Why Do "Nigerian" Scammers Say They are From Nigeria

Artificial IntelligenceInnovation & Discovery

? I periodically remind myself to re-read this 2012 by Cormac Herley at Microsoft, or at least the abstract. The answer to the question, in a nutshell, is that if someone responds, they are much more likely to be an appropriate, unsuspecting, profitable mark. False positives for the attacker are people who respond but will not fall for the scam: they are expensive to process. The obviously preposterous subject line does a lot of the triage. This little paper is a gem in its simplicity and for how it clearly points to the psychology of security at the heart of phishing. Humans are the weak links; whether they remain so depends on how badly AI agents increase the attack surface. "This allows us to view the attackers problem as a binary classification, and use Receiver Operator Characteristic (ROC) curves to analyze the economics." The most profitable strategy requires accurately distinguishing viable from non-viable users, and balancing the relative costs of true and false positives. We show that as victim density decreases the fraction of viable users than can be profitably attacked drops dramatically." The attacker's dilemma: "unless he can distinguish viable from non-viable users with great accuracy the attacker cannot find enough victims to be profitable. However, only by finding large numbers of victims can he learn how to accurately distinguish the two. [...] By sending an email that repels all but the most gullible the scammer gets the most promising marks to self-select, and tilts the true to false positive ratio in his favor."

https://www.microsoft.com/en-us/research/publication/why-do-nigerian-scammers-say-they-are-from-nigeria/