" ITREALMS: The email that promised an iPhone by Remmy Nweke - WeekendDigits@ITREALMS

Friday, July 10, 2026

The email that promised an iPhone by Remmy Nweke - WeekendDigits@ITREALMS

What begins as an email promising a free iPhone unfolds into a compelling exploration of phishing, identity theft and social engineering. In this edition of WeekendDigits@ITREALMS, REMMY NWEKE reveals, through the experience of a Lagos professional, how cybercriminals exploit human trust, not technology, to deceive unsuspecting internet users in today's digital world.
Friday mornings in Lagos often carry a quiet sense of relief.

After another exhausting week of battling traffic, deadlines and the relentless rhythm of city life, many professionals begin the day with familiar routines. For Gozie, let's call him that to protect his identity, the ritual rarely changed. He brushed his teeth, took his bath, grabbed a quick breakfast and, before stepping out for work, reached for his phone to check his email.
The email that promised an iPhone by Remmy Nweke - WeekendDigits@ITREALMS
Most mornings were predictable.

There would be newsletters he never remembered subscribing to, office correspondence waiting for attention, promotional offers from online stores and the occasional message from family or friends.

But this Friday was different.

Sitting quietly among dozens of unread messages was one with a subject line almost impossible to ignore.

"You have won Apple Laptop and iPhone."

For a brief moment, Gozie paused.

He searched his memory. Had he entered an online competition? Perhaps months ago while browsing the internet? Maybe he had simply forgotten.

Curiosity briefly defeated caution.

He opened the email.

The message congratulated him on winning an Apple laptop and an iPhone through what it described as an international promotional lottery. According to the sender, his email address had been selected randomly from millions of internet users around the world.

All he needed to do, the message said, was provide his full name, residential address, occupation, telephone number, country, age and gender so that his prize could be delivered.

It sounded surprisingly simple.

Perhaps, he thought, fortune had finally smiled on him.

But something did not quite add up.

Instead of replying immediately, Gozie did something many internet users fail to do when confronted with unexpected good fortune. He forwarded the email to me with a simple note.

"Please evaluate this. Something doesn't feel right."

I opened the message expecting another routine phishing attempt.

What I found instead was a masterclass in social engineering.

At first glance, the email looked convincing enough for someone eager to believe in good news. It carried a London address, bore the title Winning Notification and even included what appeared to be a ticket number to authenticate the supposed prize. To someone caught up in the excitement of winning an Apple laptop and an iPhone, those details might have appeared reassuring.

To a trained eye, however, the cracks appeared almost immediately.

The sender introduced herself as "Mrs. Ruth Porat," a name associated with one of the world's most recognisable technology executives. Yet the message had not been sent from a corporate email address. Instead, it originated from a personal Gmail account. Worse still, recipients were instructed not to reply to that address but to send their details to an entirely different Outlook account.

Three different identities.

Two free email services.

Not a single official company domain.

That was the first alarm bell.

The second appeared in the story itself.

The email claimed that Gozie's address had been selected from millions of internet users around the world in an annual promotional draw. It congratulated him on winning devices worth hundreds of thousands of naira despite the fact that he had never entered any competition.

Legitimate promotions do not award prizes to people who never participated. They also provide verifiable terms and conditions, official websites, customer support channels and transparent selection processes.

This email offered none of those.

Instead, it asked for something far more valuable than an acknowledgement.

It requested Gozie's full name, residential address, telephone number, occupation, country, age and gender.

To many people, those questions might seem harmless. After all, what could a criminal possibly do with a home address or an occupation?

Quite a lot.

Each answer would help build a digital profile. Combined with information already available on social media, such details could be used to impersonate the victim, answer security questions, craft more convincing phishing emails or support identity theft. In today's digital economy, personal information has become a valuable currency.

Then came another subtle clue.

The email instructed the supposed winner to keep the prize confidential until delivery, warning that this was necessary to prevent "double claiming."

That sentence revealed the psychology behind the scam.

Isolation is one of the oldest tools in a social engineer's arsenal. A victim who keeps silent is less likely to seek a second opinion from a friend, colleague or family member who might immediately recognise the fraud. Secrecy protects the scammer, not the victim.

