How to Avoid Software Development Scams in Nigeria

Outright fraud is only part of the problem. Most Nigerian businesses that lose money on software projects are not defrauded by a criminal enterprise; they are let down by an entity that took a deposit it could not deliver against, subcontracted the work to someone cheaper, or built something functional that it then refused to hand over.
The defences are the same in both cases, and they are unglamorous: verification, structured payments, documented scope and ownership of your own assets. A business that does those four things is a difficult target for a fraudster and a difficult client for an incompetent vendor.
What counts as a software development scam
It helps to separate three situations, because your response differs.
- Fraud. Taking payment with no intention or capacity to deliver. Money collected, work never started, entity disappears or stops responding.
- Bad faith. Real work happens, but the vendor misrepresents something material: the team, the ownership of the code, the origin of the product, or the true cost of the finished system.
- Incompetence. Genuine effort, inadequate skill or capacity. No deception, but the money is still gone and the system does not work.
Legally these differ; commercially they feel identical. The precautions below reduce all three, because you cannot reliably tell which one you face until money has moved.
The most common scams and bad-faith practices
| Pattern | How it presents | What exposes it |
|---|---|---|
| Borrowed portfolio | Impressive project list, no verifiable link to the vendor | Ask which parts they built and for a reference from that client |
| Phantom team | "Our team of 20 engineers" with no named people | Ask to meet the developer who will write your code |
| Deposit and disappear | Large upfront demand, urgency, discount for paying today | Refuse; pay milestones only |
| White-label resale | "Custom" system is a licensed product rebranded | Ask what is custom, what is licensed, and who owns each |
| Undisclosed subcontracting | Your contract is with A, the work is done by C | Ask directly; require disclosure in the contract |
| Perpetual 90% | Endless progress reports, no testable system | Demand a staging environment from the first milestone |
| Code hostage | Refusal to hand over code or credentials at the end | IP assignment clause and company-owned repository |
| Hosting and licence hostage | Accounts in vendor's name, renewal fees inflated | Own every account in your company's name |
| Scope bait | Very low quote, essentials priced as extras later | Compare quotes on an identical written scope |
| Unlicensed components | Pirated themes, plugins or libraries used | Require a written list of third-party components and licences |
| Fake references | Referee is a friend or an employee | Source at least one reference yourself from their stated clients |
| Advance-fee variants | Requests for "server deposit" or "licence fee" paid to a personal account | Pay a corporate account against an invoice only |
None of these require sophistication to run, and none survive a client who insists on verification and staged payment.
Warning signs before you pay anything
Treat any three of these appearing together as a reason to stop and verify further.
- No CAC registration you can confirm, or a name that does not match the account you are asked to pay
- Payment requested into an individual's personal account rather than a business account
- Pressure to decide today, or a discount that expires in hours
- A quote that is dramatically below every other quote for the same scope
- Refusal to provide a written proposal with scope, timeline and exclusions
- No contract, or a one-page document with no ownership, acceptance or termination terms
- Reluctance to name the developers who will do the work
- A portfolio of screenshots with no live links or client names
- Promises of guaranteed outcomes: "your system will handle a million users", "we guarantee first page of Google"
- Demand for 100% payment upfront, or over 50% before anything is delivered
- Unwillingness to give you an administrator account on the systems being built
A legitimate vendor may occasionally tick one of these — a small studio might genuinely prefer a higher deposit, for instance. A pattern is what matters.
How to verify that a software company is real
Spend two hours on this before you spend millions of naira.
- Check CAC registration. Ask for the registered company name and RC number, then confirm it through the Corporate Affairs Commission's public search (https://www.cac.gov.ng/). Confirm the name on the invoice matches the registered entity.
- Confirm the bank account belongs to the company. Payment should go to a corporate account in the same name as the contracting entity. A personal account for a ₦5,000,000 project is a serious warning sign.
- Verify a physical presence. Visit the office if you are in the same city, or hold a video call from the workspace. For remote vendors, confirm a verifiable business address and speak to more than one member of staff.
- Check digital footprint consistency. A company domain email rather than a free email address, a site that has existed for more than a few weeks, professional profiles for named staff, and consistent details across channels.
- Get references and source one yourself. Ask for two clients, and separately identify a third from their stated project list and contact that business directly. Ask the referee specific questions: Did the project finish? Was it on budget? What happened when something broke? Did you receive the code and credentials?
- Check that the people exist and work there. Ask for the names and roles of the project manager and lead developer, and meet them on a call before signing.
- Ask who else is involved. Any subcontracting or offshore partner should be disclosed and named in the contract.
How to verify technical capability, not just a portfolio
A real company can still be the wrong company. Capability checks that are hard to fake:
- Ask for a live system you can use. Screenshots prove nothing; a URL and a demo account prove something.
- Ask what they built versus what they maintained. Many portfolios mix both.
- Request a technical walkthrough. Have them explain the architecture for your project in business terms: where data lives, how it is backed up, how users are authenticated, how it scales.
- Probe the awkward parts of your own requirement. If you need payment reconciliation or multi-branch stock, ask how they have handled it before.
