Online shopping makes it easy to order almost anything from your phone, but it also creates opportunities for scammers to steal card details.

Your card number, expiry date, CVV and verification codes can be valuable to criminals. A fake shopping website, phishing message or compromised device can turn a normal purchase into an account-security problem.

The good news is that a few habits can significantly reduce your risk.

Here are the best practices to follow whenever you use your card online.

1. Shop Through the Official Website or App

Don't enter your card details into a website just because someone sent you a link.

If you see a product advertised on Instagram, Facebook, WhatsApp or X, consider opening your browser and manually entering the retailer's known website instead.

Scammers can create websites that look almost identical to legitimate stores.

The FTC recommends researching unfamiliar sellers and checking reviews, complaints and scam reports before buying.

2. Check the Website Address Before Paying

Before entering your card information, look carefully at the website address.

A secure connection normally uses:

https://

The padlock and HTTPS indicate that the connection is encrypted, but they do not prove that the website itself is legitimate. Scammers can also use HTTPS.

Look for other warning signs:

  • Misspelled domain names

  • Strange characters in the address

  • Unexpected redirects

  • A domain that doesn't match the company

  • A checkout page you've never seen before

  • Pressure to pay immediately

For example, a scammer might create a domain that looks similar to a real retailer but uses a different spelling.

3. Never Send Your Card Details Through Chat

A legitimate seller generally shouldn't need you to send your full card information through:

  • WhatsApp

  • Instagram DM

  • Facebook Messenger

  • SMS

  • Email

  • Telegram

Be especially suspicious if someone asks you to send:

Card number + expiry date + CVV + OTP

Those details should not be handed to a person in a chat.

If payment is legitimate, use the retailer's official checkout or a trusted payment page.

4. Never Share Your OTP

Your OTP is not a "confirmation code" you should give to a seller.

It is a security credential used to authorize certain transactions or account actions.

If someone calls or messages claiming to be from your bank and asks you to read out an OTP, stop.

Contact your bank through an official channel instead.

Phishing scams commonly attempt to trick people into providing financial information through fake messages and links.

Rule: Your OTP stays with you.

5. Don't Save Your Card on Every Website

Saving your card can make future purchases faster, but it also means the retailer or payment service retains payment information according to its systems and policies.

For stores you don't regularly use, consider entering your details only when necessary.

If a shopping site gives you the option to use a trusted payment wallet or other payment method without directly storing your card details, that may reduce the number of places where your card information is stored.

6. Use a Separate Card for Online Shopping

If your bank provides multiple cards or account options, consider using a card dedicated to online purchases.

For example, you could keep only the amount you expect to spend available on the card used for online shopping.

This doesn't make fraud impossible, but it can reduce the potential exposure of your primary funds.

Check with your bank for available card controls, spending limits or online transaction controls.

7. Turn on Transaction Notifications

Enable your bank's transaction alerts if available.

You want to know quickly when your card is charged.

Don't ignore a transaction notification simply because the amount is small.

A small unfamiliar transaction can be a sign that someone is testing whether stolen card details work.

Review your account regularly and report suspicious transactions to your bank immediately.

CBN's card rules require card issuers to provide a means for customers to report loss, theft or fraudulent use of a card at any time and take steps to stop further use of the affected card.

8. Use Strong Security on Your Banking App and Email

Your card isn't the only thing you need to protect.

Your email and banking accounts can also be used to access sensitive information or approve account changes.

Use:

  • Strong, unique passwords

  • Two-factor authentication where available

  • Device screen locks

  • Updated operating systems

  • Updated banking apps

  • App-store downloads rather than random APK files

The FTC recommends two-factor authentication as an additional layer of account protection.

9. Be Careful With Social-Media Ads

A product appearing in a Facebook or Instagram advertisement doesn't automatically mean the seller is trustworthy.

Before buying, research the seller independently.

