Fraudsters are increasingly turning the trusted identities of Nigerian government agencies into reusable tools for online theft, rotating fake websites, impersonating officials and exploiting One-Time Passwords (OTPs) to move money from victims’ bank accounts within minutes.
What initially appeared to be isolated scams involving fake Federal Road Safety Corps (FRSC) traffic notices is emerging as a wider pattern affecting agencies including the Nigeria Customs Service (NCS), Federal Inland Revenue Service (FIRS), police and other public institutions.
The common playbook is remarkably consistent. Fraudsters identify an agency Nigerians routinely interact with, create a convincing copy of its digital identity, send unsolicited messages that manufacture urgency and then direct victims to a fraudulent website.
The final step is often payment. Once victims enter card or banking information, the scammers exploit the genuine OTP generated by the victim’s bank, enabling unauthorised transactions before the victim fully understands what has happened.
The model allows the same infrastructure and tactics to be adapted repeatedly. A fake traffic offence can become a customs auction, tax refund, recruitment notification or another government-related claim with relatively little change to the underlying operation.
From traffic fines to bank debits
The scale of the threat became clearer in September after motorists began reporting fraudulent FRSC messages directing them to websites purporting to show traffic offences.
One of the domains identified in the campaign was frscgov.top, which the FRSC publicly disowned on September 16.
The agency said the website had no affiliation with it and directed motorists to its official website, frsc.gov.ng, and toll-free number 122.
The scam was convincing because it exploited a real-world event. On September 16, Nollywood actress Eva Ibiam received a message claiming she had incurred an FRSC traffic offence.
The message appeared plausible because she had recently been stopped by road safety officers and had her vehicle registration photographed.
She followed the link, entered her details on a website that displayed an alleged speeding violation and offered a reduced fine before making a payment.
Her bank subsequently generated a genuine OTP. Minutes later, about N364,574 was debited from her account in an international web transaction associated with a merchant in Dubai.
Comedian MC Monica, whose real name is Edeh Sylvester Chisom, experienced a similar attack after receiving a message about a supposed traffic fine.
He paid what appeared to be a N5,000 penalty, only to discover unauthorised transactions the following morning, including a web purchase debit of about N1.8 million.
The difference between the apparent value of the transaction and the eventual loss illustrates one of the most damaging features of the scheme: the initial payment request can be deliberately small while the real objective is to obtain credentials that facilitate much larger transactions.
For Abuja-based lawyer Usman A. Lanase, the same message almost produced another victim.
He received a notification claiming he had exceeded the speed limit at 92km/h and owed N5,000. He clicked the link and found a professional-looking website but stopped before completing the payment.
He later discovered that others had received the same message. ‘Thank God my lawyerly mind saved me. Innocent Nigerians have been defrauded,’ he said.
One playbook, multiple agencies
The significance of the FRSC incidents lies beyond the individual losses.
Similar techniques have been deployed using the identities of Customs and tax authorities.
Customs has repeatedly warned Nigerians about cloned auction portals and WhatsApp accounts offering seized or imported vehicles at attractive prices. Victims are typically directed to unofficial payment channels after being shown what appears to be a legitimate government auction.
Tax-related scams follow another variation of the same formula. Messages purporting to come from FIRS or state revenue authorities can claim that a recipient has an outstanding obligation, requires urgent profile verification or is eligible for a refund.
Recruitment scams using the identities of the police and other government institutions add another layer.
The subject changes, but the architecture remains largely the same: a trusted government name, a believable administrative event, an urgent request, a fraudulent digital destination and an attempt to extract money or sensitive information.
This makes government brands particularly valuable to fraudsters. A scammer does not need to build public trust from scratch. The reputation of the institution does much of that work.
The victim already recognises the agency. The alleged transaction fits an activity the agency legitimately performs. The message therefore needs only enough technical polish to bridge the gap between the real institution and the fake interaction.
The disposable website strategy
The technology behind the campaigns is also designed for rapid replacement. Several domains associated with the FRSC scam appeared within a short period. One was reportedly registered only a day before public complaints emerged, with registration details shielded and a location listed outside Nigeria.
The websites were designed to look credible, displaying alleged offence information, accepting vehicle registration details and eventually requesting payment information.
