By Jackson Godwin. Cybersecurity & Penetration Tester

The WhatsApp Message That Nearly Cost Someone ₦2 Million: A Cybersecurity Expert Explains What Went Wrong
Disclaimer: The following story is a fictional case study inspired by real social engineering and WhatsApp scam techniques reported in Nigeria. It is written for cybersecurity education and awareness.
One Message. One Decision. Almost ₦2 Million Gone.
It was a quiet Wednesday evening.
Around 7:45 p.m., Chinedu finally arrived home after spending hours in traffic. Like many professionals, he was exhausted. He dropped his laptop bag beside the sofa, loosened his tie, and reached for a bottle of water.
Just as he was about to switch off his phone for the evening, a WhatsApp notification appeared.
The message came from someone he trusted completely—his older brother.
“Bro, I need your help urgently. I’m in a meeting and can’t access my banking app. Please send ₦2 million to this supplier before 8 p.m. I’ll refund you first thing tomorrow morning.”
Nothing about the message seemed suspicious.
The profile picture was correct.
The contact name was correct.
Even the writing style looked familiar.
Without hesitation, Chinedu replied.
“No problem. Send the account details.”
Within seconds, the account number arrived.
He opened his banking application.
Entered the account number.
Typed ₦2,000,000.
His finger hovered over the Transfer button.
Everything looked perfectly normal.
Or so he thought.
The Detail That Saved Him
Just before confirming the transfer, something caught his attention.
His brother always ended conversations with the words:
“Thanks, my guy. God bless you.”
This time…
Nothing.
Instead, another message appeared.
“Please hurry. The supplier is waiting.”
That single sentence made Chinedu pause.
His brother was never impatient.
He never pressured people.
And whenever he needed financial help, he always picked up the phone instead of relying only on WhatsApp messages.
Something didn’t feel right.
Rather than completing the transfer, Chinedu decided to call him.
The phone rang.
No answer.
He called again.
Still nothing.
Seconds later, another WhatsApp message arrived.
“I’m still inside the meeting. Please don’t call me.”
That was the moment his instincts took over.
Instead of sending the money, he called his brother’s wife.
She answered immediately.
Before Chinedu could even finish explaining, she interrupted him.
“Wait… what meeting? He’s sitting right here beside me watching football.”
The room suddenly felt silent.
His heart started racing.
Someone else was sending those WhatsApp messages.
Someone had taken control of his brother’s account.
The supplier didn’t exist.
The emergency wasn’t real.
And the ₦2 million would have gone directly into a criminal’s account.
He looked down at his phone.
His thumb was still resting on the Transfer button.
Just one tap separated him from becoming another victim of social engineering.
A Scam That Happens Every Day
While this story is fictional, the techniques used are based on real scams reported around the world.
Cybercriminals are no longer relying on obvious spelling mistakes or poorly written messages.
Today’s attackers understand psychology.
They know how to create urgency.
They know how to imitate people you trust.
And they know that when money and family are involved, many people react emotionally before verifying the facts.
That is exactly what makes social engineering one of the most dangerous forms of cybercrime today.
(Continue with sections explaining how the scam worked, how attackers compromise messaging accounts, warning signs, prevention tips, FAQs, and a conclusion.)
About the Author
Jackson Godwin is a Cybersecurity Consultant specializing in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
Through JacksonTechnology.com.ng, Jackson publishes practical cybersecurity tutorials, penetration testing guides, compliance resources, and security awareness articles that help individuals and organizations defend against modern cyber threats.
His mission is simple: make cybersecurity understandable, practical, and accessible to everyone.