There were other warning signs.

The language was littered with grammatical inconsistencies and awkward phrases that no established international technology company would be expected to use. The formatting was uneven, and the story itself lacked the basic ingredients of a legitimate promotion: no official website, no published rules, no verifiable customer support and no transparent explanation of how the supposed winners had been selected.

ALSO READ:

When loans become surveillance & Nigeria’s regulatory triangle by Remmy Nweke -WeekendDigits@ITREALMS

Daniel in Denial and anatomy of 5,000 voices in 12 hours by Remmy Nweke - WeekendDigits@ITREALMS




By the time I reached the end of the email, the verdict was no longer in doubt.

This was not a prize notification.

It was a carefully constructed act of social engineering.

The Apple laptop never existed.

The iPhone was imaginary.

The real target was sitting in Lagos, reading the email over breakfast.

Fortunately, Gozie had paused long enough to ask a simple question before responding.

"What do you think?"

That brief moment of hesitation may have saved him from becoming another statistic in the growing catalogue of cyber-enabled fraud.

As it turned out, Gozie had unknowingly followed one of the most important rules of cyber hygiene: when in doubt, verify.

His decision to seek a second opinion before responding reflected a growing awareness that every unexpected digital offer deserves scrutiny, especially in an era when cybercriminals are becoming increasingly sophisticated in exploiting human emotions.

That simple act of caution echoes the advice of cybersecurity awareness advocate Gbemisola Esho, Lead, ConnectToBridge, who warned Nigerians that phishing attacks often disguise themselves as opportunities too attractive to ignore.

Speaking during the 2026 Nigeria DigitalSENSE Forum on Internet Governance for Development (IG4D) at the DNS Women Foundation Nigeria session titled "Phishing at a Glance," Esho offered what may be the simplest test for recognising online scams.


"If it sounds too good to be true, it is probably phishing, especially when you know you did not initiate any contest."

Her message resonated because it distilled a complex cybersecurity challenge into a practical lesson that every internet user could remember.

Cybercriminals understand that people naturally respond to promises of reward. Whether it is an iPhone, an overseas job offer, a scholarship, an investment opportunity or a government grant, the objective is the same: create excitement before critical thinking has a chance to intervene.

That was precisely the strategy behind the email Gozie received.

It promised expensive Apple devices without any record of participation in a competition. It relied on excitement rather than evidence. It asked for personal information before offering any means of independent verification. Above all, it attempted to manufacture trust where none existed.

Esho's warning therefore goes beyond phishing emails. It is a reminder that in today's digital society, skepticism is no longer a sign of cynicism. It is an essential survival skill.

Yet Gozie's experience is far from unique.

Every day, thousands of Nigerians receive emails promising smartphones, scholarships, overseas jobs, cryptocurrency windfalls, grants or investment opportunities. Behind many of these messages lies one of the oldest weapons in cybercrime, not malicious software, but the manipulation of human psychology.

Cybercriminals understand something that technology alone cannot solve.

They understand people.

They understand hope.

They understand curiosity.

They understand urgency.

Above all, they understand trust.

Unlike the hackers portrayed in Hollywood films, many cybercriminals never begin by attacking computers. They begin by studying human behaviour. They know that emotions frequently override logic, especially when those emotions involve excitement, fear or the possibility of unexpected reward.

That is why phishing remains one of the world's most effective cybercrime techniques. It is less about breaking into systems than persuading people to open the door themselves.

As Nigeria's digital economy continues to expand through online banking, e-commerce, digital identity, artificial intelligence and electronic government services, the country's cyber resilience will depend not only on stronger technology but also on more informed citizens.

The strongest firewall is not always installed on a computer.

Sometimes, it is the simple decision to pause before clicking "Reply."

For Gozie, that pause made all the difference.

The promised Apple laptop never arrived.

Neither did the iPhone.

What arrived instead was something far more valuable: the knowledge that in today's connected world, protecting one's identity begins with questioning the unexpected.

Because phishing is not really about technology.

It is about trust.

And once trust is stolen, recovering it can be far more difficult than replacing a phone.


No comments: