“Don’t Share Your Account Number” Is Wrong Advice – What Actually Gets You Hacked in Nigeria

User avatar placeholder
Written by Abraham Adebisi

Published: August 3, 2026

UPDATED: August 3, 2026

woman in traditional attire holding currency

There is a piece of financial safety advice that circulates constantly in Nigerian WhatsApp groups, family chats, and social media: “never share your account number with anyone.” People who follow this advice refuse to send their account details to employers paying their salary, clients settling invoices, family members sending money, and strangers who want to make entirely legitimate transfers. The caution feels prudent. It is, on the specific question of account numbers, almost entirely misplaced.

Your account number is not a security credential. It cannot, by itself, allow anyone to take money from your account. Understanding this isn’t a reason to be careless — it’s a reason to redirect the energy currently spent protecting the wrong thing toward protecting the things that actually matter.

This article separates what is genuinely dangerous from what Nigerian banking culture has decided is dangerous, and provides a clear picture of the actual fraud landscape in 2026.


What Your Account Number Actually Is (And Isn’t)

Your bank account number is a receiving identifier — it tells the banking system where to send money. It is designed to be shared. Every time you receive a payment, whether from an employer, a client, a family member, or a customer, they must have your account number to initiate the transfer. The entire payment infrastructure assumes your account number will be known to people who need to pay you.

Your account number alone cannot:

  • Initiate a transfer out of your account
  • Give anyone access to your account on any banking platform
  • Enable any fraudulent transaction without additional credentials
Read:
How to Open Domiciliary Account in Nigeria: The Complete 2026 Guide

Knowing your account number and your bank name gives a person the ability to send money to you. That is all. The banking system is structured this way deliberately — receiving money requires only a public identifier, while sending money requires authentication credentials (PIN, password, OTP) that only you should have.

Refusing to share your account number with legitimate payors costs you real money — the salary not received, the invoice not settled, the payment not made — while protecting you from precisely nothing. The fear is based on a misunderstanding of how the banking system works.


What the Real Fraud Vectors Actually Are

1. OTP (One-Time Password) theft — the single most common fraud method

Every Nigerian bank and most fintech apps send an OTP to your registered phone number as the final authentication step for transactions above certain amounts, and for certain sensitive operations (new payee addition, password reset). This OTP is the actual security gate. Whoever has your OTP can authenticate transactions from your account.

Fraudsters obtain OTPs through:

  • Social engineering calls — posing as bank customer service, CBN officials, telecom agents, or lottery representatives, creating scenarios that make you feel urgent pressure to “verify” something by reading out the OTP you just received
  • Phishing messages — fake SMS or email links that look like official bank communications, directing you to a fake website that captures your OTP entry
  • Malware on devices — less common but increasingly documented, software that intercepts SMS messages including OTPs on compromised devices

The protection: your OTP is never needed by anyone legitimate, ever. Your bank will never call you and ask for an OTP. CBN officials will never ask for an OTP. No legitimate lottery, promotion, or verification process requires you to read out an OTP you received. If someone asks you for an OTP you just received, they are attempting fraud. End the call, delete the message, do not engage.

Read:
Kuda Bank Review: Is Nigeria's "Bank of the Free" Still Worth It in 2026?

2. SIM swap fraud

A SIM swap occurs when a fraudster convinces your mobile network to transfer your phone number to a new SIM they control. Once they have your number on their SIM, all calls and SMS to your number — including OTPs — go to them instead of you.

How SIM swaps happen in Nigeria:

  • Fraudsters gather enough personal information about you (name, date of birth, BVN, possibly address) — sometimes through data breaches, sometimes through targeted research on social media — to pass the identity verification that telecom companies require for SIM replacement
  • They attend a telecom service centre with a printed or digital copy of a fraudulent ID in your name, or exploit inconsistent verification processes at certain service points
  • Once the swap is done, your number goes dead (you lose signal), which is usually the first signal that something is wrong — but by the time you investigate, OTPs have already been sent to and received by the fraudster

The protection: know that losing mobile signal unexpectedly — particularly if it coincides with any recent attempts to reach you about “account verification” — should be treated as a potential SIM swap emergency. Contact your bank immediately to place restrictions on your account, even before contacting your telecom provider.

