time OTP theft to drain accounts

A sophisticated phishing campaign in Nigeria is targeting citizens by mimicking official traffic violation notices to steal card details and one-time passwords (OTPs). Victims are directed to fake websites that harvest credentials in real-time, allowing attackers to execute unauthorized international transactions.
Why it matters
This highlights the growing sophistication of financial fraud in digital economies and the risks associated with real-time OTP interception.
On September 16, 2026, Nigerian actor Eva Ibiam described losing almost ₦400,000 after responding to an SMS that claimed she had a new Federal Road Safety Corps, FRSC, traffic offence. She had recently been stopped by road safety officers who photographed her plate, which made the message feel credible. The link led to a polished fake page showing a speed limit violation, a reduced fine, and a prompt for card details.
A bank alert seen by Condia shows UBA sent her a genuine one-time password at 15:27 on September 16, followed minutes later by a debit alert for ₦364,574.36. The transaction description read "Web Pur, SERIOUS FIX MACHINERY, Dubai." The fraud did not end with a local transfer out of her account. It ended with an international card transaction, authorised using a real OTP from her own bank, routed to a merchant name in the United Arab Emirates.
Screenshot (@EvaIbiam)
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in