Somebody in your business received an email on Tuesday morning that looked exactly like a message from their bank. It had the right logo, the right greeting, the right warning about a failed transfer, and a link to a page that was pixel-perfect. They tapped it, typed their details, and within the hour money was moving. This is not a story about a careless employee. It is the ordinary shape of a modern compromise, and the reason email security sits at the top of this list rather than the firewall underneath it.
Why email security starts with the inbox
Not because email is where the money is. Because email is where the reset link lives, and because inbox security is the cheapest security win available. Your bank account, your hosting, your registrar, your social page and your monitoring portal can all be recovered from an email address, and an email address is a username with a password, not a destination of its own. Take the inbox and you have a keyring. Password security covers the second lock; this is about not handing over the first.
There is a commercial point too. A business that takes customer details, quotes and invoices by email has a single point of failure that antivirus software does not address. CISA frames it plainly: criminals use phishing to steal credentials, reach business accounts and install the malware that locks a system and demands payment. The chain almost always starts here, which is why the attack chain matters.
The anatomy of a phishing email
Modern phishing is not badly spelt or badly designed any more. A competent attacker can clone your bank’s login page convincingly in under an hour and send it to forty people at once, so the tells that worked in 2015 are unreliable. The structural tells are not.
| Signal | What to look at | Why it betrays the sender |
|---|---|---|
| Where the link really goes | Hover or long-press to preview the address before you tap | The visible text says the bank’s name; the destination is an unrelated domain with a similar name |
| Where the reply goes | Full address of the sender, not the display name | A display name of Accounts Team over a free webmail address |
| Urgency and threats | Any message that demands action within a short window | Purpose-built to stop you checking, and it works on everybody |
| Unexpected attachments | Files you were not expecting, especially archives and documents | The lure, not the payload; something has to run for code to arrive |
| Context | Did you initiate this? Payment request, invoice, quotation, quotation approval | A real thread can be hijacked, so check on a known number rather than by replying |
| Generic or odd details | Greetings naming nobody, mixed currencies, impossible claims | Less reliable now, but a free signal when it appears |
Two techniques deserve particular attention because they defeat habit. The first is thread hijacking, where the attacker replies inside a genuine conversation you are already having, so the message looks like business as usual rather than an intrusion. The second is consent phishing: the link opens a genuine, real permission screen from a real provider, and the damage is done when the user approves access rather than when they enter a password. The FBI’s IC3 has warned about exactly this pattern, noting that it bypasses both passwords and multifactor authentication because the user hands over neither. The FTC’s consumer guidance on phishing is a good short reference to give staff.
The checks that actually catch them
Reading the message is a last line of defence. The durable defences are structural, and they are the practical half of email security because they work when the person is tired, rushed or reading on a phone in poor light.
Stop the reply-to trap
When something looks urgent, do not respond to the message. Open your bank app, or call the number on the back of your card, and check. A refund scam that works because you replied to the email that raised it is a self-inflicted wound. The same rule covers staff: a supplier changing bank details should be verified on a number you already had, not the one in the new message. That one habit removes a large category of business email compromise and costs nothing but the decision to do it.
Separate accounts and separate devices. The cheapest control available to a small Nigerian business is separating your personal phone from your work phone. Opening a bank app on a handset used for browsing, installers and dodgy links is where a compromised session becomes a drained account. If separation is not possible, keep the banking app apart from the browser profile that does financial work. Online banking security sets out the rest.
Turn on multifactor authentication everywhere
Not just on email. On the registrar, the hosting panel, the monitoring portal and every social account. The registrar matters more than people expect: whoever controls it can redirect a domain, and a redirected domain harvests credentials that look entirely legitimate. What an SSL certificate proves and does not prove explains why a padlock will not save you from that, and locking down social and administrative accounts covers the rest.
The forwarding rule attackers leave behind
This is the part most people never discover, and it is worth knowing even if nothing has gone wrong. After an attacker gets into a mailbox they do not just read. They add a rule that silently copies every message to an address they control, and mark existing mail as read so you never notice the gap. Nothing changes on the screen. A Lagos trader whose supplier confirmations had been quietly intercepted for two months could not tell from the inbox alone.
