Security, ISO/IEC 27001, PCI DSS, and Banking Cybersecurity. Through JacksonTechnology.com.ng, he shares practical cybersecurity tutorials, compliance guides, security awareness articles, and penetration testing resources to help individuals and organizations strengthen their cybersecurity posture.
Connect with JacksonTechnology.com.ng for expert insights on cybersecurity, ethical hacking, cloud security, digital forensics, and fraud prevention.








