WhatsApp Impersonation Scams Targeting Nigerian Businesses
WhatsApp is where most Nigerian small businesses actually operate, orders come through it, customer questions get answered on it, staff coordinate through it, and suppliers are contacted through it, often more than through any formal website or app. That central role is exactly why it has become a favoured tool for a specific, recurring kind of scam aimed at business owners: impersonation, where a fraudster does not hack your account at all, but instead copies enough of its surface, your profile photo, your display name, sometimes even your actual phone number's caller ID, to convincingly pretend to be you, or to pretend to be someone you already trust.
The two directions this scam actually runs in
It is worth understanding that WhatsApp impersonation against a business owner runs in two genuinely different directions, and the defence for each is different. The first direction targets your customers or suppliers: a fraudster creates a new WhatsApp account, saves your business's actual profile photo and display name, often copied directly and publicly from your real business profile, and messages your existing customers or contacts, sometimes using a number one digit different from your real one, hoping they will not check closely, asking for a payment to a new account, or offering a deal too good to pass up. The second direction targets you or your own staff: a fraudster impersonates a trusted contact, sometimes convincingly enough to include a cloned voice note using increasingly accessible AI voice tools, asking urgently for a fund transfer, a purchase, or sensitive information, banking on the existing trust already established with that specific contact.
Why this specific scam works as well as it does
WhatsApp impersonation succeeds precisely because it exploits an established relationship rather than trying to build trust from nothing, which is a fundamentally easier task than a cold scam attempt. A customer who has ordered from you before, seeing your familiar photo and name, has little reason for immediate suspicion. A staff member who regularly receives instructions from a specific manager's number, seeing what looks like that same manager's photo and a message written in a familiar tone, is primed to comply quickly rather than question it, particularly under any manufactured urgency. The scam is not clever in a technical sense, it is effective because it borrows trust that took real time to build honestly.
Protecting your own business's identity from being cloned
Enable WhatsApp's own two-step verification, a separate six-digit PIN required to register your number on a new device, which meaningfully raises the difficulty of someone genuinely taking over your real account, as opposed to merely cloning its visible appearance on a separate, new one. Apply for WhatsApp Business verification if your business is eligible, the small verified badge, while not available to every business and not a complete solution on its own, gives genuine customers one additional, real signal to check against an impersonator's unverified copy. Post clearly, on your actual website and social pages, what your real, verified business number is, so a customer who receives a message from an unfamiliar or slightly different number has a straightforward way to cross-check it against a source the impersonator cannot also control.
Protecting your customers from being scammed by someone pretending to be you
Establish and clearly communicate a specific, consistent payment practice, always the same bank account, always the same payment link, never a "new" or "temporary" account announced only through a chat message, so that a customer told to send money to a different account has an immediate, obvious reason for suspicion. If you learn that your business is being impersonated, act quickly and publicly: post a clear warning on your real, verified channels, naming the specific pattern being used if you know it, since customers genuinely appreciate the warning and it directly limits how many people the impersonation successfully reaches before word spreads.
Protecting your own staff from being scammed by someone pretending to be you or a colleague
Establish a simple, specific rule for any request involving money, a purchase, or sensitive information that arrives by chat message or voice note, however urgent it sounds and however convincing the sender appears: confirm it through a second channel before acting, a direct phone call to a number you already have saved, not one provided in the suspicious message itself, or, where practical, brief in-person confirmation. This single habit defeats the overwhelming majority of impersonation attempts targeting staff, since it is specifically the speed and apparent urgency of a chat message that the scam depends on, and a short, calm verification step removes exactly that advantage.
The same pattern, wearing an email instead of a chat message
Everything in this guide applies just as directly to email, in what is more formally called business email compromise, a fraudster registering a domain or email address one character different from a genuine supplier's or colleague's, and using it to request an urgent payment or a change to invoice payment details. It succeeds for exactly the same underlying reason WhatsApp impersonation does, borrowed trust and manufactured urgency, and the same second-channel verification habit defeats it just as reliably: a phone call to a number you already had, not one provided in the suspicious email itself, before acting on any request involving money or a change to payment details, regardless of which app or inbox it arrived through.
