Technology

June 24, 2026

Weak passwords, fake links biggest threats to journalists — Expert warns

Weak passwords, fake links biggest threats to journalists — Expert warns

By Juliet Umeh

The Wole Soyinka Centre for Investigative Journalism, WSCIJ, has identified weak passwords, phishing links and poor digital security habits as some of the biggest threats facing investigative journalists, warning that a single security lapse could expose confidential sources, compromise sensitive investigations and damage newsroom credibility.


The warning was issued during the Civic Space Guard Holistic Safety Masterclass for Investigative Reporters, where Technology and Innovation Officer at WSCIJ, Stefan Akinnimi, trained journalists on practical measures for protecting their digital assets amid increasingly sophisticated cyber threats.


According to Akinnimi, cybercriminals are no longer relying on crude scam messages but are now deploying personalised attacks designed to exploit journalists’ trust and professional activities.


“Today’s session is not about turning anyone into a cybersecurity expert. It is about building simple digital safety habits that reduce harm. We are looking at common risks, tools that can help, and what to do when something goes wrong,” he said.


Akinnimi explained that the training focused on three key areas: threats, protection and response.
He listed phishing attacks, account takeovers, malicious files, impersonation and device loss among the most common threats facing journalists.


According to him, digital security is particularly important because investigative journalism often involves sensitive information, powerful interests and confidential sources.


“Investigative journalism is consequential journalism because it can expose wrongdoing, trigger accountability and affect powerful individuals or institutions. That is why security matters. When you are working on sensitive stories, your security is also at risk,” he said.


He warned that compromised accounts and devices can have serious consequences for journalists and their sources.


“A weak account can expose a source. A stolen phone can reveal notes, photos and locations. A malicious document can compromise a device, while a fake message can damage trust in a journalist or newsroom,” he said.


Akinnimi stressed that digital security extends beyond protecting laptops and mobile phones.
According to him, journalists must also safeguard confidential sources, unpublished investigations, research materials, evidence, cloud storage, social media accounts, content management systems and even their movement patterns.”Digital security is not just about devices. It is about protecting people, evidence and trust,” he said.


To demonstrate how cyber attacks occur, Akinnimi shared a case study involving a professional who clicked on what appeared to be a legitimate project collaboration link.


The victim was directed to a fake Google Drive page designed to harvest login credentials and infect his computer with malicious software.


“The attackers made the message look legitimate because it was connected to the person’s professional work. It appeared to be a genuine collaboration opportunity, so he trusted it and clicked,” Akinnimi explained.


He noted that modern cybercriminals frequently gather information from social media platforms, professional profiles and public records to create highly convincing phishing campaigns.


“Gone are the days when attackers simply send messages claiming you have won money. They study their targets, learn about their activities and send messages that look completely normal,” he said.


He identified several warning signs of phishing attacks, including urgent requests to open documents, unexpected password confirmation requests, suspicious interview invitations and messages supposedly sent by editors or colleagues.


Before acting on such requests, he advised journalists to verify the sender’s identity, inspect web links carefully and avoid sharing passwords or authentication codes.


Akinnimi also described email accounts as the “master key” to a person’s digital life because they can be used to reset passwords on multiple platforms.


He therefore urged journalists to use different passwords for different accounts and avoid reusing credentials across platforms.


“Many people use the same password everywhere. If an attacker gains access to one account, they can use the same credentials to access other accounts. That is why unique passwords are essential,” he said.
To strengthen account security, he recommended the use of password managers and multi-factor authentication, MFA, which requires an additional verification code before access is granted.


“Even if an attacker gets your password, they will still need the verification code. That extra layer can stop many attacks,” he explained.


He further advised journalists to regularly review active login sessions, remove unfamiliar devices and revoke access granted to unnecessary third-party applications.


Responding to questions from participants, Akinnimi warned about the risks associated with public Wi-Fi networks in hotels, airports and other public locations.


According to him, some cybercriminals create fake Wi-Fi networks with names similar to legitimate services in order to intercept users’ data and credentials.


He urged journalists to adopt proactive security habits, maintain regular backups of important files and remain vigilant against unsolicited messages and suspicious links.


“The reality is that cyber attackers are getting smarter every day. Prevention remains the best defence. Journalists must think before they click, verify before they trust and secure their accounts before it is too late,” he said.