Types of Cyber Threats
Know Your Enemy
Defending well starts with understanding how attacks work. This lesson covers the four threat types you will meet most often: phishing, social engineering, malware, and ransomware. We will use scenarios that are typical of what people and businesses face in Nigeria and around the world. The scenarios are illustrative composites, not reports of specific named incidents.
Phishing
Phishing is a fraudulent message that pretends to be from a trusted source to trick you into clicking a link, opening a file, or handing over information.
Scenario: The fake Access Bank SMS
"Dear Customer, your Access Bank account will be deactivated today. Verify your BVN now: accessbank-secure-verify.com/login"
This is a Nigerian example, but the same trick is used everywhere. A UK customer might see "Your Barclays account has been suspended, verify your details at barclays-secure-login.co", and a US customer might see the same with Chase or Bank of America.
Why it works:
- Urgency: "deactivated today" pushes you to act without thinking.
- Authority: It uses a bank name you trust.
- Look-alike link: The real domain is
accessbankplc.com(oraccessbankplc.com/ng).accessbank-secure-verify.comis a completely different website. - Data request: Banks do not ask you to "verify" BVN, PIN, or OTP through a link in a text message.
Types of phishing
| Type | Channel |
|---|---|
| Email phishing | Mass emails to many people |
| Spear phishing | Targeted email to one person, using their real details |
| Smishing | SMS phishing |
| Vishing | Voice calls ("I am calling from your bank's fraud unit") |
| Whaling | Targeting executives |
How to spot phishing
- Check the sender address, not just the display name.
- Hover over links before clicking; look at the real domain.
- Be suspicious of urgency, threats, and prizes.
- Watch for spelling and formatting oddities.
- Never share OTPs, PINs, or passwords. No genuine bank staff member will ask for them.
Social Engineering
Social engineering manipulates people into breaking security procedures. Technology is bypassed by targeting human trust.
Scenario: The SIM swap
A fraudster collects your name, date of birth, and phone number from social media. They walk into a telco outlet, or call, posing as you with a "lost phone", and ask for your number to be moved to a new SIM. Once done, your phone loses signal and the attacker receives your OTPs. A single persuasive conversation and one careless verification step is all it takes.
Scenario: Business email compromise (BEC)
A finance officer at a mid-sized company (in Lagos, Manchester, or Chicago; the trick is identical) receives an email that appears to be from the managing director, who is travelling:
"I need you to process an urgent payment to a new vendor today. Keep this confidential until I return."
The email address is one letter off from the real one. The finance officer complies. The money leaves the company and is quickly moved on.
BEC succeeds because it uses authority, urgency, and secrecy. Defences include: verifying payment changes by phone using a known number, requiring two approvers, and delaying first-time payments.
Scenario: The fake credit alert
A buyer pays a trader with a screenshot of a transfer or a forged SMS alert. The trader hands over the goods before checking the actual account balance. Always confirm payments in your bank app or official statement, never from a screenshot or an SMS alone.
Other social engineering tactics
- Pretexting: Inventing a believable story ("I am from IT support, I need your password").
- Baiting: Leaving infected USB drives or offering free downloads.
- Tailgating: Following an employee into a secure building.
Malware
Malware (malicious software) is code designed to harm, spy, or take control.
| Type | What it does |
|---|---|
| Virus | Attaches to files and spreads when they are shared |
| Worm | Spreads across networks by itself |
| Trojan | Looks legitimate (a cracked app, a "free" tool) but hides malicious code |
| Spyware | Secretly records activity and steals data |
| Keylogger | Records what you type, including passwords |
| Banking trojan | Steals banking credentials, often by overlaying fake login screens on real apps |
| Botnet | A network of infected devices controlled by an attacker |
How malware arrives
- Email attachments (fake invoices, "CV" files)
- Pirated software and cracked games
- Malicious apps installed from outside official stores
- Links in WhatsApp forwards and SMS
Ransomware
Ransomware encrypts a victim's files and demands payment for the decryption key. Modern groups also steal data first and threaten to publish it, a tactic called double extortion.
The typical chain
- A phishing email delivers a malicious attachment, or an exposed remote-access service is exploited.
- The attacker moves through the network and gains admin access.
- Backups are found and deleted.
- Files are encrypted and a ransom note appears.
Why it hurts
- Hospitals, schools, and businesses lose access to critical systems (availability).
- Stolen data can be leaked (confidentiality).
- Paying does not guarantee recovery and funds further crime.
Defences
- Offline, tested backups (the single most important control)
- Patching and updates
- Email filtering and staff awareness training
- Limiting admin privileges
Comparing the Threats
| Threat | Targets | Main weakness exploited |
|---|---|---|
| Phishing | Individuals and staff | Trust and urgency |
| Social engineering | People and processes | Weak verification |
| Malware | Devices | Unpatched software, unsafe downloads |
| Ransomware | Organisations | Poor backups, weak access control |
Notice that the first two rely on people. That is why awareness matters as much as any firewall.
Try It Yourself
The editor contains a threat classifier. Read each real-world style message and decide which category it belongs to. Then check your answer.
Try it yourself
Key Takeaways
- Phishing tricks you into revealing information through fake messages; check the real domain, not the display name.
- Social engineering (SIM swaps, BEC, fake alerts) targets human trust and weak verification.
- Malware includes viruses, trojans, spyware, and keyloggers, and often arrives through pirated software or attachments.
- Ransomware encrypts files and increasingly steals data too; offline backups are the best defence.
- Always verify urgent requests through a separate, trusted channel.
Quick Quiz
1.Which detail in this SMS is the biggest red flag? "Your Access Bank account will be deactivated today. Verify your BVN at accessbank-secure-verify.com"
2.A finance officer gets an email from the 'MD' asking for an urgent, confidential payment to a new vendor. What is the best response?
3.A trader receives an SMS 'credit alert' from a buyer. What should they do before handing over goods?
4.What is the single most important defence against ransomware?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx