Hackers can target your wealth adviser’s WhatsApp: How to protect your money

Recent incidents highlight the increasing threat of compromised WhatsApp accounts among financial advisers in India. These attacks exploit trust, as fraudsters impersonate advisers through hacked accounts. Financial firms have implemented strict n...

Hackers can target your wealth adviser’s WhatsApp: How to protect your money
The message looked routine. A financial firm’s WhatsApp account had sent what appeared to be an important document to team members, asking them to open it on their computers, not their phones. The sender’s name was familiar.

Across India, financial advisers and wealth managers have been encountering a version of the same incident over the past several weeks. A WhatsApp account belonging to the firm, a senior executive, or a trusted colleague gets compromised through malware downloaded on a linked laptop. The account then sends malicious files to contacts, wrapped in the credibilit of a name the recipient already trusts. A compliance notice, a GST document or a statement of account. Something you would normally open without thinking twice.

Ajay Sehgal, Director at Allegiance Financial, a wealth management firm that serves over 1,000 clients, was among those who encountered this. One of his team members, while downloading documents for research, inadvertently installed malware on a company laptop that was connected to a WhatsApp account as a secondary device. The attacker slipped in through that gap. “The person on the other side immediately gained access to the WhatsApp,” Sehgal says. The firm caught it before the file reached clients, isolating the laptop, logging out of all linked devices, blocking the SIM and re-registering WhatsApp. They also reported the incident on the government’s cybercrime portal.


“The important thing is that one has to report the matter to the Government of India cybercrime portal,” Sehgal says. His firm was not alone.

When WhatsApp becomes a cyber risk

im-2
AJAY SEHGAL

Director, Allegiance Financial

Clients: 1,000+

What happened?

Malware on a linked laptop compromised the firm’s WhatsApp account.
ADVERTISEMENT

New safeguards

Restricted WhatsApp access; reinforced IT policy; enabled two-factor authentication.
ADVERTISEMENT

im-3
VALANCE FERNANDES

CEO, Wealixir

Clients: 3,000+

What happened?

Tax team opened a malicious ZIP sent by a client; infection spread through WhatsApp.

New safeguards

Reduced document sharing on WhatsApp; explored secure file-upload systems.

im-4
PAWAN AGARWAL

QPFP®️, Founder, GoodMoneyMan Associates

Clients: 1,267

What happened?

Office WhatsApp number was taken over; clients received a malicious ZIP file.

New safeguards

Two-step verification; linked-device checks every three days; WhatsApp only on company computer.

im-5
BHUSHAN WANI

QPFP®️, Director, Crescent Mutual Fund Distributors

Clients: 6,147

What happened?

Accidentally downloaded a suspicious file received through a compromised WhatsApp account.

New safeguards

No WhatsApp-only transactions; phone call confirmation + email approval + NSE platform.

A hacked relationship

Prasanto Roy, a public policy adviser who works in cybersecurity and payments, argues that framing this as a WhatsApp vulnerability misses the point. “I would not put it down to a WhatsApp-specific issue,” he says. “Since WhatsApp is the leading driver of smartphone adoption, and is on 700-800 million phones as the default communication platform, there’s no question that it will become the platform for both commerce as well as for scammers.”

What makes a financial adviser’s compromised account particularly dangerous is the pre-existing architecture of trust. The fraudster does not have to build a fake identity from scratch. They inherit the adviser’s name, photograph, existing conversation threads, client list and, critically, the context of ongoing financial relationships.

“The commonest way of taking over this WhatsApp communication is a session hijack,” Roy says, “which goes through a WhatsApp Web session takeover. This is not as if it’s coming in through WhatsApp on your phone; it is installing malware on your PC to hijack WhatsApp web, and do a session takeover using tokens and cookies.”

ALSO READ | Why are Registered Investment Advisers so rare in India? The big reason may surprise investors

Najm Bilgrami, National Head of Liability Lines at Tata AIG General Insurance, puts it simply: “The biggest advantage for a fraudster is trust. A compromised WhatsApp account allows them to approach the victim through a channel they already trust and communicate in a familiar manner.” The fraudster doesn’t necessarily have to break into your bank account. He may first break into the person you trust with your money.

How the attack moves

The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, had issued a formal advisory on this threat on 7 August 2026. The agency had warned that self-propagating malware, disguised as account statements and RBI communications, was spreading over WhatsApp, SMS and e-mail. Further, chartered accountants, company directors, chief financial officers and corporate finance teams were the prime targets. The agency observed a sharp rise in complaints relating to WhatsApp account takeovers through malicious files circulated as account statements and regulatory communications. Incidents following an identical pattern have been reported from multiple states, including Delhi, Gujarat, Maharashtra and Rajasthan. I4C had intimated over 58,000 potential victims in the previous 30 days alone.

