By Jackson Godwin. Cybersecurity Analyst & Penetration Tester

The Bank’s Investigation Was Good News
A few days after reporting the fraud, the bank contacted me with an update.
Their investigation confirmed that my account had been targeted by a phishing attack.
The transactions didn’t match my normal spending habits.
They originated from unfamiliar merchants and locations.
Because I reported the fraud immediately, the bank was able to stop additional transactions and begin the process of reversing the unauthorised charges, in accordance with its investigation procedures and applicable policies.
Quick action made all the difference.
I Changed Everything
The experience taught me that cancelling my card wasn’t enough.
I immediately:
- Changed my online banking password.
- Changed the password for my email account.
- Enabled multi-factor authentication (MFA) wherever possible.
- Logged out of all active sessions.
- Reviewed every financial account connected to my email.
Why my email?
Because if criminals gain access to your email, they may be able to reset passwords for many of your other accounts.
Protecting it became my highest priority.
I Examined the Fake Message Again
When I looked at the original SMS more carefully, several warning signs became obvious.
The message:
- Created a sense of panic.
- Demanded immediate action.
- Included a link instead of asking me to use the official banking app.
- Used a web address that looked similar—but not identical—to my bank’s real website.
None of those signs seemed obvious while I was frightened.
Looking back, they were everywhere.
The Investigator Explained the Psychology
The bank’s fraud investigator told me something I will never forget.
“Phishing isn’t just about stealing passwords. It’s about manipulating emotions.”
The criminals wanted me to react before I had time to think.
Fear became their most effective tool.
Once panic took over, I stopped asking questions.
I simply followed instructions.
Warning Signs of Fake Bank Fraud Alerts
Looking back, these were the biggest red flags.
🚩 Messages Creating Extreme Urgency
Scammers often claim:
- Your account has been suspended.
- Fraud has been detected.
- Immediate verification is required.
Urgency is designed to stop you from thinking carefully.
🚩 Links in Unexpected Messages
Instead of clicking a link in an email or SMS, open your bank’s official app or type the bank’s website address yourself.
If there really is a problem, you’ll usually see it there.
🚩 Requests for Full Card Information
Be cautious if a website asks for:
- Your full card number.
- The CVV security code.
- A one-time password (OTP).
Legitimate banks have established authentication processes and generally do not ask customers to disclose one-time passwords through unsolicited links or messages.
🚩 Slightly Different Website Addresses
Cybercriminals often register domains that look almost identical to genuine banking websites.
One missing or extra letter can make all the difference.
Always check the full website address carefully.
How to Protect Yourself
You can reduce your risk by following a few simple habits.
- Never click banking links in unexpected emails or text messages.
- Use your bank’s official mobile app or manually type the website address.
- Enable transaction alerts for your accounts.
- Turn on multi-factor authentication where available.
- Keep your devices and browsers updated.
- If you’re unsure, contact your bank using the official phone number from its website or the back of your card.
Taking a few extra seconds to verify can prevent hours—or even months—of financial stress.
Frequently Asked Questions
Can phishing websites look exactly like real banking websites?
Yes.
Modern phishing pages can closely imitate the design, colours and branding of legitimate banks.
That’s why checking the website address and accessing your bank through trusted methods is so important.
What should I do if I accidentally enter my banking details on a fake website?
Act immediately.
Contact your bank through its official channels, change your passwords, monitor your accounts and follow your bank’s guidance to secure your finances.
The sooner you report the incident, the better your chances of limiting the damage.
Why did the scammers ask for my one-time password?
One-time passwords are designed to confirm certain banking actions.
If you enter an OTP into a phishing website, criminals may try to use it to complete unauthorised actions before it expires.
Never share an OTP with anyone unless you initiated the action through your bank’s trusted channels.
Final Thoughts
The criminals never broke into my bank.
They never hacked my phone.
They never guessed my password.
Instead, they convinced me to hand over everything willingly.
That experience completely changed how I think about cybersecurity.
The strongest password in the world can’t protect you if you voluntarily give it to the wrong person.
Today, whenever I receive an unexpected banking message, I pause.
I don’t click.
I don’t panic.
I verify first.
Because one moment of caution can prevent a lifetime of regret.
About the Author
Jackson Godwin is a Cybersecurity Consultant specialising in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
Through JacksonTechnology.com.ng, he publishes cybersecurity awareness stories, ethical hacking tutorials, compliance guides, and practical online safety advice to help individuals and organisations recognise cyber threats, prevent financial fraud, and stay secure in an increasingly digital world.
His mission is to make cybersecurity practical, relatable, and accessible—one cyberstory at a time.





