{"id":1573,"date":"2024-01-16T08:56:52","date_gmt":"2024-01-16T08:56:52","guid":{"rendered":"https:\/\/aqqute.com\/blog\/?p=1573"},"modified":"2024-01-16T08:56:52","modified_gmt":"2024-01-16T08:56:52","slug":"heightened-threat-fraudsters-pose-as-nigerian-tech-ceos-attempt-employee-email-scams","status":"publish","type":"post","link":"https:\/\/aqqute.com\/blog\/2024\/01\/16\/heightened-threat-fraudsters-pose-as-nigerian-tech-ceos-attempt-employee-email-scams\/","title":{"rendered":"Heightened Threat: Fraudsters Pose as Nigerian Tech CEOs, Attempt Employee Email Scams"},"content":{"rendered":"<p><b>Heightened Threat: Fraudsters Pose as Nigerian Tech CEOs, Attempt Employee Email Scams<\/b><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1574\" src=\"https:\/\/aqqute.wordpress.com\/wp-content\/uploads\/2024\/03\/d04e9-side-view-male-hacker-with-gloves-laptop-1536x1024-kenoye-kitoye.jpg?w=300&#038;h=200\" alt=\"\" width=\"300\" height=\"200\" \/><\/p>\n<p><span style=\"font-weight: 400\">In a worrisome trend, <\/span><a href=\"https:\/\/techpoint.africa\/\"><span style=\"font-weight: 400\">Techpoint Africa<\/span><\/a><span style=\"font-weight: 400\"> has verified three distinct incidents involving employees receiving deceptive emails impersonating their (former) CEOs. The emails, seemingly urgent in nature, requested immediate assistance in resolving overdue payments.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The content of these emails typically follows a professional tone and structure, with variations in the requested amount, promised reimbursement timeframe, and the CEO&#8217;s email signature.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">A common thread among them is the appeal for the recipient to cover an overdue payment, often expressed as follows: <\/span><b><i>&#8220;Do you have up to N1m in your personal account to cover an overdue payment for me this morning? I will make arrangement(sic) for a refund on Friday. Please advise, and I will forward the beneficiary details within the next hour.&#8221;<\/i><\/b><\/p>\n<p><span style=\"font-weight: 400\">The initial report was filed by Emmanuel Paul, Managing Editor at Techpoint Africa, who received an email posing as Adewale Yusuf, the company&#8217;s co-founder and former CEO. Immediate action was taken, notifying Yusuf about the attempted fraudulent activity.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Subsequently, two similar cases were documented on X (formerly Twitter) by Abimbola Adebakin, CEO of Advantage Health Africa, and Ikpeme Neto, CEO of WellaHealth. During a brief conversation, Adebakin confirmed that three employees reported encountering a similar email scam.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1575\" src=\"https:\/\/aqqute.wordpress.com\/wp-content\/uploads\/2024\/03\/4d401-gaf4m2exgaaqumh-kenoye-kitoye.jpg?w=276&#038;h=300\" alt=\"\" width=\"276\" height=\"300\" \/><\/p>\n<p><span style=\"font-weight: 400\">Interestingly, the scammers went to great lengths to impersonate the CEOs by creating Outlook and Hotmail accounts in their names to dispatch the deceptive emails.<\/span><\/p>\n<p><span style=\"font-weight: 400\">In one instance, when an employee requested account details for the supposed transfer, they were provided with account information in the CEO&#8217;s name, linked to OPay and Palmpay accounts. Notably, the provided phone number associated with these accounts was inactive and did not belong to the CEO.<\/span><\/p>\n<p><span style=\"font-weight: 400\">This situation raises concerns about the account opening processes within Nigeria&#8217;s expanding digital banking sector. The incident prompts questions about the efficacy of the account verification procedures employed by digital banks, Neobanks, and MFBs in the country.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The surge in fraud within the fintech space has become a growing concern for industry founders. Reports suggest that certain digital banks may have lax procedures for opening accounts, leaving potential vulnerabilities for exploitation.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Fortunately, none of the targeted employees fell victim to these scams, as they sought confirmation from their CEOs regarding the emails&#8217; authenticity.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Blessing Agbor, a cybersecurity engineer, categorizes these incidents as instances of email spoofing, specifically Business Email Compromise (BEC). This type of scam leverages familiarity and personalization to exploit victims&#8217; trust in their employers, using financial incentives and fear of repercussions to elicit favorable responses.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Agbor recommends several preventive measures, including establishing clear reporting procedures for suspicious emails, educating employees about email spoofing techniques and scam red flags, enforcing strong passwords and multi-factor authentication (MFA), and implementing host-based anti-malware software.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Heightened Threat: Fraudsters Pose as Nigerian Tech CEOs, Attempt Employee Email Scams In a worrisome trend, Techpoint Africa has verified three distinct incidents involving employees receiving deceptive emails impersonating their (former) CEOs. The emails, seemingly urgent in nature, requested immediate assistance in resolving overdue payments. The content of these emails typically follows a professional tone &hellip;<\/p>\n","protected":false},"author":1,"featured_media":1574,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology-trends-and-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/posts\/1573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/comments?post=1573"}],"version-history":[{"count":0,"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/posts\/1573\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aqqute.com\/blog\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/media?parent=1573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/categories?post=1573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aqqute.com\/blog\/wp-json\/wp\/v2\/tags?post=1573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}