PERSON VERIFICATION

Verify the person separately before you act on the request.

A familiar name, profile photo, phone number, voice or account can still be fake or compromised. When a person you know or an organisation you trust makes an unusual request, leave the requesting channel and confirm both the person's identity and the specific request through a separate trusted channel.

Do not let the request choose the verification method.

If the message says, "Call this number to confirm," calling that number is not independent verification. If a caller says, "Read the code back so I know it is you," the caller is controlling the verification conversation.

Independent verification means moving outside the channel that created the request and using contact information or a trusted route you already had, or one you find independently.

What does 'verify separately' mean?
It means using a different trusted channel to confirm the person and the request. Examples include calling a relative using a number already saved in your phone, contacting a company through its official website, opening a bank's official app yourself or using an established workplace communication route.
Why verify the request if I already verified the person?
A genuine person's account can be compromised. The person may be real while the person controlling the account is not. Confirm the exact request, payment details, amount, destination or information being requested, not just the person's identity.
What if it really is an emergency?
Independent verification does not mean ignoring an emergency. It means using another trusted route to confirm what is happening and then taking the appropriate action. A genuine emergency can survive a short verification step; a scam often depends on preventing one.
Can a familiar voice, video or profile photo prove identity?
No. They can be useful clues, but they should not be treated as sufficient proof for a high-consequence request. Match the strength of your verification to the consequence of being wrong.
SEPARATE VERIFICATION

Use this process when a familiar identity makes an unusual request.

The objective is not to distrust everyone. It is to prevent someone from borrowing a trusted identity to make you act.

STEP 01

Recognize the identity being presented

Start by identifying who the person claims to be and what makes the identity look familiar.

What should I do?
Write down the claim: a relative, friend, colleague, bank employee, support agent, supplier, manager or other trusted person. Notice the name, number, profile, voice or account being presented, but do not treat those features as proof. Familiarity tells you who the person claims to be, not who is actually controlling the channel.
STEP 02

Identify exactly what they want

An identity claim becomes more important when it is attached to a consequential request.

What should I do?
Identify whether they want money, a password, OTP, recovery code, identity document, personal information, payment change, account access, installation or another action. The more consequential the request, the stronger your independent verification should be.
STEP 03

Leave the requesting channel

The channel that created the request should not be the only channel you use to verify it.

What should I do?
Do not verify a WhatsApp message by replying to the same WhatsApp account. Do not verify a caller by asking the caller whether they are genuine. Do not verify a support link by opening the link it supplied. Move to a phone number, website, app, workplace channel or other contact route you trusted before the request arrived.
STEP 04

Verify the person independently

Use a source that the suspected impersonator does not control.

What should I do?
Call the person using a number already saved in your contacts. Contact a relative through another established route. For a company or bank, open the official website or app yourself and use its published contact method. For a colleague, use an established workplace channel. Do not take the verification number or link from the suspicious message.
STEP 05

Verify the specific request

Even a genuine person's account can be compromised, so identity alone is not enough.

What should I do?
Ask the independently contacted person whether they actually made this request, what they want you to do and whether the details are correct. A real person may have a compromised account, so confirm the exact action, payment destination, amount or information being requested.
STEP 06

Check the pressure and consequence

Urgency does not prove fraud, but it should increase your care.

What should I do?
Notice demands for immediate action, secrecy, unusual payment methods, authentication codes or instructions to avoid contacting anyone else. Ask what could happen if you are wrong. The greater the potential loss, the less acceptable it is to rely on appearance alone.
STEP 07

Act only after the verification supports the action

If you cannot independently verify both the person and the request, pause.

What should I do?
Do not send a small amount just to test the request. Do not reveal one code 'just this once.' Do not click a link because the account looks familiar. Do not install an application because the caller sounds convincing. If verification fails, stop and use an official recovery or reporting route when appropriate.
REAL-WORLD EXAMPLES

Practise breaking the impersonator's control of the conversation.

In each example, the safest move is to separate the verification from the channel that created the request.

Example 1: A relative suddenly uses a new number

A WhatsApp message says: 'It is me. I lost my phone. Please send me ₦80,000 urgently.' The profile photograph looks correct and the person mentions a recent family event. Do not use the new number to verify itself. Call the old number if available, contact another family member through a previously trusted channel, or use another established way to confirm the request before sending money.

Example 2: A familiar account asks for money

A friend's existing account suddenly asks for a transfer, gift card, cryptocurrency or another form of value. The account may genuinely belong to your friend, but it could also be compromised. Contact your friend through a separate channel you already trust and confirm the exact request before acting.

Example 3: A bank caller asks for an OTP

A caller says there is a problem with your account and asks for the OTP just sent to your phone. Do not read the code to the caller. End the call and contact the bank using the official app, website or a phone number you already trust. The OTP helps authenticate an account action; it does not prove that the caller is a bank employee.

Example 4: A fake support account

A social-media account claims to be customer support and asks for your password or recovery code to fix an account problem. Do not provide the secret. Open the service yourself and use its official support or account-security process. Verify the organisation independently instead of relying on the account that contacted you.

Example 5: A family emergency message

A message appears to come from a relative who says they are stranded and cannot answer a call. They demand immediate payment and ask you not to tell anyone. Treat the urgency as a reason to verify, not a reason to skip verification. Contact the relative using a number you already had or reach another trusted family member.

Example 6: A manager requests an urgent payment

A message from a manager appears to request an urgent payment or purchase. The name and profile picture are correct. Do not approve a consequential business action from the message alone. Use an established workplace channel, known phone number or existing approval process to confirm the request.

Example 7: A known supplier changes bank details

A familiar supplier sends a message saying future payments must go to a new account. Do not verify the change by replying to that same message. Call the supplier using contact information already stored in your records and confirm the new payment details before changing the beneficiary.

Example 8: The impersonator knows personal details

Someone claims to be a relative and knows your workplace, hometown, family member's name or recent activity. Those details can make the conversation convincing, but they are not proof of identity. Ask how the request can be independently verified and use a trusted channel that existed before the contact.

HIGH-CONSEQUENCE REQUESTS

Slow down when the request can cause serious harm.

These requests deserve independent verification before you act.

Money transfers or urgent payments

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Changes to bank or payment details

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Passwords, PINs, OTPs or recovery codes

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Identity documents or sensitive personal information

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Requests to install an application

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Requests for remote access to a device or account

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Cryptocurrency or gift-card payments

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Account or beneficiary changes

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Requests to keep the matter secret

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

Instructions that prevent you from contacting anyone else

Do not rely on the identity presented in the requesting conversation alone. Verify through an appropriate independent channel first.

The five-question separate-verification test:

1. WHO? Who does this person claim to be?

2. WHAT? What exactly are they asking me to do?

3. SEPARATE? Have I left the channel that made the request?

4. CONFIRM? Did I independently confirm both the person and the specific request?

5. CONSEQUENCE? What happens if I am wrong?

If a consequential request cannot pass this test, pause before acting.

If you already acted, move quickly.

If you sent money, contact your bank or payment provider through its official channel. If you shared an OTP, password or recovery information, secure the affected account through its official security process. If sensitive information was shared, document what happened and consider which accounts or services could be affected.

Preserve relevant messages, numbers, usernames, URLs, transaction references and timestamps before deleting evidence unnecessarily.

Familiarity is recognition, not proof.

A familiar identity can be copied. A familiar account can be compromised. A familiar voice can be imitated. When the request matters, separate the verification from the request.

PAUSE → IDENTIFY → SEPARATE → VERIFY → CONFIRM → ACT

VERIFY BEFORE YOU TRUST.