This creates a disposable infrastructure. Once an address is publicly identified, reported or blocked, another domain can be registered and deployed with the same basic website, message template and payment mechanism.
The result is a game of speed. Government agencies may successfully warn citizens about one fraudulent address, but the warning can become outdated when another domain appears.
The same principle applies across agencies. A scammer does not need a new business model for every target. It can reuse the underlying infrastructure and change the branding, message and alleged government service.
That makes the government agency itself almost a plug-in component of the fraud operation.
OTP becomes the final vulnerability
The most important part of the playbook is not necessarily the fake website itself but what happens after the victim reaches it.
The site is designed to collect information that can help initiate or facilitate a legitimate banking transaction. When the victim receives an OTP from the bank, the security mechanism can become part of the attack if the code is disclosed or relayed to the fraudster.
The transaction can then be completed while the victim is still interacting with the fake government portal.
This explains why some losses occur within minutes. The fraud does not depend entirely on stealing money directly through the fake government website. Instead, the website becomes the social-engineering layer that persuades the victim to provide the information required for a real financial transaction.
The scam therefore combines social engineering, domain impersonation and real-time transaction manipulation.
Why the model keeps working
Several structural conditions make the playbook attractive. Nigeria has millions of citizens interacting with government agencies through digital channels, while phone numbers and other personal information are widely circulated across commercial and public systems.
The cost of registering domains and distributing bulk SMS is relatively low compared with the potential return from a successful campaign.
More importantly, the fraudsters can exploit situations that citizens already expect to encounter.
A traffic offence is plausible. So is a tax notice, customs payment, recruitment update or government refund.
The fraud therefore does not ask victims to believe something extraordinary. It asks them to respond quickly to something that could reasonably happen to them.
Urgency does the rest. A warning that a fine will increase, a tax obligation will attract penalties or an offer will expire creates pressure that discourages independent verification.
A national trust problem
The consequence goes beyond the money stolen from individual victims. Repeated impersonation risks weakening public confidence in legitimate government digital services.
Citizens who receive genuine government messages may become reluctant to click legitimate links. Others may ignore important notices because they have learned that official-looking messages can be fraudulent.
The government agencies themselves consequently face a trust problem: every successful impersonation campaign potentially makes legitimate digital communication less effective.
Official responses have largely focused on public warnings.
The FRSC has urged citizens to ‘STOP. VERIFY. REPORT’, while its Corps Marshal, Shehu Mohammed, directed nationwide sensitisation following the latest incidents.
Customs has similarly warned that legitimate auctions are conducted through its official channels and that officers do not solicit payments through private messaging platforms.
Tax authorities and the police have also issued warnings over fraudulent messages and websites using their identities. But individual takedowns cannot eliminate a system built around replacement.
From agency-specific scams to a shared fraud economy
The evidence does not establish that every campaign against FRSC, Customs, FIRS and other agencies is being operated by one organisation.
What it reveals is a common and increasingly reusable fraud model. The same operational logic can be applied to virtually any institution with a strong public identity and regular interaction with citizens.
That changes the nature of the problem. It is no longer simply about identifying a fraudulent FRSC website or shutting down a fake Customs auction page. It is about disrupting an ecosystem in which domains, messages, impersonation techniques and payment tactics can be repeatedly repurposed.
Banks and telecommunications companies therefore have roles alongside government agencies. Detection of unusual transactions, suspicious OTP activity, bulk messaging patterns and newly registered domains could help identify campaigns earlier.
What Nigerians must do to stay ahead
Jide Awe, tech expert therefore urged Nigerians to treat unsolicited messages demanding immediate payment, personal information or OTPs with caution, even when they appear to come from a government agency.
‘Citizens should independently type the agency’s official website into their browser or use verified contact channels rather than clicking links embedded in SMS messages, WhatsApp chats or emails,’ Awe advised.
They should also never share bank OTPs, PINs or card security details with anyone claiming to represent a government institution, Awe appealed, adding that, ‘Where a message appears suspicious, recipients should preserve the SMS, website address and transaction details and report them to the relevant agency, their bank and appropriate law-enforcement or cybercrime authorities.’
The emerging lesson from the latest scams is that fraudsters are not merely cloning government websites. They are cloning the trust Nigerians place in government institutions and reusing that trust across different scams.