What law enforcement can, and honestly cannot, do once this has already happened
It is worth setting realistic expectations here rather than an overly optimistic one. If money has already been sent to a fraudulent account, reporting promptly to your bank and, per our guide to the Cybercrimes Act, to the police cybercrime unit or the EFCC for financial fraud specifically, genuinely does matter and does sometimes result in funds being frozen or recovered, particularly the faster it is reported. It is not, however, a reliable guarantee, and the honest, more valuable takeaway from this entire guide is that prevention, the habits described above, costs nothing and is dramatically more reliable than recovery after the fact ever is.
A worked example: an impersonation attempt against a small business's staff
Picture a small online store's junior staff member receiving a WhatsApp message that appears to be from the store owner, complete with the owner's actual profile photo, asking urgently for a transfer to a "supplier" account to secure a time-limited stock deal, with a tone and urgency that closely matches how the real owner sometimes writes. Rather than acting immediately, as the message's urgency clearly wants, the staff member places a direct phone call to the owner's number already saved in their own phone, separate from the chat itself. The real owner, confused, confirms they sent no such message and knows nothing about any supplier deal. The impersonation attempt is caught in minutes, at the cost of one short phone call, specifically because the staff member's habit was to verify through an independent channel rather than trust the chat message alone, however convincing it looked.
Mistakes that let this scam actually succeed
Acting on any urgent money-related request received purely through chat, without a second, independent confirmation step. This single habit is the actual point of failure in nearly every successful case of this scam, far more than any technical weakness.
Not enabling WhatsApp's own two-step verification PIN. This is a free, five-minute setting that specifically raises the bar against your real account being taken over, not just visually cloned, and there is no good reason to leave it off.
Treating a familiar profile photo and name as sufficient proof of someone's identity. Both are trivially copyable from any public profile, and neither one is, on its own, meaningful evidence of who is actually sending a message.
Staying silent once you discover your business is being impersonated, out of embarrassment or uncertainty about what to say. A clear, prompt public warning through your own verified channels limits real damage far more effectively than hoping the impersonation quietly goes away on its own.
Telling a cloned account apart from a genuinely hacked one
These are two different situations that call for two different responses, and confusing them wastes exactly the time you do not have. A cloned account is a brand new WhatsApp registration that merely copies your visible photo and name; your own real account is untouched and still fully in your control, which means the fix is entirely about warning others and reporting the impersonating account to WhatsApp, not about recovering anything of your own. A genuinely hacked or taken-over account means your own real number's registration itself has been compromised, typically through a SIM swap or by someone tricking you into reading out a verification code, and you have likely lost access to your own account entirely, which calls for the account-recovery steps in our SIM swap fraud guide rather than simply reporting an impersonator. A quick way to tell which situation you are actually facing: if you can still open and use your own WhatsApp normally while the impersonation is happening elsewhere, it is a clone; if you cannot, it is a genuine takeover.
A short glossary
Impersonation: copying the visible identity, photo, name, sometimes a similar number, of a real person or business without actually controlling their real account. Two-step verification (WhatsApp): an additional PIN required to register a phone number on a new device, protecting against a genuine account takeover rather than a visual clone. Business verification badge: WhatsApp's official confirmation mark for eligible businesses, a genuine trust signal a cloned account cannot also obtain. Second-channel confirmation: verifying an unusual or urgent request through a separate, independently known communication method before acting on it.
Where this fits alongside your wider security practice
WhatsApp impersonation is one specific, high-frequency attack among several a Nigerian business owner realistically faces, alongside the SIM swap risks covered in our SIM swap fraud guide and the VTU-specific fraud patterns in our guide to how VTU business owners actually get scammed. If you are running a WhatsApp bot as part of your business on our platform, our WhatsApp bot guide and Cloud API tutorial cover the official, verified integration path this guide's protections assume you are building on, rather than an unofficial, more easily spoofed alternative.




Comments
No comments yet. Be the first to share your thoughts.