A conversation with cybersecurity professional Ayomide Bode-Asa on scams, deepfakes, oversharing, and what it will actually take to keep Nigerians safe online.

I almost applied for a job that didn't exist.

The email looked legitimate. It came from a name at a multinational corporation I genuinely admired, offering an interview slot for a role I had wanted for years. I clicked the link to book a time. Then, without warning, a Facebook login screen popped up, a request to authenticate through my social account just to schedule a job interview.

Something felt off. I didn't recognise the pairing, and I couldn't recall a partnership between the company and Facebook that would explain it. I searched for the sender's name instead of logging in, and found a warning on LinkedIn: other job seekers had flagged the same email as a scam.

I brought that story, and a longer list of questions about what it means to live online in an AI-driven world, to Ayomide Bode-Asa, a cybersecurity professional, when he joined me by phone for a conversation on my radio show. We talked about why "should we worry about AI?" is the wrong question, what small business owners in Nigeria are unknowingly exposing when they adopt AI tools, why seeing is no longer believing, and why he thinks online safety belongs in primary school curricula. Below is our conversation.

We should all be concerned, but not afraid to stop innovating

I opened with the obvious question: should we be worried about an AI-driven world?

"Yes," Asa said, without hesitation, then immediately qualified his answer. "We should all be concerned about how the world is going in terms of AI, but we should not be afraid enough to stop innovating toward that."

AI is changing how people work, communicate, and do business, he said, and that shift brings real opportunity, particularly for small businesses in developing economies. But opportunity and exposure, in his telling, are two sides of the same coin. "It also changes some of the risks," he said. "The conversation isn't really about fearing AI. It's about making sure our security, our awareness, and our judgment develop as much as AI is developing as well."

The woman running a shop on Instagram is already an AI user, and an AI target

I pushed him to move the conversation away from banks and tech firms, and toward the small business owner most Nigerians actually resemble: someone running a shop, a POS stand, or a family business out of a phone.

Asa didn't hesitate. People in that position are already deep into AI tools, he said, using them to answer a flood of customer messages, generate ads, and run a one-person operation as efficiently as a much larger team. "It makes things easy for you," he said. "But in that sense, it also makes it so that you are putting a lot of data out there. It is a two-edged sword."

That data, customer names, phone numbers, payment details, is exactly what makes a small business valuable to advertise with, and exactly what makes it vulnerable. "You have a lot of people trusting you with their personal information," he said. His advice wasn't to abandon the tools. It was to build a habit of pausing: "Looking out before you post certain things, before you put certain data into your own system."

What should never go into an AI tool casually?

I asked him directly: if I'm a small business owner using an AI tool for invoicing, customer messaging, or marketing, what should I never casually type in?

His answer was less a list than a framework. Trust, he said, has to be earned by the platform before information is handed over, and most people never actually check. "A lot of us go through terms and agreements, privacy policies, and we don't even read through them to understand what it is about," he said. Established platforms that are transparent about data-sharing practices can reasonably hold basic business details. Untested third-party AI tools that appear overnight are a different story entirely.

"You should not trust these systems enough to even put in something as simple as your login credentials," he said, let alone customer information, payment plans, invoices, or card details. His rule of thumb: source-check any new AI tool before feeding it anything sensitive.

Nigeria went digital fast. Awareness didn't keep pace.

Nigeria's shift online, banking, shopping, government services, social life, has happened over roughly a decade. I asked whether public awareness of online safety had grown at the same speed as the demand to be online.

"No," Asa said flatly. The novelty of AI and the convenience it offers have outpaced people's understanding of the risk it carries. People now use AI for nearly everything, writing emails, helping children with homework, making business decisions, without stopping to verify what it produces. "You have to be AI literate," he said. "Can you independently verify what is real, rather than depending on AI to verify that for you? Because you're then depending on a computer to verify a digital system, you're kind of not making any sense in that regard."

The fix, he argued, isn't slowing adoption. It's making sure awareness and responsibility scale alongside demand, not behind it.

Beyond "the hacker": what online safety actually means

When Nigerians hear "cybersecurity," Asa said, the instinct is to picture a hacker in a hoodie. He wanted to reset that image entirely.

"Online safety means using the internet in a way that protects you, your information, and the people around you," he said. It's not primarily about withholding data outright; plenty of people believe they're being careful by partially obscuring a card number, unaware that a partial number can still be exploited. It's about behaviour: verifying before acting. His example was direct. A message on WhatsApp claiming to be a relative in trouble, urgently asking for money. "Online safety could just simply be putting out a call to that person to say: are you the one reaching out to me?"

It's not about being afraid of the internet. It's about developing the habits that would allow you to enjoy the benefits of the internet without unnecessarily exposing yourself to the risks that come with it.

The real threat isn't hacking. It's a well-timed message.

I asked him to name the single biggest cyber threat facing ordinary Nigerians right now. His answer: scams, fake bank alerts, fake delivery notifications, fake POS messages, and increasingly, AI-assisted versions of the same old con.

"It's a major development where criminals can use AI to write messages now," he said. "It's easier for them, it's faster, and it can reach many people at the same time." Scammers can now tailor messages to specific groups, pensioners, for instance, and blast them out at scale. The emotional trigger is the same as it's always been: urgency. "They panic. They try to reach out. They put their details on platforms they shouldn't put them on." What follows is predictable: lost data, lost money, lost investments.

