If Fake Government Messages Can Find Us, What Does That Say About Nigeria’s Digital Identity?
Fake NIPOST and FRSC messages reveal a bigger question about digital identity, data privacy, and how Nigerians should navigate an increasingly connected digital economy.On Tuesday, September 15, I received a text message from NIPOST telling me that my delivery was incomplete and that the postal service had been unable to complete it.
I was asked to update my details through a link that, at first glance, looked like it belonged to the Nigerian Postal Service.
A colleague received almost the same message around the same time. She was actually expecting a delivery from an order she had placed, so unlike me, the message immediately made sense to her; she was already considering clicking the link and apparently updating her details.
I told her I had received the same message but had not ordered anything online and was not expecting a delivery. That was the moment the message became interesting.
Not because it was an unusually sophisticated scam, but because it demonstrated something more uncomfortable about digital life in Nigeria: a fraudulent message does not have to know everything about you to sound as if it does.
The Scam Does Not Need to Know Your Life
Think about how easily the message could work.
Someone is expecting a package. A message arrives saying the delivery is incomplete and asking for an update. The recipient is not being offered millions of naira, invited into an investment scheme, or promised a miraculous opportunity. They are simply being told that something they are already waiting for has encountered a problem.
That is what makes these messages dangerous.
NIPOST itself has previously warned about fake websites impersonating the organisation, while its official tracking service allows customers to check packages using tracking or reference numbers.
Now put my colleague back into the story.
She had a genuine reason to believe a delivery might be involved. If she had clicked the link quickly, the scam would not have needed to convince her that she was expecting a package. Her real life would have done that part for the scammer.
And she is unlikely to be the only person who could find herself in that situation.
This is how social engineering works. The message does not necessarily need to contain your entire identity. It only needs to arrive at the right moment, touch something plausible, and create enough urgency for you to act before thinking.
A similar pattern has now appeared in a separate incident involving the Federal Road Safety Corps.
On September 16, the FRSC warned Nigerians about fraudulent SMS messages claiming that recipients had new road traffic offences and directing them to a deceptive website. The Corps specifically identified frscgov.top/ng as unaffiliated with FRSC.
Different institutions. Different stories. But the same basic idea: borrow a trusted name, create urgency, and wait for a real person to complete the rest.
So Where Are These Numbers Coming From?
This is where the conversation becomes more complicated.
When several people receive similar unsolicited messages, the natural reaction is: Who gave them our numbers?
It is a reasonable question.
Yes, there may have been a data breach, but it is important not to jump from suspicion to conclusion since we cannot fully ascertain that. A suspicious SMS is not proof that a particular institution suffered a data breach.
We can only infer possibilities until the institutions speak up, and neither the NIPOST message I received nor the current FRSC warning establishes that their databases were compromised.
There are other possibilities. Phone numbers can circulate through marketing databases, old registrations, leaked datasets, compromised accounts, data brokers, or lists assembled from multiple sources.
A mass campaign may not need to know whether you are a NIPOST customer or an FRSC motorist; it can simply send the same message to thousands of numbers and wait for the circumstances of individual recipients to make some of them believable.
But that uncertainty should not make the question disappear. It should make it bigger.
How many organisations have our phone numbers? How many third parties have access to them? How long are they retaining them? Who can share them, process them, or lose them? And when something goes wrong, how does an ordinary Nigerian know?
These are no longer abstract privacy questions.
Our phone numbers increasingly connect to our names, addresses, banking details, identification records and online accounts. Nigeria’s data-protection framework requires personal data to be collected lawfully, limited to what is necessary and protected against unauthorised access.
The question is whether Nigerians see that protection working when suspicious messages arrive.
We Need More Than “Be Careful”
There is an obvious part of the solution that belongs to individuals.
We need to slow down before clicking unsolicited links, check whether a message makes sense, and use independently verified official channels rather than allowing a text message to dictate our next action.
But digital security cannot become another responsibility that is quietly transferred entirely to the citizen.
Nigeria is building a much more interconnected digital identity ecosystem. The new NIMC Act 2026 strengthens NIMC’s role in national identity management and places it at the centre of digital trust, authentication and public-key infrastructure, while emphasising data protection and cybersecurity.
That means the conversation has to move beyond teaching Nigerians not to click strange links.
We should be asking what happens when trusted institutions are repeatedly impersonated. How quickly can fraudulent domains be identified and taken down? How are breaches detected and communicated? How do organisations control third-party access to personal data, and what accountability exists when citizens’ information is exposed?
And there is another issue we rarely discuss enough: trust itself is becoming digital infrastructure.
When a message arrives carrying the name of a government institution, people should not have to become cybersecurity experts to determine whether it is real.
When criminals repeatedly imitate public institutions, they do more than attempt to steal information; they also make people question legitimate digital communication.
That is why my NIPOST message matters even though I did not click it. It is a small incident, but it sits inside a much bigger question.
My colleague had a package coming. Someone else may have a driving concern. Another person may be waiting for a bank transfer, passport, parcel, or official document.
The scammer only needs to find the person whose real life makes the fake message believable.
So yes, Nigerians need to be careful.
But institutions also need to make digital trust easier to recognise, breaches harder to exploit, and suspicious activity easier to report and investigate.
Because Nigeria’s digital identity is no longer something sitting quietly inside an identity card.
It is travelling through our phones every day.
And if strangers can keep finding ways to make us believe they already know us, the question is no longer simply “How do I avoid this scam?”
It is also: “Who is responsible for making sure my digital identity remains mine?”