3. BVN-linked phishing

Your BVN (Bank Verification Number) is more sensitive than your account number — it is linked to your biometric data and cross-references across all your bank accounts. Fraudsters who obtain your BVN can use it in social engineering scenarios (posing as bank staff and quoting your BVN to appear legitimate), and in some cases it has been used in combination with other information to attempt account takeovers.

Read:
First Bank Nigeria Review 2026: Nigeria's Oldest Bank Put to the Honest Test

How BVNs are compromised:

  • Fake “BVN verification” websites that capture your BVN (often circulated on social media as “check if your BVN is linked to multiple accounts” or “verify your NIN-BVN link”)
  • Data breaches from platforms that collected BVN information without adequate security
  • Social engineering scenarios where you’re asked to “confirm” your BVN with someone posing as a bank representative

The protection: your BVN should not be shared with anyone who contacts you. Legitimate bank processes that require your BVN will do so through official channels (your bank’s app, their official website, a bank branch visit). Never enter your BVN on a website you were directed to from an unsolicited SMS or call.

4. Phishing websites mimicking Nigerian banks

Fake websites designed to look exactly like GTBank, Access Bank, UBA, or other Nigerian banks’ login pages capture usernames, passwords, and sometimes OTPs when you enter them thinking you’re on the real bank site. These are distributed through SMS (“your account has been flagged — click to verify”), email, and social media.

The protection: always access your bank through the official app, not through links in messages. If you receive an SMS with a link about your bank account, do not click it — open your bank’s official app directly instead. The link you clicked may or may not be the real bank’s site; the official app is definitively the real bank.

5. Card skimming and POS fraud

Physical card data theft — capturing card numbers and PINs through compromised ATM machines or POS terminals equipped with skimming devices — remains a real vector, particularly at certain ATM locations. Signs of a potentially compromised ATM: unusual attachments around the card slot, a keypad that feels different from normal, a camera positioned to capture PIN entry.

Read:
GTBank Review 2026: Is It Still Worth Using as Your Main Bank?

The protection: cover the keypad when entering your PIN at any ATM or POS. Use ATMs inside bank branches over those in isolated outdoor locations where tampering is harder to detect and report.


The Real Risk Hierarchy

ThreatRisk LevelMechanismProtection
OTP theft via social engineeringVery HighFraudster calls/messages you and obtains OTPNever share OTP with anyone, ever
SIM swapHighFraudster takes over your phone numberMonitor for unexpected signal loss; enable SIM lock with your telecom
BVN phishingHighFake websites/calls capture BVNNever share BVN through unsolicited contacts
Phishing websitesHighFake bank login pages capture credentialsOnly access banks through official apps
Card skimmingMediumPhysical card data capture at ATMs/POSCover PIN entry; use branch ATMs
Sharing account numberNear zeroAccount number alone enables nothingNo protection needed

The table above is the clearest illustration of the mismatch between what Nigerians protect against (account numbers) and what actually causes fraud losses (the top four items, all of which involve authentication credentials, not receiving identifiers).


Why This Misconception Is So Persistent

The vocabulary confusion. “Account number” and “account credentials” are used interchangeably in casual conversation, which produces genuine confusion about what each actually is. When a fraud alert warns “don’t share your account details,” people interpret “details” to mean “number” when the relevant details are credentials (PIN, password, OTP). The language is ambiguous enough that a genuinely cautious interpretation of “details” might include “number” — but the cautious interpretation is the wrong one.

The occasional partial accuracy. In specific fraud scenarios — particularly some types of fraud involving check payments or certain business payment schemes — account number combined with other information can sometimes be used in more complex fraud chains. This edge case has been generalised into “account numbers are dangerous,” which overstates the risk dramatically for the typical personal banking context.

Read:
BVN in Nigeria: What It Is, How to Get It, Link It, Check It, and What to Do If You Lose It

The comfort of a simple rule. “Never share your account number” is simple. “Never share your OTP, treat unsolicited calls about your account with extreme suspicion, monitor for unexpected SIM activity, only access your bank through official apps, and cover your PIN at ATMs” is more complex. Simple rules travel better in WhatsApp groups and family advice, even when they’re wrong.

💵 Try the TurnetFinance Salary Breakdown Tool

Understanding your actual banking situation clearly — what accounts you have, what’s in them, and what your legitimate monthly flows look like — is the foundation of noticing when something unusual is happening. The Salary Breakdown Tool helps you maintain a clear picture of your finances.

