By Jackson Godwin. Cybersecurity Analyst & Penetration Testing

I Decided to Verify His Story
Instead of sending money, I started asking questions.
Simple questions.
Questions that a genuine soldier should have been able to answer.
I asked:
- Which military unit does he belong to?
- The name of the base where he was stationed.
- Whether he could arrange an official military email.
- Whether there was another way to verify his identity.
His answers became increasingly vague.
Sometimes he ignored the questions completely.
Other times, he changed the subject.
That was my first real clue.
I Looked Closer at the Photos
I decided to examine the photographs he had sent me over the past few months.
They all looked convincing.
But something caught my attention.
Many of them looked professionally taken.
Some even appeared in different locations but with the exact same pose.
Out of curiosity, I performed a reverse image search.
Within seconds, I found several of the same photographs on other websites.
The pictures belonged to a real soldier.
But the name was completely different.
Someone had stolen his identity.
The “Official Documents” Were Fake
Next, I examined the documents he had sent.
At first glance, they looked authentic.
But after reading them carefully, I noticed several inconsistencies.
Some logos were outdated.
Certain words were misspelled.
The formatting was inconsistent.
Official organisations rarely make those kinds of mistakes.
The documents weren’t official.
They had been designed to look convincing.
I Confronted Him
I finally sent him a direct message.
“I searched your photos. They belong to someone else.”
For several minutes, there was no reply.
Then he responded.
Instead of explaining, he became defensive.
“You don’t trust me.”
“I thought you loved me.”
“Someone is trying to destroy our relationship.”
He never answered my questions.
He only tried to make me feel guilty.
Then He Disappeared
The following morning, I opened our conversation.
His profile photo was gone.
A few hours later, the account disappeared completely.
I searched for his name.
Nothing.
Months of conversations had ended without a goodbye.
The person I thought I knew had vanished.
Because that person had never existed.
Why Criminals Pretend to Be Soldiers
After researching military romance scams, I discovered why scammers often impersonate soldiers.
Military personnel are commonly viewed as:
- Honest.
- Disciplined.
- Courageous.
- Trustworthy.
Using a military identity helps scammers gain credibility more quickly.
They also use “deployment” as an excuse to explain why they cannot:
- Meet in person.
- Join video calls.
- Receive normal bank transfers.
- Verify their identity.
The story is carefully designed to answer the questions victims are most likely to ask.
How to Protect Yourself
If someone online claims to be serving in the military:
- Be cautious if they avoid every request for a live video call.
- Verify information independently instead of relying only on documents or photographs.
- Be sceptical of requests for money, gift cards or cryptocurrency.
- Remember that genuine military organisations do not normally ask strangers to pay personal deployment expenses.
- Discuss suspicious situations with trusted friends or family before sending money.
Final Thoughts
The scammer didn’t need sophisticated hacking tools.
They didn’t need malware.
They didn’t need my password.
They only needed me to believe a carefully created story.
That experience reminded me that cybersecurity isn’t always about technology.
Sometimes, it’s about recognising manipulation before it becomes financial loss.
Today, I follow one simple rule:
No matter how convincing someone’s story sounds, I verify their identity before trusting them with my money—or my heart.
Real soldiers deserve our respect.
Scammers exploit that respect.
Knowing the difference could protect you from becoming their next victim.
About the Author
Jackson Godwin is a Cybersecurity Consultant specialising in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
Through JacksonTechnology.com.ng, he publishes cybersecurity awareness stories, practical security guides, and educational resources to help individuals and organisations recognise cyber threats, avoid online scams, and build safer digital habits.









