As more Ghanaians embrace digital services, cybercriminals are also finding new ways to exploit trust, steal information and manipulate victims. For journalists, the challenge is no longer just reporting these crimes, it is understanding the threats, verifying digital evidence and helping the public stay safe.
A phone call from an unknown number. A WhatsApp message from someone who appears familiar. An attractive investment opportunity. A link promising a job. A friend request from a stranger. These are ordinary experiences in Ghana’s increasingly digital society. But behind some of them could be a cybercriminal searching for the right opportunity to strike.
Today, mobile phones are used for banking, mobile-money transactions, work, education, shopping and social interaction. This growing dependence on technology has brought enormous opportunities, but it has also increased exposure to cyber threats.

That thinking is behind the National Community Media Cyber Capability Building Project, implemented by the Cyber Security Authority (CSA), the Africa Centre for Digital Transformation (ACDT) and the Government of the Czech Republic under the Czech Republic’s Transformation Cooperation Programme.
The project seeks to improve media coverage of cybercrime and strengthen public awareness of online safety. Through four training modules, journalists and media practitioners have been exposed to cybersecurity fundamentals, online fraud and cybercrime reporting, digital forensics, media ethics and law, child online protection and responsible reporting of cyber incidents.
Understanding the threat
One major lesson from the training is that cybersecurity is not simply about protecting computers. It involves protecting devices, networks, information and people from unauthorised access, misuse, alteration, disruption or destruction.

The training introduced three important principles: Confidentiality, Integrity and Availability. Confidentiality means sensitive information should only be available to authorised people. Integrity means information should remain accurate and unaltered, while availability means legitimate users should be able to access information and systems when needed. These principles have direct implications for journalists. A compromised phone, for example, could expose a confidential source, unpublished information or sensitive recordings.
Cybercriminals do not always need sophisticated technology to succeed. Sometimes, they simply manipulate people. Phishing and social engineering can use urgency, fear, authority, affection or trust to convince victims to disclose information or take actions they normally would not take.
A criminal may pretend to be a bank official, relative, employer or trusted organisation. The objective could be to obtain money, passwords, one-time codes or personal information. This is why simple precautions matter: unique passwords, multi-factor authentication, regular software updates, secure backups and careful handling of unexpected messages and links.
When trust becomes a weapon
The training on online fraud showed that many scams follow a pattern. The criminal first establishes contact, then tries to build trust. The victim is subsequently pushed into an action, such as transferring money, clicking a link or sharing information. Once something valuable is obtained, the criminal may return with further demands or threats. These methods can be used in mobile-money fraud, romance scams, fake investments, job and scholarship scams, business email compromise, identity theft, account takeover and sextortion.

For journalists, however, reporting that someone has been defrauded is not enough. A cybercrime report should establish what happened, what has been verified, what evidence exists, which institution is handling the matter and what useful lesson the public can learn from it. Victims should also be treated with dignity rather than blamed for falling for a scam. Criminals can deliberately study and manipulate their targets, meaning even educated and experienced people can become victims.
Can we trust what we see online?
Another important lesson from the programme concerns digital forensics and verification. A photograph appearing on social media is not automatically proof of an event. A genuine video can be old, taken from another country or accompanied by a false caption.

Journalists must therefore verify digital material before publishing it. The training stressed the importance of preserving the original material. Where possible, a journalist should record where a file came from, when it was received and its original source before working on a copy.
Images can be subjected to reverse-image searches, while dates, locations, landmarks, signs and other details can be compared with independent sources. Metadata may also provide information about a digital file, but it must be treated carefully because it can be removed or manipulated. The lesson for journalists is this: Do not believe digital content merely because it looks convincing. Verify it.
Protecting children online
Cyber threats are not limited to financial crime. Children increasingly use the internet for education, entertainment and communication, but they can also encounter cyberbullying, grooming, sextortion, harmful content and sexual exploitation.

Grooming may involve an offender gradually gaining a child’s trust for sexual exploitation. Sextortion can involve threatening to expose intimate material unless the victim provides money, more images or meets other demands.
The training emphasised that journalists reporting such cases have an additional responsibility to protect the child. A report should not unnecessarily reveal a child’s name, face, school, location or other information capable of identifying them. Journalists should also avoid language that blames or humiliates the victim. Protecting children must take priority over producing a sensational story.
Don’t turn criminals into news sources
Cybersecurity reporting can become even more sensitive when an attack involves a major public institution or critical infrastructure. One striking lesson from the training was that a defaced website does not automatically mean an institution’s entire system has been compromised. Journalists should establish the actual scale of an incident before reporting it.

Cybercriminals may also exaggerate their achievements to create fear and confusion. If journalists immediately repeat such claims without verification, the media can unintentionally become a loudspeaker for the attackers.
Likewise, revealing details of a security vulnerability while specialists are still fixing it could provide other criminals with information they can exploit. Responsible reporting therefore requires a balance between the public’s right to know and the responsibility not to cause additional harm. Accuracy, fairness, privacy, public interest and minimising harm must guide the journalist’s decisions.
The media can become part of the defence
The biggest lesson from the four modules is perhaps that journalists are not passive observers in the fight against cybercrime. They can become an important link between cybersecurity professionals and ordinary citizens.

A radio presenter can teach listeners never to disclose their PIN or one-time password. A journalist can expose an emerging scam without publishing information that teaches criminals how to reproduce it. A news report can help parents recognise signs of online grooming.
A reporter can prevent misinformation from spreading by verifying a viral image before publication. And during a major cyber incident, responsible journalism can inform the public without creating unnecessary fear.
When something suspicious happens online, citizens should also know where to seek assistance. The training highlighted the Cyber Security Authority’s 292 short code as an official channel for cybersecurity incident support.

Cyber threats will continue to change as technology evolves. The solution is therefore not to become afraid of technology, but to become better informed about how we use it.
For citizens, that means thinking before clicking, protecting personal information and questioning suspicious requests. For parents, it means paying attention to children’s online activities. For institutions, it means protecting systems and the people who depend on them.
And for journalists, the responsibility is this: Verify before publishing. Preserve digital evidence. Protect victims. Avoid unnecessary panic. Explain cyber threats in language people understand.

The hidden cyber threats facing Ghanaians may begin behind a screen. But through informed citizens, responsible journalism and stronger cooperation between the media and cybersecurity professionals, they do not have to remain hidden.
In today’s digital Ghana, cybersecurity awareness is no longer only a technical necessity. It is a public responsibility.
By: Victor Wilson Lavor








