When Trust Becomes a Trap: Inside the Fake FRSC Websites Exposing Nigeria’s Digital Compliance Gaps
A text message arrives on a motorist’s phone: a traffic offence has been recorded and requires immediate attention. There is a link to review the alleged violation. The language is official enough to...
A text message arrives on a motorist’s phone: a traffic offence has been recorded and requires immediate attention. There is a link to review the alleged violation. The language is official enough to create urgency, and the website waiting at the other end appears to belong to the Federal Road Safety Corps (FRSC).
For one Nigerian actress, Eva Ibiam, the message came with a devastating price.
Ibiam lost N400,000 after interacting with one of the fraudulent traffic-fine platforms and subsequently took to X to warn other motorists. “Beware of scammers! I just got defrauded of almost 400k!! Do not click this link please!!!” she wrote.
Her experience was not an isolated incident. FIJ’s investigation published on September 17, 2026, found multiple websites designed to deceive motorists by impersonating the FRSC and presenting fabricated traffic offences as genuine government records. Four days later, FIJ reported that two of the fraudulent websites it had identified had gone offline.
The episode offers more than another account of online fraud. It exposes a deeper compliance question: how easily can public trust in a government institution be converted into a tool for deception?
The answer, in this case, appears to have been alarmingly simple.
A Government Identity Without a Government Domain
The fraudulent platforms identified by FIJ included frsc-gov.sbs.ng and frsc.gov.eu.cc.ng. At first glance, their addresses contained the words motorists would expect to see: “FRSC”, “gov” and “ng”.
The websites also copied elements of the FRSC’s branding, layout and service presentation, according to FIJ. But there was a critical difference. They were not hosted under the agency’s official frsc.gov.ng domain.
That distinction is central to the compliance story.
Digital compliance is partly about ensuring that citizens can identify an authorised channel and distinguish it from an unauthorised one. When a fraudulent website can reproduce an institution’s visual identity and construct a domain name that appears official, the problem moves beyond individual gullibility. It becomes an issue of digital identity protection, consumer protection and institutional risk management.
FIJ put the websites through a simple test: fictitious vehicle registration numbers were entered into their systems. Even number plates that did not conform to Nigeria’s standard vehicle-registration format reportedly generated alleged traffic offences.
The websites then produced purported fines of N10,000 and offered motorists a 50 percent discount if they paid immediately.
The numbers tell their own story. A supposed N10,000 fine reduced by half for immediate payment creates the kind of urgency that can discourage verification. For a fraudster, the proposition is simple: manufacture an offence, attach a deadline, offer a discount and direct the target towards payment.
For a compliance professional, each stage represents a control point.
Where the Money Trail Begins
The fraudulent websites did not stop at generating fictional offences. Motorists were redirected to a third-party payment page called Payfast Now.
During testing, the payment page requested card information, including card numbers and CVVs. In one version, it also requested the cardholder’s name and card PIN.
That last demand was a particularly important warning sign. A card PIN is highly sensitive authentication information and its request during an online payment should immediately trigger suspicion.
The payment channel itself provided another compliance indicator. FIJ reported that the recognised electronic payment channel for prescribed FRSC traffic fines is Remita, rather than the Payfast Now platform used by the fraudulent websites.
This distinction illustrates an important principle in digital compliance: authentication should not depend solely on appearance. A website can look official and still be unauthorised. A payment page can appear professional and still have no legitimate connection to the institution whose identity it invokes.
The compliance question therefore becomes: does the entire transaction chain, from notification to website to payment, correspond with the institution’s approved process?
In the FRSC case, the fraudulent platforms failed that test.
The Human Cost Behind the Metrics
The N400,000 loss reported by Ibiam gives the story a human dimension that statistics alone cannot capture.
Her experience also demonstrates why phishing campaigns built around government services can be particularly effective. The target is not merely being promised an investment return or persuaded to buy a product. The message suggests that the recipient has committed an offence.
That changes the psychology of the transaction.
A person receiving a message about an alleged traffic violation may be more concerned with resolving the problem than investigating the authenticity of the website. A discount for immediate payment adds another layer of pressure.
FIJ reported that many other car owners subsequently posted versions of similar phishing messages on X after Ibiam’s warning, suggesting that the campaign was not directed at a single individual.
