Most people who lose money to fake banking websites were not careless. They were in a hurry. They followed a link from what looked like an official message. They saw the padlock. The site looked perfect. They typed their details and went about their day. The fraud happened hours later, sometimes days later, when they were completely unprepared.
The gap between "this looks right" and "this is right" is exactly where banking fraud lives. This checklist closes that gap in under sixty seconds.
One minute of checking before you log in is worth more than any amount of reporting after you have been defrauded.
Step 1: Did You Navigate Here Yourself?
This is the most important question on the list. Before anything else, ask: did you type this address yourself, click your own saved bookmark, or did you arrive here by following a link from an email, SMS, WhatsApp message, or search engine result?
If you followed a link — close the tab. Open a new one. Type your bank's address directly or use a bookmark you saved yourself. This single step eliminates the vast majority of phishing attacks before they can do any damage. Fraudsters cannot intercept you if you never follow their links.
Step 2: Read the Address Bar — All of It
Look at the full web address in your browser's address bar before you type a single character. Find your bank's actual name in the address. It must appear immediately before the first dot that leads to .com, .ng, or whatever the extension is.
Check for: extra words added around the bank name (gtb-secure.com, zenithbank-verify.ng), subtle letter substitutions (firstbannk.com, 1stbank.com), hyphens inserted anywhere in the address, or a long address where your bank's name appears in the middle rather than at the end before the slash (firstbank.com.secure-login.net — here the real domain is secure-login.net, not firstbank.com).
If anything about the address looks different from what you have seen before, do not proceed. Close the tab and type the address yourself from scratch.
Step 3: Do Not Trust the Padlock Alone
The padlock icon and HTTPS in your browser address bar mean the connection is encrypted. They do not mean the website belongs to your bank. Fraudsters obtain free HTTPS certificates in under five minutes. A fake banking site can have a padlock just as easily as the real one.
The padlock confirms the connection is secure. It does not confirm the destination is legitimate. Use it as one signal among several — never as the final confirmation.
Step 4: Check How You Received This Link
If you arrived at this login page through any of the following, treat it as suspicious until proven otherwise: an email claiming your account needs verification, an SMS warning of suspicious activity, a WhatsApp message from any source, a search engine advertisement (the results marked "Sponsored" at the top), or a social media post linking to a bank security alert.
Legitimate banks do not require you to verify your account through emailed links. They do not send SMS messages with login links. If the message creates urgency — "your account will be suspended," "verify within 24 hours," "unusual activity detected" — that urgency is a tool designed to stop you from thinking. Slow down exactly when the message is telling you to hurry.
Step 5: Notice What the Page Is Asking For
A genuine bank login page asks for your username or account number and your password or PIN. That is it. Be alert to any login page that asks for more than this combination before you have initiated a transaction.
Red flags to watch for immediately: a page requesting your full debit card number, expiry date, and CVV on the login screen; a page asking you to "confirm your PIN" or "re-enter your password for security reasons" before you have done anything; a page requesting your NIN, BVN, or date of birth as part of the login process rather than during initial account setup. Real bank login pages do not need this information at login. Fake ones collect it because it has value.
Step 6: Watch the Behaviour After You Log In
A real bank takes you to your account dashboard with your actual balance, your recent transactions, and your name displayed correctly. Watch for: a dashboard that loads slowly or never fully loads; a page that immediately asks you to "complete your profile" or "verify your identity" with card details right after login; an error message asking you to try again after you have entered your details; a session that expires unusually quickly and sends you back to the login page.
The silent redirect attack — where a fake site captures your details and immediately forwards you to the real bank so you end up logged in — is the hardest to detect because it works perfectly. If you ever notice a brief loading delay between entering your credentials and landing on what appears to be your real account, that gap is worth paying attention to. Check your transaction history immediately for any activity you did not initiate.
Step 7: Trust Your Own Reaction
If at any point during a banking session something feels slightly off — the page loaded differently than usual, a button was in the wrong place, the font looked slightly different, the wording on a confirmation screen was unusual — those instincts are worth acting on. Close the session. Open a new browser tab. Navigate to your bank directly. Log in again.
You lose thirty seconds. Fraudsters lose their window entirely.
Keep These Three Things Current
Save your bank's correct web address as a bookmark right now — before you need it in a hurry. Save your bank's official customer service number in your phone contacts so you never need to search for it during an emergency. Know your bank's official app name in the App Store or Play Store so you never download an impersonator.
These three things take two minutes to set up and are worth more than any security feature your bank can build, because they protect the moment before you even reach the bank's systems.
THE BEST SECURITY IS THE HABIT YOU PRACTICE BEFORE ANYTHING GOES WRONG — NOT THE CALL YOU MAKE AFTER.
What to Do If Something Already Went Wrong
If you suspect you entered your details on a fake site: call your bank's fraud line immediately using the number on the back of your card or from their official website — not from any number in the suspicious message. Ask for an immediate account freeze. Change your internet banking password and transaction PIN from a device you trust. Report to the EFCC at efcc.gov.ng or call their hotline, and report to NITDA at nitda.gov.ng.
Do not wait to see if anything happens. The fastest reported fraud cases are also the ones with the best recovery outcomes.
Platforms like browncode.name.ng will keep publishing practical security guides — because the most effective protection is always awareness before an attack, never damage control after.
Get new Security & Fraud alerts
One email when a new security & fraud article like this one goes live. No spam, unsubscribe anytime.