- Request a paid discovery phase. A small, separately priced discovery producing a requirements document and plan lets you assess the team for an indicative ₦150,000–₦600,000 before committing to the full build. If the document is thin, you have learned something cheaply.
- Ask about testing and handover. A vendor who cannot describe their QA process or the contents of a handover pack has probably not done either before.
Payment structures that protect you
The payment schedule is your strongest practical protection, because it limits what a bad actor can take.
| Structure | Risk to you | When it is reasonable |
|---|---|---|
| 100% upfront | Very high | Almost never |
| 70% upfront, 30% on completion | High | Rarely; only for very small, very short work |
| Milestone-based with 20–30% kick-off | Moderate and manageable | The normal, defensible structure |
| Milestones plus 5–10% retention | Lowest | Preferred on projects above a few million naira |
Indicative norms rather than fixed rules; vendors differ and some staged structures are negotiable.
Principles to apply:
- Tie every payment to a deliverable you can inspect, not to a date or a percentage complete.
- Keep the kick-off payment proportionate. It should cover the vendor's early work, not the whole project.
- Hold a retention of 5–10% released 30–60 days after go-live.
- Pay a company account, on an invoice, with the project name and milestone stated.
- Never pay ahead of the schedule because of a hardship story. Sympathy is not a contract term.
- Keep a payment record with dates, amounts, invoice references and what each payment was for. If a dispute arises, this is your evidence.
Contract clauses that make a scam hard
A signed contract will not stop a determined fraudster, but it makes bad faith expensive and gives you standing to recover. At minimum, insist on:
- Parties and entity details, including RC number and registered address.
- Scope, with a feature list and a written out-of-scope list.
- Milestones and acceptance criteria, defining how a deliverable is judged complete.
- Payment schedule matching those milestones, with retention.
- Intellectual property assignment of custom code, designs and documentation to your company on payment.
- Third-party components list, with licence types, and a warranty that nothing unlicensed is used.
- Source code delivery, specifying a repository owned by your company, with commits made throughout the project rather than dumped at the end.
- Credentials and accounts, requiring everything to be created in your company's name.
- Confidentiality and data protection, covering how your customer data is handled under the Nigeria Data Protection Act 2023.
- Subcontracting disclosure, requiring written consent.
- Warranty period for defect fixes after go-live, typically 30–90 days.
- Termination and exit, including what you receive if the relationship ends early.
- Dispute resolution and governing law, with a Nigerian forum specified.
Have a Nigerian lawyer review any contract of significant value. This article explains commercial risk; it is not legal advice.
Ownership and access: never let your system be held hostage
The most common form of leverage used against Nigerian businesses is not theft of money — it is control of assets.
Create these in your company's name, with your business email as owner, before development starts:
- Code repository account, with the vendor added as a collaborator
- Cloud or server hosting account and billing
- Domain registrar account
- Database and any managed service accounts
- Payment gateway account (Paystack, Flutterwave, Interswitch, Moniepoint or similar)
- Email and workspace accounts
- Analytics and monitoring accounts
- Any third-party API or licence subscriptions
Then ask for commits to the repository from week one. A repository that fills up steadily is evidence of work. A repository that stays empty until "handover" is a risk you should not accept. Ask for a deployment or setup document as a milestone deliverable, so another developer could take over.
If a vendor resists creating accounts in your name, that resistance is the answer to the question you were asking about them.
Example (hypothetical): a ₦12 million platform that never appeared
Example (hypothetical). A Port Harcourt equipment-leasing company commissions a leasing management platform. The quote is ₦12,000,000 against competing quotes of ₦18,000,000 and ₦21,000,000. The vendor asks for 60% upfront "to mobilise the team", paid into an account whose name differs slightly from the company on the proposal.
What the business does not do: verify the RC number, ask to meet the developers, or require a staging environment. There is no written contract, only a proposal and WhatsApp messages.
How it unfolds: weekly updates arrive as documents and screenshots for three months. The first request to see a working system is met with "it is in final testing". At month five the vendor stops responding. There is no repository, no server the company controls, and no signed agreement.
What would have changed the outcome, at almost no cost:
- Confirming the entity and paying only a company account matching the contract
- A kick-off payment of 25% rather than 60%
- A staging URL as the milestone-two deliverable, with payment withheld until the finance manager could log in
- A repository in the company's name with the vendor as collaborator
- One reference call to a client the company found independently
- A ₦400,000 paid discovery phase before committing ₦12,000,000
The wide gap between the quotes was not a bargain. On an identical written scope, a quote far below the market usually means a different scope, a different level of capability, or a different intention.
What to do if you have already lost money
Act quickly and in order.
- Stop further payments immediately, including any standing instruction or recurring charge.
- Secure what you can reach. Change passwords on any account you control, remove the vendor's access from your systems, and download any code, designs or data you can access.
- Assemble evidence. Proposal, invoices, transfer records, contract and messages, exported with dates.
- Send a formal written demand to the registered company address and email, stating what was paid, what was due, and a deadline for delivery or refund. Keep proof of delivery.