The precise number of people targeted remains unclear from the published investigation. But the existence of multiple website iterations, different domain names and reports from several motorists indicates a broader phishing operation rather than a single isolated fraudulent page.
That uncertainty is itself relevant to compliance. Effective incident management requires organisations to determine not only what has been detected but also the potential scale of exposure: how many people were targeted, how many interacted with the platform, whether personal information was submitted, whether payments were made and whether compromised information could be reused elsewhere.
The Regulators and the Rules
Nigeria already has standards governing government websites.
FIJ reported that the National Information Technology Development Agency’s Standards and Guidelines for Government Websites require websites and web applications to undergo security audits based on the Open Web Application Security Project Testing Guide before being hosted. The guidelines expect such audits to show zero high- and medium-risk alerts.
The guidelines also recognise that government websites are important points of contact between citizens and public institutions.
This matters because a government website is not simply another webpage. Citizens may assume that information appearing on it is authoritative and that services offered through it are legitimate.
That assumption creates a responsibility for public institutions to protect their digital identity.
The fake FRSC platforms demonstrate what can happen when criminals exploit that trust from outside the institution’s own infrastructure.
A Pattern Larger Than FRSC
FIJ’s September investigation did not occur in isolation. The publication connected the fake FRSC websites to earlier reporting on weaknesses in Nigerian government and public-service digital platforms.
In July 2024, FIJ reported that 26 of Nigeria’s 36 states and the Federal Capital Territory had substandard government websites after assessing their functionality, accessibility and reliability.
In April 2024, the publication reported that the Nigeria Police Force’s online cybercrime-reporting portal presented security concerns and did not comply with relevant NITDA standards.
More recently, FIJ reported in March that the Nigeria Open Contracting Portal, operated by the Bureau of Public Procurement, had been without a valid Secure Sockets Layer certificate since October 2025.
These cases are different in nature and should not automatically be treated as evidence of the same underlying failure. But together, they raise a recurring compliance issue: digital government services require continuous oversight because citizens increasingly depend on them as official points of contact.
The FRSC case adds another dimension. It is not merely that a government platform might contain a vulnerability. A criminal can create a separate platform that borrows the institution’s identity and exploits the public’s confidence in it.
When Journalism Becomes an Early-Warning System
The two fraudulent FRSC websites eventually became inaccessible after FIJ published its investigation.
That sequence gives the story one of its most compelling features.
The reporting did not merely document an existing problem; it was followed by a visible change in the status of the websites. The takedown demonstrates the potential value of external scrutiny as part of the wider compliance ecosystem.
Investigative journalists, consumers, regulators, cybersecurity researchers and technology companies can all become sources of early warnings. Their observations can identify threats that formal monitoring systems have not yet detected.
But taking down two websites does not necessarily eliminate the underlying risk.
FIJ itself noted that fraudsters can register new domains or redirect potential victims to other websites once an existing platform disappears.
That means the relevant compliance metric cannot simply be “website taken down”.
A stronger assessment would ask whether the institution can detect new impersonation attempts quickly, whether suspicious domains are reported to relevant registrars and authorities, whether motorists are warned through verified channels, whether victims can report losses easily and whether the organisation has a documented incident-response process.
The Compliance Lesson
The fake FRSC websites reveal a fundamental vulnerability in the digital relationship between government and citizens: trust can be copied.
A fraudulent actor does not need to reproduce an entire government system. It may only need the right logo, a convincing domain name, a fabricated offence and a payment page.
That makes digital compliance an ongoing process rather than a one-time technical exercise.
The shutdown of frsc-gov.sbs.ng and frsc.gov.eu.cc.ng is therefore an important immediate outcome, but the larger issue is what happens next. The enduring response must involve stronger public verification, continuous monitoring for impersonation, secure payment processes, rapid incident escalation and clear communication about authorised government channels.
For motorists, the episode is a warning that an official-looking website is not necessarily an official website.
For government institutions, it is a reminder that protecting citizens increasingly means protecting the digital identity through which citizens encounter the state.
And for compliance professionals, the story offers a broader lesson: a control is only effective if the public can recognise it, trust it and use it safely.
In the space between a text message and a payment page, that responsibility can determine whether a government service remains a channel of public trust or becomes a hunting ground for fraud.


No Comment! Be the first one.