Open the Salary Breakdown Tool →


Practical Security Checklist: What to Actually Protect

Your OTP — protect absolutely. No exceptions. No legitimate person or organisation needs your OTP. If anyone asks for it, it’s fraud.

Your banking app password/PIN — protect carefully. Don’t use the same PIN across multiple platforms. Don’t use your date of birth, which can be researched. Enable biometric authentication where available.

Your BVN — protect thoughtfully. Share only with your bank directly (in branch or through the official app), with regulated financial institutions as part of a formal application, or with regulatory bodies through official channels. Not with websites you were directed to from unsolicited messages.

Your mobile number and SIM — protect actively. Enable SIM lock (a PIN that prevents your SIM from being used in a different phone without authorisation) with your network provider. Monitor for unexpected signal loss. Consider registering a separate line for sensitive banking communications.

Read:
USSD Banking Codes for All Nigerian Banks and Fintechs in 2026: The Complete Reference Guide

Your physical card and PIN — protect simultaneously. Cover the PIN pad when entering at any location. Report a lost or stolen card immediately. Disable international transactions on your card if you don’t travel internationally.

Your account number — share freely with legitimate payors. Employers, clients, family, customers. This is the identifying number for receiving payments and is designed to be known by people who pay you.


Frequently Asked Questions

Q: What should I do if I accidentally shared my OTP?
A: Contact your bank immediately — this is an emergency call, not a routine one. Call the official bank number (found on the back of your card or the official bank website, not from the number that called you) and report that your OTP may have been compromised. Request that any pending transactions be reviewed and that your account be temporarily restricted if necessary. The faster you act after OTP compromise, the better the chance of preventing or recovering from a fraudulent transaction.

Q: Is it safe to give out my account number on social media?
A: For the purpose of receiving legitimate payments — yes, in the same way that a business lists its account number on an invoice. The risk from posting your account number publicly is that it might result in unsolicited contact from people who want to “discuss business” and then attempt social engineering — not that anyone can steal money simply from having your account number. Be aware of the secondary social engineering risk, but don’t confuse it with the account number itself being a vulnerability.

Read:
Bank Transfer Charges in Nigeria 2026: Which Bank Actually Charges You Less?

Q: Can a fraudster use my account number to reverse a payment they made to me?
A: No — payment reversal requires authentication credentials and processes on the sender’s side, not just the recipient’s account number. A legitimate payment reversal goes through the bank’s formal dispute process. A fraudster cannot “take back” money sent to your account simply by knowing your account number.

Q: My bank’s SMS said my account has been restricted and I need to call a number to fix it — what do I do?
A: Do not call the number in the SMS. Call your bank’s official customer service number (found on the back of your card or on the official bank website that you navigate to yourself, not through a link in the SMS). Many bank fraud attempts begin with exactly this scenario — a fake SMS directing you to a fraud call centre posing as your bank. The rule: always initiate contact with your bank through channels you find independently, never through numbers or links provided in unsolicited messages.


The Bottom Line

The Nigerian banking security conversation is having the wrong conversation — spending energy and creating real friction around account numbers, which are public receiving identifiers with no inherent security sensitivity, while the actual fraud vectors (OTP theft, SIM swaps, phishing, BVN compromise) receive far less attention in everyday financial safety culture.

The cost of this mismatch is real: legitimate payments refused or delayed because someone “doesn’t share their account number,” while the same person freely reads OTPs to callers posing as bank officials. The fear is high in the wrong place and low in the right ones.

Redirect the vigilance: OTP is never for sharing, BVN is not for unsolicited websites, official apps are the only banking channel, unexpected signal loss is a potential emergency. Account numbers are for sharing with people who need to pay you. That’s what they’re for.


Related: GTBank Review 2026 | Bank Transfer Charges in Nigeria 2026 | Kuda Bank Review 2026

Image placeholder

Author: Abraham Adebisi founded TurnetFinance, a personal finance platform dedicated to providing practical, data-driven tools and insights tailored to Nigerian economic realities. With over 8 years of experience in digital strategy, SEO, and financial education, Abraham previously founded Turnet Digitals and SkillSteps Nigeria. He is passionate about demystifying personal finance and empowering Nigerians with honest, locally relevant content and free tools to navigate salaries, loans, budgeting, and cost of living.

1 thought on ““Don’t Share Your Account Number” Is Wrong Advice – What Actually Gets You Hacked in Nigeria”

Leave a Reply