- Instruct a Nigerian lawyer. For amounts of any significance, a solicitor's letter and, if needed, a civil claim is the route to recovery.
- Report to your bank. Provide transaction details promptly; timing affects what any financial institution can do.
- Report suspected fraud to the Nigeria Police Force and, for online financial fraud, the Economic and Financial Crimes Commission. Take your documentary evidence with you.
- Salvage the project. Have an independent developer assess whatever exists. Sometimes partial work is usable; often a clean rebuild on a properly structured contract is faster than fighting for a half-finished system.
None of this is legal advice. A qualified Nigerian lawyer should guide the recovery steps for your specific situation.
What changes for Nigerian businesses
- Deals run on relationships and WhatsApp. Referrals and chat are how much Nigerian technology procurement happens. Keep the speed, but convert every material agreement into a signed document. A referral is not due diligence.
- Bank transfer is final. There is no chargeback on a transfer the way there can be with a card payment. Staged payments matter more here than in markets where reversal is easier.
- Entity verification is accessible. CAC registration is publicly searchable, which makes a basic check cheap. Very few victims perform it before paying.
- Wide price dispersion is normal. Quotes for the same system can differ by a factor of three or more because scope, seniority and support differ. That variance is also cover for unrealistic quotes, so always compare on identical written scope.
- Foreign-currency costs create pretexts. "The dollar moved, we need more for servers" is sometimes true and sometimes a pretext. Require recurring costs to be itemised at quotation and billed to accounts you own.
- Informal teams are common and not inherently bad. Many capable Nigerian developers work as small partnerships. Judge them on verifiable work, a proper contract and staged payments rather than on office size.
- Data protection duties are yours. If a vendor mishandles customer data, your business still carries obligations under the Nigeria Data Protection Act 2023. Put data handling terms in the contract and check the Nigeria Data Protection Commission's current guidance.
Mistakes that make businesses easy targets
- Choosing on price alone. The lowest quote on a complex system is usually the least complete.
- Paying before verifying. Two hours of checks protect months of budget.
- Working without a contract because "we know each other". Relationships change when money is at stake.
- Letting the vendor own the accounts. This is how leverage is created.
- Accepting screenshots as progress. Insist on logging in yourself.
- Paying extra to regain access to your own system. Once you pay a ransom, expect another demand.
- Not talking to references. One phone call reveals more than a polished proposal.
Conclusion
Avoiding software development fraud in Nigeria is a procurement discipline, not a matter of intuition. Verify the entity through CAC and references you sourced yourself, meet the people who will write the code, buy a small paid discovery before a large build, pay milestones against deliverables you can open and test, retain a final percentage, and hold every account and repository in your company's name. Businesses that do this rarely lose large sums, because there is never a large sum sitting with an unproven vendor.
If you are evaluating proposals for a custom system and want a second opinion on the scope, the milestone structure and the ownership terms before you sign, Linestech can walk you through how a properly structured software engagement should be set up.
Frequently asked questions
Is a very low quote always a scam?
No, but it always requires explanation. A lower price can reflect a smaller team, less overhead, a simpler technical approach or genuine efficiency. Ask what is excluded, who does the work, what happens after launch, and what the recurring costs are. If the vendor cannot explain the difference in scope terms, treat the quote as incomplete rather than cheap.
Should I use an escrow service for software payments?
Milestone payments achieve most of the same protection with less friction, and are the common practice in Nigeria. If you do use a third-party escrow arrangement, verify the provider independently, understand the release conditions and the fees, and never use an "escrow" account introduced by the vendor without your own verification.
How much should I pay upfront?
A kick-off payment of roughly 20–30% of the project value is a defensible norm for a custom software build, with the balance released against accepted milestones and a 5–10% retention after go-live. Demands above 50% before any deliverable exist should prompt questions, and 100% upfront should be refused.
Can I get my money back if the developer disappears?
Sometimes, and it depends on evidence, timing and whether the entity is traceable. A signed contract, invoices, transfers to a company account and written correspondence make recovery far more realistic than a WhatsApp arrangement and a personal-account transfer. Act quickly, involve a lawyer, and report suspected fraud to the police or the EFCC.
How do I check a developer's portfolio is genuine?
Ask for live URLs or installable apps rather than images, ask specifically which components they built, and contact at least one client you identified yourself rather than only the referees supplied. If work was done under a non-disclosure agreement, a genuine vendor will say so and offer an alternative demonstration.
Is it safer to hire an agency than a freelancer?
Neither is inherently safe. An agency usually offers continuity, QA and a registered entity to hold accountable; a freelancer may be more affordable and equally reliable. The protections that matter are the same for both: verified identity, written contract, staged payments, company-owned accounts and IP assignment.
What if my vendor refuses to release my source code?
Check your contract first: an IP assignment clause effective on payment gives you a clear position. Send a written demand referencing the clause. If the code was committed throughout the project to a repository in your company's name, the issue rarely arises, which is why that arrangement belongs in the contract rather than in a dispute.
Sources and further reading
Figures, platform rules and regulations change. These are the primary references behind this article and the places to check before you act on it.


