Phishing test ideas for Nigerian offices
A generic phishing test built for a US or European office often misses the fraud patterns Nigerian staff actually encounter. Here are six simulation ideas built around local context. All of them use fictional names, companies, and domains, with no real brand or live malicious link.
1. Fake POS “wrong transfer, please refund” alert
Scenario: A text message claims a customer accidentally transferred money to the wrong account via POS and urgently requests a refund, with fake transaction details attached.
What it teaches: Staff who handle payments should verify any reversal request directly through official banking channels, never by acting on an unsolicited alert alone.
2. Vendor bank-detail change email
Scenario: An email appearing to come from a known vendor claims their bank account has changed “due to an internal audit” ahead of this month’s invoice.
What it teaches: Any change to payment details requires a phone call to a number already on file, never a reply to the email making the request.
3. WhatsApp family-emergency message
Scenario: A message from an unknown number claims to be a relative in urgent trouble, asking for money or an OTP to be shared immediately.
What it teaches: Urgency plus a request to share money or an OTP, from a number you don’t recognize, is a scam pattern regardless of how personal it feels.
4. Fake CBN or EFCC impersonation call
Scenario: A caller claims to be from a regulator, alleging a compliance issue and demanding payment or account access to “resolve” it.
What it teaches: Regulators don’t resolve compliance issues over an unsolicited phone call demanding immediate payment. This should be escalated internally, not handled on the spot.
5. Fake recruitment or loan-app message
Scenario: A message offering a surprisingly generous job opportunity or loan, asking the recipient to fill out a form with sensitive personal and banking details.
What it teaches: Unsolicited offers that are unusually generous, paired with a request for sensitive data upfront, are a common data-harvesting pattern.
6. Quishing poster in the break room
Scenario: A QR code poster placed in a common area offers a prize or survey, leading to a fake login page when scanned.
What it teaches: A QR code deserves the same scrutiny as a link: check where it leads before entering any credentials.
Running these safely
Every simulation should point only to your own tracking and landing page, never a real external destination, and should end with an immediate, specific teachable moment when someone clicks, replies, or calls back. See our full phishing simulation program for how we run these end to end, rotated through a 12-month calendar so no employee sees the same test twice in a year.