But Asa was careful to place the responsibility correctly. "The only way that is vulnerable is still human beings," he said. "It's not really the fault of the system. It comes down to us verifying, checking, and stopping before we put our details online."

When I told him about my almost-scam

I told Asa about the fake job email and the strange Facebook login prompt, and asked how Nigerian job seekers, desperate for opportunity in a tight market, can build that instinct to pause.

He used my own story to make his point. The fact that I wanted the job and still didn't click immediately, he said, was exactly the right response. "You saw that email; you received that email. Even though it was something you were pushing for, you didn't panic and click immediately."

He also offered an uncomfortable explanation for why the email felt so targeted: scammers do their own reconnaissance. "They check the stuff you post online. They just do a check, someone monitoring your presence online," he said, which is why he considers what you post publicly, including job aspirations, part of your exposed surface area.

His practical checklist for spotting a fake:

  • Read the sender's actual email address, not just the display name. Small substitutions, a lowercase "l" swapped for an "i", for instance, are common.
  • Look for tells in the writing, spelling and phrasing that don't match how a real corporation communicates.
  • Hover before you click. Most browsers and email clients will show the true destination URL at the bottom of the screen. "Some of these links are very different to what you're supposed to go into," he said.
  • Don't assume clicking is safe just because you haven't logged in. "In some cases, you don't even have to log in. They just need you to press something, and they have access to your system."
  • Use your company's security channels. Most organisations now have security operations centres or reporting lines specifically for this, and Nigeria has government bodies that handle it too.

Deepfakes, cloned voices, and why "seeing is no longer believing"

We moved to a newer problem: AI-generated images, videos, and cloned voices realistic enough to convince someone that a stranger is a family member. I asked how people should recalibrate their trust in what they see and hear online.

Bode-Asa's first point reframed the whole question: verification doesn't have to happen inside your own head. "You don't necessarily have to make yourself the one to identify that," he said. If an unfamiliar image or voice message arrives, even from someone claiming to be known to you, the move is to verify through a separate channel, a phone call to the person directly, rather than trusting the artefact itself.

He pointed to a disturbingly simple version of this scam already circulating: an AI-generated image of someone crying, paired with a message asking family members for urgent money. Detection tools exist that can flag whether an image or video is AI-generated, and Asa recommends using them. But the underlying shift, he said, is bigger than any single tool. "Seeing is no longer believing. It doesn't mean we have to distrust everything, but our verification habits need to be stronger."

Oversharing has a physical cost, not just a digital one

Social media in Nigeria carries birthdays, workplaces, children, travel, and, often in real time, location. I asked whether that openness makes people easier to target.

"Definitely," Asa said, "because it makes a pattern in our lives." He was careful not to condemn content creation itself. The engagement people get from sharing their lives is genuinely meaningful to them, and he didn't frame that as naive. But he distinguished between sharing and live sharing. His concrete advice: post after the fact, not in the moment. "You can put things online a few hours afterwards so you're not being traced."

The stakes, in his view, go beyond digital fraud. "There is also the physical aspect of security," he said, pointing to real cases of people being targeted or abducted based on information they'd broadcast about their location or movements in real time. "Security is a very fragile thing in Nigeria now, not even online, but physically as well."

The Nigeria Data Protection Act exists. Enforcement is the gap.

I asked about the government's role, and specifically what Nigeria has already done. Asa pointed to the Nigeria Data Protection Act of 2023, which he credited with creating a real framework around personal data protection. But he was blunt about where the system currently falls short.

"There is a framework, but implementing that framework is another story," he said. The responsibility the law creates, in his reading, sits mainly with organisations, banks, hospitals, and technology platforms that hold direct access to citizens' data, not with individuals policing their own passwords. "It's then important for them to carry out these policies. By doing so, they in turn protect the citizens of the country."

His critique of the government's role wasn't that policy is missing, but that accountability is soft. "I believe the government needs to demand more accountability from these organisations," he said, arguing that the consequences for noncompliance currently give companies too much leeway. "I just feel like it should be a bit stricter."

Should cybersecurity be taught in primary school?

I asked whether online safety should become a required part of Nigerian education, given how embedded AI and digital life now are, perhaps starting at the secondary level.

Asa went further than I expected. "Even primary, it should be taught," he said. Not with technical jargon aimed at nine-year-olds, but through scenario-based lessons: someone online asks for your details; what do you do? Someone sends a strange link; what do you do? "We teach children about physical safety, where to go, how to move," he said. "But a child of nine or ten has access to a smartphone now." He argued the responsibility sits with both schools and homes, and that it doesn't need the label "cybersecurity" to work; "online safety" or "finance training for children" accomplishes the same goal without the intimidation factor.

What a safer Nigerian cyberspace looks like in five years

I closed by asking him to describe what genuine progress would look like over the next five years.

His answer combined institutional follow-through with individual accountability. "It looks like an environment where, from the government, we are implementing the policies that exist already," he said, closing the gap between the Data Protection Act on paper and its enforcement in practice. Alongside that, he wants to see Nigerians take fuller ownership of both what they post and what they consume. "We like to believe we are in control of the information we put out there and take back in. But you always have to look at it like you don't know any better; the person trying to scam you knows much more than you do, and they are always one step ahead."

His closing note was less a warning than a call to pace-match a moving target. "It's gonna take a lot of growth, a lot of accountability," he said. "AI is growing. The world is growing. We just have to catch up with it as much as we can."

Ayomide Bode-Asa is a cybersecurity professional and researcher. He can be reached at [email protected] or through his website, securityposture.co.uk.