October 1, 2026
A person using a smartphone, illustrating mobile-message security

Nigeria’s telecommunications regulator has warned that criminals can exploit fake mobile networks to intercept text messages and impersonate banks, raising a security concern for customers who rely on SMS for financial transactions.

The Nigerian Communications Commission’s Computer Security Incident Response Team, NCC-CSIRT, sets out the threat in advisory NCC-CSIRT-2026-010. It follows an alert to Nigerian authorities about a criminal case in the United Arab Emirates.

The advisory identifies a potential risk to Nigeria. It does not report a confirmed domestic outbreak, give a Nigerian victim count or quantify losses in the country.

According to NCC-CSIRT, the technique involves disrupting legitimate signals and using a rogue base station to draw nearby phones onto an attacker-controlled network. Criminals may then send messages posing as financial institutions or intercept communications, including one-time passwords.

The team classifies the potential damage as critical and the probability as high. Those ratings express its assessment of the threat; they should not be read as evidence that every subscriber is currently being targeted.

Its recommended response focuses on telecom infrastructure: detecting unauthorised base stations, monitoring spectrum and SMS gateways, blocking illegal transmissions and working with security agencies.

For customers, the warning matters because a familiar-looking text can become the starting point of a financial scam. Recognising a bank’s name in a message does not establish that the request is genuine.

This also places a responsibility on institutions. Subscribers cannot independently inspect the radio infrastructure around them. Effective protection therefore requires action by operators and regulators alongside sensible precautions by account holders.

The advisory concerns the telecommunications layer, so it should not be reduced to a simple instruction to install antivirus software. The wider lesson is to treat unexpected financial requests cautiously, even when they arrive through an everyday service.

General anti-phishing guidance from the UK’s National Cyber Security Centre advises people to stop contact when a message seems suspicious. It also recommends contacting a bank promptly if banking details have been disclosed to a scammer.

Ofcom’s consumer guidance similarly advises contacting an organisation through a number obtained independently from its official website, rather than using a number supplied by a suspicious caller or message.

Those principles offer a practical response for Nigerian customers too: pause before acting, verify through the bank’s established channels and avoid treating urgency as proof of authenticity. They are general precautions, rather than a guarantee against interception.

Anyone who believes an account may have been compromised should contact their bank immediately. An unexpected loss of mobile service, on its own, does not prove that a rogue network is operating; it should be assessed without jumping to conclusions.

The distinction between a warning and a documented attack is essential. Public awareness can help reduce fraud, but unsupported claims about a nationwide compromise would create anxiety without improving protection.

The next meaningful development will be evidence of detection, prevention or enforcement. Until then, the NCC notice provides an opportunity for operators, banks and customers to review how financial messages are trusted.

Read the official NCC-CSIRT advisory and use your bank’s verified contact channels if a financial message causes concern.

Leave a Reply

Your email address will not be published. Required fields are marked *