The mechanism is a multi-step chain. A compressed file arrives over WhatsApp bearing names like “Statement of Account. zip”, “RBI.zip” or “MCA.zip”, accompanied by a message designed to appear as either a routine financial document or an urgent regulatory notice. The archive contains a Windows executable file. Opening it on a desktop or laptop installs a Trojan that hijacks the active WhatsApp Web session. Once inside, the compromised account automatically circulates the same file to all contacts and groups, typically with a request to forward it to the recipient’s “finance manager for verification” and to open it on a computer. In the more advanced form of this attack, known as the “Boss Scam” or CEO impersonation fraud, the fraudster uses the captured executive account to instruct finance personnel to transfer funds to mule accounts.

When it comes to cyber scams in the financial adviser and wealth management ecosystem, the first target may not always be the client. It may be the adviser’s employee, laptop or WhatsApp Web session. The client becomes the next target.

Even experienced clients click

Valance Fernandes, CEO of Wealixir, which manages roughly 3,000 client families, encountered exactly this sequence. A client sent a file to his tax team. The team assumed it was a GST-related document from an existing client, a reasonable assumption, since clients regularly send them tax documents over WhatsApp. They opened it. The infection then forwarded itself from the tax team’s account to Fernandes. He opened it, believing it had come from his own staff. “Even our clients, who are highly sophisticated professionals, including company CFOs and national heads, opened the message because they were expecting documents from us,” Fernandes says.

ALSO READ | AI can pick the fund, but can it stop you from selling at the bottom?

The red flag here was not visible in the message. In the middle of a busy workday, while managing client files and expecting documents, a compressed file from a known contact can easily look like just another task. Fernandes’ firm immediately killed all WhatsApp sessions and formatted every infected device, without waiting to assess the extent of the damage. “We didn’t wait to see the damage. We formatted all our systems,” he says. “We also realised that we have no filter when it comes to WhatsApp; people are okay sending us bank statements, income tax statements, anything and everything.”

Drawing a line

Pawan Agarwal, QPFP®️, Founder - GoodMoneyMan Associates, which works with about 1,267 clients, had long followed a policy borrowed from his father’s pre-WhatsApp instincts: important client details, documents, and bank account information should only travel over email. WhatsApp was a communication channel, not a verification or transaction channel. Even so, the firm’s office number was taken over. Clients received a ZIP file asking them to share it with their finance manager. “All of a sudden I saw a few clients just calling back-to-back,” Agarwal says.

The difference was that the communication compromise did not automatically become a transaction compromise. The firm’s response was layered: they immediately contacted clients from a different number, posted warnings on WhatsApp status, implemented two-step verification for all business numbers, began checking linked devices every three days and restricted WhatsApp Business access to a single registered company computer on the company network. A draft email, ready to send to the entire client list, now sits in the firm’s email account. “Calling 1,200-1,500 people will take time, not easy. But email is the fastest thing that can be sent across,” Agarwal says.

A complete transaction

Bhushan Wani, QPFP®️, Director, Crescent Mutual Fund Distributors, which serves 6,147 clients, follows a three-step rule. If a client sends a WhatsApp message asking to redeem, the sales team calls the client on their personal number to confirm. The team then processes the transaction through the NSE Mutual Fund platform, and the client receives an email for approval. “We will not do any transaction only with the WhatsApp communication,” Wani says. Two of Wani’s clients have experienced WhatsApp-based fraud unrelated to investments. One, a well-educated engineer, was socially engineered through a combination of a birthday call, a fake parcel story and escalating pressure, ultimately transferring around Rs.20 lakh.

Separately, another client’s administrative employee received a WhatsApp call from what appeared to be the business owner’s account, complete with the owner’s display picture, and transferred Rs.35 lakh.

What if you get hit by a WhatsApp scam?

im-6_640x351
Mind the message

Never open unexpected ZIP, APK or exectable fules, particularly when the label references a statement, a regulatory body, income tax, KYC or GST.

im-7

What should you do differently?

The advisers’ experiences point to a consistent set of investor-side responsibilities.

A message from your adviser’s existing WhatsApp number is not sufficient verification for anything that involves money, a new product, changed bank details or an unusual instruction. Bilgrami recommends “stepping outside the WhatsApp conversation and independently verifying the request”, meaning a call to the known number, not a reply in the same thread.

Never open unexpected ZIP, APK or executable files, particularly when the label references a statement, a regulatory body, income tax, KYC or GST. I4C specifically advises against downloading, extracting or opening such files from unknown or unverified sources. Regulators such as the Reserve Bank of India do not distribute account statements or compliance notices as WhatsApp attachments.

Do not share One-Time Passwords (OTP), passwords or authentication credentials over WhatsApp, even if the request appears to come from a trusted adviser. For investment transactions, authenticate through the official platform.

The Securities and Exchange Board of India’s (Sebi) February 2026 circular requires regulated entities and their agents to disclose their registered name and registration number on social-media handles, including WhatsApp. This is a useful identification aid, but it is not proof that a particular message is genuine. Registration disclosure tells you who the account belongs to. It does not tell you who is currently sending from it.

