Gmail extension detects Nigerian fintech phishing with sender checks and AI
A Gmail-Based Phishing Detection Prototype for Nigerian Fintech Emails Using Sender Checks and BiLSTM Classification
Cryptography and Security
Summary
Phishing emails trick people by pretending to be from trusted Nigerian fintech companies. The authors made a Gmail extension that checks sender addresses and links, plus uses a special AI model called BiLSTM to spot scam emails. Their tests showed very high accuracy on a large collection of emails, though some data overlap may make the results look better than they are. They demonstrated the extension works in Gmail, but haven’t fully tested it on new unknown phishing emails yet.
What this means in practice
- •For email security teams: Use the integrated sender and URL checks with BiLSTM to flag suspicious Nigerian fintech emails in corporate Gmail accounts.
- •For browser extension developers: Build similar email protection tools based on combining domain checks and deep learning models to improve phishing detection.
Tested on one dataset.
Authors
Gideon Francis Oghie, Uche Emmanuel Unoke
Abstract
Phishing emails that impersonate Nigerian fintech providers can combine deceptive sender addresses, lookalike links, and locally familiar language. This study presents a Gmail browser extension that integrates sender-domain and URL checks with a bidirectional long short-term memory (BiLSTM) classifier. The extension compares visible sender addresses and links with profiles for eight fintech platforms, obtains a phishing probability from a locally hosted Flask service, and displays a legitimate, warning, or phishing verdict when an email is opened. The BiLSTM classifier was evaluated on 8,943 test messages from a cleaned dataset of 59,622 phishing and legitimate emails. The test confusion matrix recorded 4,308 true negatives, no false positives, one false negative, and 4,634 true positives. These counts correspond to 99.99% accuracy, 100.00% precision, 99.98% recall, and 99.99% F1 score. Tokenized sequence analysis identified 5.79% overlap between the training and test sets, which may inflate performance estimates for independent messages. A Gmail demonstration showed the integrated extension producing user-visible verdicts, although the complete system was not evaluated on a labeled test set. The findings establish the feasibility of the implemented prototype while leaving its end-to-end detection performance and generalization to unseen attacks open for further evaluation.