← Back to list

You're not cautious enough.

Phishing is evolving beyond emails. Here's what you can do about it.

Mujidat Dada · 2025-05-23 11:02 · 1 claps · 3.9 min read
#cybersecurity #user-awareness #phishing #whatsapp #threat-detection
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

You're not cautious enough.

Phishing is evolving beyond emails. Here's what you can do about it.

A few months back, someone very dear to me received a WhatsApp message saying her account had been locked. To “regain access”, she was asked to enter a code; one of those 6-digit authentication codes. Thinking that it was official, she followed through. That one action gave the scammer full control of her WhatsApp account. He locked her out and started sending urgent messages to her contacts, including me, asking for money. In my case, it was money to settle hospital bills. Some sent it, unfortunately, some others called her to confirm. It was scary. it was real. And it wasn't even an email. It happened to many other people, but this was close to home. It's way more common in this part of the world, and yeah, it’s a real issue.

Phishing Has Evolved

When people hear the word “phishing”, they often think of shady-looking emails. However, phishing is no longer limited to inboxes. it now lives in your WhatsApp chats, Instagram DMs, and even fake customer support calls. Hackers adapt and are getting smarter, more personal, and more convincing.

Cybersecurity is way more than a tech issue. It’s a human issue. The platforms can only do so much to protect their users. Users have to be aware. It’s no surprise that people are often the weakest link in cybersecurity. Tools can only do so much. User awareness is everything. It shouldn't just be one item to tick off the checklist. It should be intentional.

The Data Doesn't Lie

The stats don’t lie. According to the Anti-Phishing Working Group, in an article written by Gary Smith, over 4.7 million phishing attacks were recorded in 2022, a number that has been increasing by over 150% annually since 2019. Additionally, 84% of organizations faced at least one phishing attempt in the same year. The numbers paint a disturbing reality: phishing is not just rising, it’s evolving. Some platforms like WhatsApp and Telegram are now being exploited for direct messaging-based phishing attacks, especially in regions with high mobile usage like Nigeria.

Bill Toulas, a tech writer, in his article “*CoGUI phishing platform sent 580 million emails to steal credentials*”, explains that:

The best way to mitigate phishing risks is never to act with haste when receiving emails requesting urgent action, and always log in to the claimed platform independently instead of following embedded links.

That last part is critical. Phishing thrives on urgency. The attacker wants you to panic. You might panic, but at the same time be cautious; it’s never that urgent. They want you to act fast based on that, to click first and think later.

What Does The Attacker Want?

Over the years, one thing has become clear to me about phishing: the attacker always has a goal: to steal from you. It could be your:

  • Data
  • Identity (to carry out malicious acts)
  • Money.

So, it’s not just your finances at risk, but your reputation too. And it doesn’t matter whether you’re an employee, a top executive, a student, or just a random person minding their business; anyone can be a target.

This brings me to the different types of phishing you should know about. There are over 15 known types of phishing, but here are the ones everyday Nigerians are most likely to run into, from your email inbox to WhatsApp and even Google search.

Email Phishing A fake email from “UBA” notifies you that your account will be deactivated. You click a link, enter your details, and just like that, your money is wiped out. Smishing (SMS Phishing) A message from “NIPOST” informs you that your parcel is being held until you pay a small fee. The link takes you to a fake site that collects your card details. Vishing (Voice Phishing) Someone calls, claiming to be from your bank’s fraud unit. They say your BVN has been compromised and ask for your OTP “to block the hacker.” WhatsApp Phishing / Social Engineering You receive a message: “Your WhatsApp will be locked. Reply with your code to keep it active.” After you respond, the scammer gains control and begins soliciting money from your contacts. Angler Phishing (Fake Support on Social Media) You tweet at your Bank. A fake support handle slides into your DMs asking for your card or BVN to “fix it fast.” Evil Twin WiFi You connect to “Free WiFi” in a café or park. Behind the scenes, a scammer is capturing your passwords. Search Engine Phishing You Google “JAMB result” or “WAEC scratch card” and click a top result — but it’s a cloned site asking you to pay and submit your details.

Want to know more? **Here’s a full list of phishing types explained in simple terms.**

How to Protect Yourself

  • Always confirm links by visiting the official site directly. Do not trust search results with sponsored tags.
  • Don't trust texts with links, even from known contacts, especially if they create urgency.
  • No bank will ever ask you for your OTP over the phone.
  • Avoid logging into sensitive accounts on public WiFi. It is recommended that you enable a Virtual Private Network, popularly known as a VPN, if you have to use public WiFi.
  • Apply the **Zero Trust Policy. Just like I do, don’t assume safety just because someone sounds nice, looks real, or has mutual friends. Verify before you trust.**

You don't need a cybersecurity degree to avoid getting phished. You just need awareness, a bit of skepticism, and the courage to slow down and verify, yes, that’s the word. Slow down, then verify. Be cautious.

Have you or someone you know fallen victim to a phishing scam before?

Share your story; it could be useful. Let's watch our backs and educate more people.


메타데이터
post_id
2bb2f5edd5e9
slug
youre-not-cautious-enough-2bb2f5edd5e9
url
https://medium.com/@mujidatdada/youre-not-cautious-enough-2bb2f5edd5e9
canonical_url
https://medium.com/@mujidatdada/youre-not-cautious-enough-2bb2f5edd5e9
author_url
https://medium.com/@mujidatdada
status
ok
fetched_at
2026-08-29 19:58:42