The first hour after a hack

Roy emphasises preparation and speed above response and investigation. “Most compa nies have to plan that they will get hacked through this route,” he says. “If you haven’t planned a Standard Operating Procedure for responding to an attack, you lose time during the golden hour.” Money moved through mule accounts can reach a second or third account within two hours and begin exiting the country.

For advisers, the sequence is: isolate the affected device, log out all linked WhatsApp sessions, immediately alert clients not to open recent files, contact the bank if any money has moved, and report simultaneously to the National Cyber Crime Helpline at 1930 or through cybercrime.gov.in. Sebi’s Cybersecurity and Cyber Resilience Framework requires regulated entities to have incident-response plans and defined responsibilities: who switches off the compromised device, who calls clients, and who contacts the bank.

SIM swap attack: How hackers steal your OTPs and empty your bank account
1/7

SIM swap fraud is a type of cybercrime where a criminal tricks your telecom provider into transferring your mobile number to a new SIM card that they control. Once they gain access to your number, they can intercept all your OTPs and verification codes. This allows them to break into your bank accounts, email, and social media, often before you even realize something is wrong.

SIM swap fraud is a type of cybercrime where a criminal tricks your telecom provider into transferring your mobile number to a new SIM card that they control. Once they gain access to your number, th..
Read More

The attack starts long before the SIM swap takes place. Criminals collect your personal information through phishing emails, data leaks, or social engineering. They then walk into a telecom store, impersonate you, and request a duplicate SIM. Once issued, your real SIM stops working and theirs becomes active. From that moment, every OTP meant for you goes straight to them, giving them full access to your accounts.

The attack starts long before the SIM swap takes place. Criminals collect your personal information through phishing emails, data leaks, or social engineering. They then walk into a telecom store, im..
Read More

Good news for UPI users, there's an extra layer of protection. Even if a fraudster successfully swaps your SIM, they still can't access your UPI app on a new phone without your Aadhaar number or bank debit card details. This additional verification step acts as a strong safety net, making it significantly harder for criminals to misuse UPI even after a successful SIM swap.

Good news for UPI users, there's an extra layer of protection. Even if a fraudster successfully swaps your SIM, they still can't access your UPI app on a new phone without your Aadhaar number or bank..
Read More

Watch out for these red flags:
* Your phone suddenly loses network signal
* You stop receiving calls or SMS messages
* You get alerts about account changes you didn't make
* Your bank sends unauthorized transaction notifications

If your SIM stops working without reason, don't assume it's a network issue. Contact your telecom provider immediately, every minute of delay gives the fraudster more time to steal.

Watch out for these red flags:* Your phone suddenly loses network signal* You stop receiving calls or SMS messages* You get alerts about account changes you didn't make* Your bank sends unauthorized ..
Read More

Act fast, speed is everything in SIM swap fraud. First, call your telecom provider to suspend the compromised SIM and reclaim your number. Then reset passwords for your bank, email, and social media accounts, most sensitive ones first. Check all recent account activity for unauthorized transactions and alert your bank right away. Also enable app-based authentication instead of SMS-based OTPs going forward.

Act fast, speed is everything in SIM swap fraud. First, call your telecom provider to suspend the compromised SIM and reclaim your number. Then reset passwords for your bank, email, and social media ..
Read More

SIM binding links your account to a specific SIM card or device, making it harder for fraudsters to access your accounts even after a swap. When a login attempt occurs, the system checks if it's coming from your trusted device, and flags anything suspicious. However, SIM binding alone isn't foolproof. Criminals combine SIM swapping with phishing and malware to bypass it, so it should be used as one layer among many.

SIM binding links your account to a specific SIM card or device, making it harder for fraudsters to access your accounts even after a swap. When a login attempt occurs, the system checks if it's comi..
Read More

Stay protected with these steps:
* Never share personal details over calls or suspicious links
* Use authenticator apps (Google/Microsoft Authenticator) instead of SMS OTPs
* Set a SIM card lock on your phone (available on Samsung and most Android devices)
* Regularly monitor your bank and account activity
* Add a PIN or passcode with your telecom provider for any SIM-related requests
* Your mobile number is the key to your financial life, guard it like your ATM PIN.

Stay protected with these steps:* Never share personal details over calls or suspicious links* Use authenticator apps (Google/Microsoft Authenticator) instead of SMS OTPs* Set a SIM card lock on your..
Read More
For investors who have already transferred money or opened a suspicious file, Bilgrami says the first call goes to the bank: “If money has been transferred, the bank should be contacted immediately to secure the account and explore whether the transaction can be stopped or traced.”

Use WhatsApp for convenience

The lesson from these incidents is not that advisers should abandon WhatsApp. The lesson is that communication and authentication are different, and mixing them is where the risk lies. WhatsApp can be used to say: please check your email. It can be used to arrange a call, discuss a portfolio, send a reminder. But when money is about to move, the investor should step outside the WhatsApp conversation and into a separate, fully authenticated process.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › Wealth › Invest › Hackers can target your wealth adviser’s WhatsApp: How to protect your money
Text Size:AAA
Success
This article has been saved

*

+