Search:

Seller name + scam

or:

Seller name + complaints

Also check:

  • How long the account has existed

  • Customer complaints

  • Reviews outside the seller's page

  • Return policy

  • Physical/business information

  • Whether the prices make sense

Extremely low prices can be a warning sign, especially for expensive products.

10. Don't Let a "Limited-Time Offer" Rush You

Scammers often create urgency.

You might see:

"Only 2 left!"

"Pay in the next 10 minutes!"

"Your discount expires now!"

Don't allow a countdown timer to make you ignore basic security checks.

Stop and verify the seller first.

A genuine discount is not worth losing your card details.

11. Avoid Suspicious Payment Links

Imagine you receive:

"Your order could not be delivered. Click here to update your card."

Don't click.

Instead, open the retailer's official app or website yourself and check your order.

The same applies to messages claiming:

  • Your payment failed

  • Your card has been blocked

  • You need to verify your account

  • Your refund is waiting

  • Your delivery requires another payment

  • Your bank account needs verification

The FTC advises people not to click unexpected links requesting payment information and instead contact the company through a known legitimate website or phone number.

12. Don't Assume a Padlock Means "Safe"

This is an important distinction.

HTTPS = encrypted connection.

It does not mean:

"This website is trustworthy."

Scammers can obtain HTTPS certificates for fraudulent websites too.

So use HTTPS as one security check, not your entire security check.

13. Keep Your Phone Updated

Your phone is effectively your shopping device, banking device and authentication device.

Keep:

  • Android/iOS updated

  • Browser updated

  • Banking apps updated

  • Security software updated

Don't install suspicious applications simply because a website tells you that you need them to complete a payment.

14. Don't Shop on Public or Untrusted Devices

Avoid entering card information on:

  • Public computers

  • Someone else's phone

  • Untrusted shared devices

  • Computers with unknown software

If you must use a shared device, avoid saving passwords or card details and log out completely afterwards.

15. Check the Amount Before Confirming

Before pressing Pay, look carefully at:

  • Product price

  • Delivery fee

  • Taxes

  • Currency

  • Quantity

  • Final amount

Scammers can also manipulate users into paying more than expected.

Take a screenshot or save the receipt for important purchases.

The FTC recommends keeping records of the seller, purchase, amount paid, communications and transaction records.

What To Do If You Think Your Card Details Were Exposed

Don't wait until money disappears.

Step 1: Contact your bank immediately

Use the official number on your card, your bank's official app or its verified website.

Tell the bank that your card details may have been compromised.

Step 2: Ask about blocking or freezing the card

Your bank can tell you whether the card should be blocked, replaced or restricted.

Step 3: Monitor your account

Look for unfamiliar transactions.

Step 4: Change compromised credentials

If you entered your banking password on a suspicious website, change it immediately from the official banking app or website.

If you reused that password elsewhere, change it there too.

Step 5: Preserve evidence

Keep:

  • Screenshots

  • Website address

  • Order confirmation

  • Emails

  • WhatsApp/DM conversations

  • Transaction reference

  • Payment receipt

Step 6: Report the fraud

Your bank should be your first point of contact for an unauthorized card transaction.

The FTC likewise recommends contacting the card issuer or bank immediately when unauthorized card use occurs.

The 10-Second Card Safety Checklist

Before entering your card details, ask:

☐ Is this the real website or app?

☐ Did I open it myself or click an unexpected link?

☐ Does the domain look correct?

☐ Is the connection encrypted?

☐ Have I checked the seller?

☐ Is the price realistic?

☐ Am I being pressured to pay?

☐ Am I entering my details directly into a secure checkout?

☐ Am I being asked to send card details through chat?

☐ Is anyone asking me for my OTP?

If something feels wrong, stop the payment and verify first.

The Golden Rule

Your card details should be treated like sensitive financial information.

Don't send them to strangers.

Don't enter them into suspicious websites.

Don't share your OTP.

Don't click unexpected payment links.

And report suspicious transactions to your bank immediately.

Online shopping doesn't have to be dangerous.

The key is to slow down long enough to verify who you're paying, where you're paying and what you're authorizing.