Somebody will try to trick you this year: a phone call, a fake link, a voice that sounds exactly like someone you trust. This is the field guide to their fifteen moves, and the one line that beats each.
You don't need to know every trick. A handful of habits stops most of them before they start.
Every scam needs you to act now, before you think, before you check. The rush is the tell. Give it ten minutes and most of them fall apart.
A moment of hesitation can save you everything. Ask a friend, ask the bank, ask anyone. No real request ever suffers from being checked.
Not the "your account is locked" text, not the prize, not the delivery notice. Go to the site yourself. A link is the cheapest thing a scammer owns.
OTP, PIN, password, nobody real ever needs them. Not the bank, not "support," not a friend in a hurry. The moment someone asks, that's the scam.
Call back on the number you saved, not the one they gave you. Reach them on an app you already use. Never let them choose how you check.
AI can fake a voice note, even a video call. Trust the check, not the familiarity. If it sounds like someone you know asking for money, verify anyway.
Every scam is a move with a counter. Tap a card to turn it: the front is the attacker's move, the back is how you beat it.
We collected scam reports from students and the public, not to retell each story, but to find what they had in common. Eleven from the team, twelve from the public. Of those twelve public stories, five people lost money and seven saw it coming. Twenty-three stories, one clear shape.
Most reports began the same way: someone pretending to be a bank, an official, or a person the victim already knew. Trust is the door every one of them walks through.
No virus. No breached system. Every single report was a person being persuaded to act. The vulnerability was human judgement under pressure, which is exactly why policy, not software, is the defence.
Of those who avoided the scam, most had been told beforehand what it would look like, a bank officer's warning, a story from a friend. Knowing the move is the counter to the move.
Transfers, OTPs, marketplace payments, "processing fees." However the story starts, it funnels to one thing: moving value out of your reach and into theirs.
Akure, Ondo, Ogun, Ibadan, Lagos. Not "somewhere on the internet", in our own towns, to people we know, this week.
NIST SP 800-83 names four elements of malware prevention, policy, awareness, vulnerability mitigation, and threat mitigation. Policy comes first: in Stallings' words, it "provides a basis for implementing appropriate preventative countermeasures." This project owns that element.
"A security policy is a statement of what is, and what is not, allowed."
, Matt Bishop, Introduction to Computer Security (2005)
Documented rules that make prevention enforceable and assign accountability.
This projectTeaching people to recognise the tricks before they arrive.
Patching, least privilege, and hardening to shrink the attack surface.
Detection, containment, and response once something gets through.
Social engineering attacks people, not machines. No antivirus stops a person being talked into trusting the wrong thing, only knowing the move does. This policy makes that knowledge the default.
All students, staff, and contractors. Any account or device. Every channel the attacks arrive through, phone, email, WhatsApp, in person, QR codes.
Your password, OTP, and PIN are secret, nobody legitimate asks. Verify unexpected requests through a known channel. Urgency plus authority is a red flag, not a reason to rush. Don't run unknown files or plug in unknown drives. Turn on two-step verification.
Report anything suspicious to ICT the same day. Good-faith reports are never punished, that line is what makes people report instead of hiding it.
ICT owns and enforces it. HODs and deans promote it. Staff and students follow and report. One careless click can reach the whole network.
Reviewed regularly, because the tricks change. Deepfakes were on no one's list two years ago. A policy that doesn't update is already out of date.
Falling for one of these isn't foolish, it's engineered to work on smart people in a hurry. What matters is the next few minutes.
Stop replying. Send nothing more. If an account is involved, change the password from a device you trust.
Your bank's official line, or FUTA ICT, the number you already know, never the one the scammer gave you.
If your account was used, tell your contacts it's compromised so the scam doesn't jump to them next.
Reporting fast is how it gets stopped, for you and everyone after you. Good-faith reports are never punished.
This isn't only a school project. A scam can feel far off, something you read about in the news, right up until it isn't: someone close to you gets hit, an account gets taken, and because everyone is connected, you can become the next step in an attack without ever choosing to.
So guard the small things, because they are the whole game. Keep your passwords to yourself. Protect your privacy like it matters. Open links you trust, and when you don't trust one, open it somewhere that can't touch your machine. If you have to run code you didn't write, run it in a virtual machine.
None of it is hard. It's just paying attention. Let's make the web feel safe again, one careful click at a time.