What gives it away is a rule you did not create, a forwarding address that is not yours, and mail vanishing from other devices because the attacker set server-side rules. The phishing reference material describes how this phase works. The habit that catches it is simple: once a quarter, open the mail settings, read the rules and forwarding addresses, and remove anything unrecognised. Do it the day a provider changes their settings, which is when a hostile administrator can add one.
What to do in the first hour
If you have clicked and entered a password, or suspect a mailbox is compromised, the order matters more than the speed. Change the password from a device you trust, not from the compromised one. Then revoke active sessions, because changing a password alone does not end a session an attacker is already holding. Then change that same password, or a close variant, everywhere else it was used, starting with the registrar and the hosting panel. Then enable multifactor authentication. Then tell the bank if financial details were involved, and tell affected customers if their data was in the mailbox.
Two Nigerian realities are worth stating. First, reporting matters more than people assume: the country’s cybercrime legislation places a duty on institutions operating networks and computer systems to report incidents, and silence makes it harder for anyone to help you. The UN Office on Drugs and Crime assessment of cybercrime in Nigeria sets out the framework. Second, a compromised mailbox is a business continuity event as much as a security one, the argument in ransomware preparation for small businesses.
Frequently asked questions
How do I know if an email is really from my bank?
Do not decide from the message. Close it, open the banking app yourself, or read the number off the back of your card and call. A genuine bank will never ask you to move to a link, will never ask for your full PIN, will never ask you to act on an OTP code, and will never create urgency to stop you checking. No bank behaves that way, so a message claiming to be your bank and behaving that way is a fraud attempt regardless of how official it looks.
Should I use an authenticator app or SMS codes?
An authenticator app, clearly. CISA’s phishing-resistant multifactor authentication fact sheet describes why: SMS codes can be phished, intercepted through signalling weaknesses and stolen through SIM swaps, so they are a last resort. If your provider supports passkeys or a hardware security key, that is stronger still, because the credential is tied to the real site and cannot be replayed from a lookalike page.
Is it safe to open an unexpected attachment?
No, and even after checking treat it as a risk. Modern lures are documents, spreadsheets, archive files and PDFs rather than executables, because those get through mail filters. If a message you did not expect carries a file, verify the sender on a channel you already trust. If you have already opened it, disconnect from the network rather than shutting down, so the session can be examined, and treat the machine as compromised until somebody has checked it.
How do I train staff who ignore security advice?
Train on their own inbox. Send a mock message to the whole company, explain the three tells it contained, and let people react in a low-stakes setting. Repeat it quarterly, and reward whoever reports something real rather than whoever thinks they are untouchable. The CISA small business teaching guidance is written for organisations with no security team, which describes most businesses here.
Key Takeaways
- Email is the account that matters because everything else is recoverable from it. A stolen inbox is a stolen keyring, and good email security is mostly habit rather than product.
- Forget spelling and grammar as your primary test. Check where the link goes, where the reply goes, and whether you started the conversation at all.
- Never reply to the message that raised the alarm. Verify on a number you already had, which alone removes most invoice and refund fraud.
- Check mail forwarding rules and active sessions quarterly. A compromised inbox can hide its own theft.
- Use an authenticator app or a passkey rather than SMS codes, which can be phished, intercepted and stolen through a SIM swap. This is the single biggest security upgrade most businesses here can make this month.
- If something has already been clicked, change the password from a clean device, revoke sessions, then work outward to the registrar and the bank.
Passwords and the accounts they protect are the next layer, and password security for 2026 covers how to build them properly rather than reusing one everywhere.
Sources: FBI alert on consent phishing, which bypasses passwords and multifactor authentication; FTC guidance on recognising and avoiding phishing scams; CISA guidance on teaching employees to avoid phishing; CISA fact sheet on implementing phishing-resistant multifactor authentication; UNODC assessment of cybercrime in Nigeria and the reporting framework; phishing reference material.
0 Comments