Before a scammer calls you, they already know your name, your bank, your employer, your family members, and your recent life events. You told them everything yourself.
This is not a guess. It is not luck. It is the result of a deliberate, systematic intelligence-gathering operation that happens long before any phone call is made, any message is sent, or any trap is sprung. Understanding exactly how fraudsters build a complete profile on their targets is the most important step toward making yourself a much harder target.
The Open Source Intelligence Problem
Professional fraud networks use a methodology called Open Source Intelligence — the practice of collecting personal data entirely from publicly available sources without hacking a single system or breaking a single law. Everything they need is already out there. You put it there yourself, and you continue adding to it every day.
Your Facebook profile alone can tell a skilled fraudster your full name, your approximate age, the city you live in, where you work, who your family members are, what bank you complain about when a transfer fails, what phone you use, and what major events have happened in your life recently. Your LinkedIn tells them your job title, your career history, your education, and your professional network. Your Instagram tells them what you own, where you go, and what your daily life looks like.
None of this required any technical skill to obtain. It required five minutes and a search engine.
The Data Breach Ecosystem
Beyond what you post voluntarily, there is a second layer of intelligence that fraudsters access through purchased data from breaches. Every time a company you signed up with gets hacked — a shopping site, a food delivery app, a loyalty program, a job portal — your data enters a black market ecosystem where it is bought, sold, and traded for years.
This data typically includes your full name, your email address, your phone number, your date of birth, your physical address, and sometimes your hashed password. When this information is cross-referenced with your social media profiles, a fraudster can build a remarkably complete picture of who you are without ever interacting with you directly.
Nigeria alone has seen data from millions of citizens circulate in underground markets following breaches of telecoms, fintech platforms, and government-linked databases. If you have been online for more than five years, there is a strong probability that some version of your personal data has already been sold at least once.
The SIM Registration Gold Mine
One of the most valuable datasets in the Nigerian fraud ecosystem is SIM registration data. When mobile networks enforced mandatory NIN-SIM linking, millions of Nigerians submitted their full names, National Identification Numbers, dates of birth, and addresses to telecoms agents — many of whom operated informal outlets with no meaningful data security controls.
This data, when leaked or sold, gives fraudsters a direct link between a phone number and a verified government identity. Combined with bank verification number data that links phone numbers to account names, a fraudster can identify your bank simply by knowing your phone number. This is not speculation. The BVN system, while valuable for financial security, created a centralized data point that, when compromised, exposes the bank identity of millions of customers at once.
How They Identify Your Bank Without Asking
One of the most psychologically effective elements of a fraud call is when the caller correctly identifies your bank before you say a word. Most victims assume this means the caller is genuinely from the bank. In reality, there are several ways a fraudster identifies your bank before making contact.
Leaked BVN-linked data directly maps phone numbers to bank names. Social media posts complaining about failed transfers, delayed salaries, or app downtime frequently name the bank explicitly. Payment screenshots shared publicly to confirm transactions show the sender's bank name in the transaction details. Cashback and savings challenge posts often tag or name the bank providing the offer. WhatsApp status updates celebrating salary arrivals sometimes show bank notification screenshots in full.
By the time a fraudster calls you and says "I am calling from Access Bank regarding your account," they already confirmed your bank from one of these sources. The call feels legitimate because the detail is correct. That feeling is the trap.
The Family Member Research Layer
Sophisticated fraud operations do not stop at the primary target. They map the target's family network specifically to enable a secondary attack vector — calling a family member pretending to be the target in distress, or calling the target pretending to have information about a family member.
Your tagged family photos on Facebook make this mapping effortless. A fraudster can identify your mother, your spouse, your siblings, and your children by name from your public profile in minutes. They can find your mother's phone number from her own public profile. They now have everything they need to call her and say: "Good afternoon ma, I am calling about your son Sir Brown AD. There is an issue with his account and he asked me to reach you urgently."
Your mother hears her son's name, hears urgency, and complies — because the caller knew things a stranger should not know.
The Timing Intelligence Advantage
Fraudsters also study timing. They do not call randomly. They call when the intelligence suggests you are most likely to be financially active or emotionally vulnerable.
A post announcing a new job tells them a salary is incoming. A post celebrating a business contract tells them money has arrived. A post about a death in the family tells them you are emotionally compromised and less likely to think clearly. A complaint about an urgent bill tells them you are under financial pressure. Each of these signals narrows the optimal attack window and increases the probability that the target will act without thinking.
The WhatsApp Group Intelligence Problem
Beyond public social media, WhatsApp groups represent a significant and underappreciated intelligence source for fraudsters. Community groups, church groups, school alumni groups, and neighborhood groups frequently contain members who are unknown to most participants. A fraudster embedded in a group for weeks can quietly collect the names, phone numbers, locations, and personal circumstances of every active member — all shared organically in the course of normal group conversation.
This is why unsolicited additions to WhatsApp groups by unknown numbers should always be treated as a potential intelligence-gathering operation rather than a simple mistake.
Protecting Your Intelligence Footprint
Understanding how the intelligence is gathered is the foundation of reducing your exposure. The goal is not to disappear from the internet — it is to reduce the quality and completeness of the profile a fraudster can build on you from publicly available information.
Set every personal social media account to private and audit your existing posts for information you would not want a stranger to know. Remove your phone number, employer, and address from all public profile fields. Never post bank transaction screenshots publicly, even to celebrate or complain. Stop tagging family members in posts that reveal identifying information about them. Be deeply cautious about what you share in any WhatsApp group that contains people you do not personally know.
When you receive a call from someone who demonstrates knowledge of personal details about you, do not interpret that knowledge as proof of legitimacy. Interpret it as proof that your data has been collected. Hang up. Call your bank directly on the number printed on your card.
Conclusion
The intelligence file a fraudster builds on you before making contact is assembled from sources you control. Your social media posts, your public profiles, your group memberships, and the data you submitted to platforms that were later breached — these are the raw materials of the attack. Reducing what you share publicly does not make you paranoid. It makes you a significantly harder target in an environment where the easiest targets are chosen first.
Get new Security & Fraud alerts
One email when a new security & fraud article like this one goes live. No spam, unsubscribe anytime.

