Almost Got Got
A field guide to social engineeringCPE 510 Β· FUTA

Almost
Got Got

Somebody will try to trick you this year: a phone call, a fake link, a voice that sounds exactly like someone you trust. This is the field guide to their fifteen moves, and the one line that beats each.

00

Contents

Fifteen plays
01

First, the habits

Beats almost everything

You don't need to know every trick. A handful of habits stops most of them before they start.

01

Slow down. Urgency is the weapon.

Every scam needs you to act now, before you think, before you check. The rush is the tell. Give it ten minutes and most of them fall apart.

02

If you're not sure, ask someone.

A moment of hesitation can save you everything. Ask a friend, ask the bank, ask anyone. No real request ever suffers from being checked.

03

Don't tap links you didn't expect.

Not the "your account is locked" text, not the prize, not the delivery notice. Go to the site yourself. A link is the cheapest thing a scammer owns.

04

Your codes and passwords are yours alone.

OTP, PIN, password, nobody real ever needs them. Not the bank, not "support," not a friend in a hurry. The moment someone asks, that's the scam.

05

Verify on a channel you already trust.

Call back on the number you saved, not the one they gave you. Reach them on an app you already use. Never let them choose how you check.

06

A face or a voice is no longer proof.

AI can fake a voice note, even a video call. Trust the check, not the familiarity. If it sounds like someone you know asking for money, verify anyway.

02

The plays

Move & counter

Every scam is a move with a counter. Tap a card to turn it: the front is the attacker's move, the back is how you beat it.

03

The pattern

From the survey

We collected scam reports from students and the public, not to retell each story, but to find what they had in common. Eleven from the team, twelve from the public. Of those twelve public stories, five people lost money and seven saw it coming. Twenty-three stories, one clear shape.

23
Stories gathered
11
From the team
12
From the public
5
Towns & cities
i

Impersonation leads

Most reports began the same way: someone pretending to be a bank, an official, or a person the victim already knew. Trust is the door every one of them walks through.

ii

Not one was a "hack"

No virus. No breached system. Every single report was a person being persuaded to act. The vulnerability was human judgement under pressure, which is exactly why policy, not software, is the defence.

iii

Warning is what worked

Of those who avoided the scam, most had been told beforehand what it would look like, a bank officer's warning, a story from a friend. Knowing the move is the counter to the move.

iv

The ask is always money or a code

Transfers, OTPs, marketplace payments, "processing fees." However the story starts, it funnels to one thing: moving value out of your reach and into theirs.

v

It's happening here

Akure, Ondo, Ogun, Ibadan, Lagos. Not "somewhere on the internet", in our own towns, to people we know, this week.

04

The policy

NIST SP 800-83

NIST SP 800-83 names four elements of malware prevention, policy, awareness, vulnerability mitigation, and threat mitigation. Policy comes first: in Stallings' words, it "provides a basis for implementing appropriate preventative countermeasures." This project owns that element.

"A security policy is a statement of what is, and what is not, allowed."

, Matt Bishop, Introduction to Computer Security (2005)
01

Policy

Documented rules that make prevention enforceable and assign accountability.

This project
02

Awareness

Teaching people to recognise the tricks before they arrive.

03

Vulnerability mitigation

Patching, least privilege, and hardening to shrink the attack surface.

04

Threat mitigation

Detection, containment, and response once something gets through.

01 Β· Purpose

People are the target

Social engineering attacks people, not machines. No antivirus stops a person being talked into trusting the wrong thing, only knowing the move does. This policy makes that knowledge the default.

02 Β· Scope

Everyone, every channel

All students, staff, and contractors. Any account or device. Every channel the attacks arrive through, phone, email, WhatsApp, in person, QR codes.

03 Β· The rules

Five that hold

Your password, OTP, and PIN are secret, nobody legitimate asks. Verify unexpected requests through a known channel. Urgency plus authority is a red flag, not a reason to rush. Don't run unknown files or plug in unknown drives. Turn on two-step verification.

04 Β· Reporting

Tell someone the same day

Report anything suspicious to ICT the same day. Good-faith reports are never punished, that line is what makes people report instead of hiding it.

05 Β· Roles

Shared responsibility

ICT owns and enforces it. HODs and deans promote it. Staff and students follow and report. One careless click can reach the whole network.

06 Β· Review

Kept current

Reviewed regularly, because the tricks change. Deepfakes were on no one's list two years ago. A policy that doesn't update is already out of date.

05

If it happens

First minutes

Falling for one of these isn't foolish, it's engineered to work on smart people in a hurry. What matters is the next few minutes.

Step 01

Cut it off

Stop replying. Send nothing more. If an account is involved, change the password from a device you trust.

Step 02

Call the real people

Your bank's official line, or FUTA ICT, the number you already know, never the one the scammer gave you.

Step 03

Warn your circle

If your account was used, tell your contacts it's compromised so the scam doesn't jump to them next.

Step 04

Report it, no shame

Reporting fast is how it gets stopped, for you and everyone after you. Good-faith reports are never punished.

06

Sources

Grounding
Framework
NIST SP 800-83, Guide to Malware Incident Prevention and Handling"SP 800-83 lists four main elements of prevention: policy, awareness, vulnerability mitigation, and threat mitigation." (as cited in Stallings, p.360)
Textbook
William Stallings, Network Security Essentials: Applications and Standards, 6th ed.Pearson, 2017. Β§10.10 "Malware Countermeasure Approaches," pp.360–361. Definitions of malware (p.338) and social engineering (p.353).
Textbook
Matt Bishop, Introduction to Computer SecurityAddison-Wesley, 2005. Security policy defined (p.7); social engineering and the human factor (p.19).
Case
The Arup deepfake fraud, 2024A $25m loss to an AI-generated video call. Reported by CNN, May 2024.
Case
NDDC fake-scholarship warning, 2025Reported by The PUNCH.
Survey
Almost Got Got scam survey, 202623 stories collected (11 from the team, 12 from the public); used to identify the pattern, not quoted individually.
β€”

This one's on all of us

This isn't only a school project. A scam can feel far off, something you read about in the news, right up until it isn't: someone close to you gets hit, an account gets taken, and because everyone is connected, you can become the next step in an attack without ever choosing to.

So guard the small things, because they are the whole game. Keep your passwords to yourself. Protect your privacy like it matters. Open links you trust, and when you don't trust one, open it somewhere that can't touch your machine. If you have to run code you didn't write, run it in a virtual machine.

None of it is hard. It's just paying attention. Let's make the web feel safe again, one careful click at a time.