Hackers can target your wealth adviser’s WhatsApp: How to protect your money
Recent incidents highlight the increasing threat of compromised WhatsApp accounts among financial advisers in India. These attacks exploit trust, as fraudsters impersonate advisers through hacked accounts. Financial firms have implemented strict n...

Across India, financial advisers and wealth managers have been encountering a version of the same incident over the past several weeks. A WhatsApp account belonging to the firm, a senior executive, or a trusted colleague gets compromised through malware downloaded on a linked laptop. The account then sends malicious files to contacts, wrapped in the credibilit of a name the recipient already trusts. A compliance notice, a GST document or a statement of account. Something you would normally open without thinking twice.
Ajay Sehgal, Director at Allegiance Financial, a wealth management firm that serves over 1,000 clients, was among those who encountered this. One of his team members, while downloading documents for research, inadvertently installed malware on a company laptop that was connected to a WhatsApp account as a secondary device. The attacker slipped in through that gap. “The person on the other side immediately gained access to the WhatsApp,” Sehgal says. The firm caught it before the file reached clients, isolating the laptop, logging out of all linked devices, blocking the SIM and re-registering WhatsApp. They also reported the incident on the government’s cybercrime portal.
“The important thing is that one has to report the matter to the Government of India cybercrime portal,” Sehgal says. His firm was not alone.
When WhatsApp becomes a cyber risk

Director, Allegiance Financial
Clients: 1,000+
What happened?
Malware on a linked laptop compromised the firm’s WhatsApp account.
New safeguards
Restricted WhatsApp access; reinforced IT policy; enabled two-factor authentication.

CEO, Wealixir
Clients: 3,000+
What happened?
Tax team opened a malicious ZIP sent by a client; infection spread through WhatsApp.
New safeguards
Reduced document sharing on WhatsApp; explored secure file-upload systems.

QPFP®️, Founder, GoodMoneyMan Associates
Clients: 1,267
What happened?
Office WhatsApp number was taken over; clients received a malicious ZIP file.
New safeguards
Two-step verification; linked-device checks every three days; WhatsApp only on company computer.

QPFP®️, Director, Crescent Mutual Fund Distributors
Clients: 6,147
What happened?
Accidentally downloaded a suspicious file received through a compromised WhatsApp account.
New safeguards
No WhatsApp-only transactions; phone call confirmation + email approval + NSE platform.
A hacked relationship
Prasanto Roy, a public policy adviser who works in cybersecurity and payments, argues that framing this as a WhatsApp vulnerability misses the point. “I would not put it down to a WhatsApp-specific issue,” he says. “Since WhatsApp is the leading driver of smartphone adoption, and is on 700-800 million phones as the default communication platform, there’s no question that it will become the platform for both commerce as well as for scammers.”What makes a financial adviser’s compromised account particularly dangerous is the pre-existing architecture of trust. The fraudster does not have to build a fake identity from scratch. They inherit the adviser’s name, photograph, existing conversation threads, client list and, critically, the context of ongoing financial relationships.
“The commonest way of taking over this WhatsApp communication is a session hijack,” Roy says, “which goes through a WhatsApp Web session takeover. This is not as if it’s coming in through WhatsApp on your phone; it is installing malware on your PC to hijack WhatsApp web, and do a session takeover using tokens and cookies.”
ALSO READ | Why are Registered Investment Advisers so rare in India? The big reason may surprise investors
Najm Bilgrami, National Head of Liability Lines at Tata AIG General Insurance, puts it simply: “The biggest advantage for a fraudster is trust. A compromised WhatsApp account allows them to approach the victim through a channel they already trust and communicate in a familiar manner.” The fraudster doesn’t necessarily have to break into your bank account. He may first break into the person you trust with your money.
How the attack moves
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, had issued a formal advisory on this threat on 7 August 2026. The agency had warned that self-propagating malware, disguised as account statements and RBI communications, was spreading over WhatsApp, SMS and e-mail. Further, chartered accountants, company directors, chief financial officers and corporate finance teams were the prime targets. The agency observed a sharp rise in complaints relating to WhatsApp account takeovers through malicious files circulated as account statements and regulatory communications. Incidents following an identical pattern have been reported from multiple states, including Delhi, Gujarat, Maharashtra and Rajasthan. I4C had intimated over 58,000 potential victims in the previous 30 days alone.The mechanism is a multi-step chain. A compressed file arrives over WhatsApp bearing names like “Statement of Account. zip”, “RBI.zip” or “MCA.zip”, accompanied by a message designed to appear as either a routine financial document or an urgent regulatory notice. The archive contains a Windows executable file. Opening it on a desktop or laptop installs a Trojan that hijacks the active WhatsApp Web session. Once inside, the compromised account automatically circulates the same file to all contacts and groups, typically with a request to forward it to the recipient’s “finance manager for verification” and to open it on a computer. In the more advanced form of this attack, known as the “Boss Scam” or CEO impersonation fraud, the fraudster uses the captured executive account to instruct finance personnel to transfer funds to mule accounts.
When it comes to cyber scams in the financial adviser and wealth management ecosystem, the first target may not always be the client. It may be the adviser’s employee, laptop or WhatsApp Web session. The client becomes the next target.
Even experienced clients click
Valance Fernandes, CEO of Wealixir, which manages roughly 3,000 client families, encountered exactly this sequence. A client sent a file to his tax team. The team assumed it was a GST-related document from an existing client, a reasonable assumption, since clients regularly send them tax documents over WhatsApp. They opened it. The infection then forwarded itself from the tax team’s account to Fernandes. He opened it, believing it had come from his own staff. “Even our clients, who are highly sophisticated professionals, including company CFOs and national heads, opened the message because they were expecting documents from us,” Fernandes says.ALSO READ | AI can pick the fund, but can it stop you from selling at the bottom?
The red flag here was not visible in the message. In the middle of a busy workday, while managing client files and expecting documents, a compressed file from a known contact can easily look like just another task. Fernandes’ firm immediately killed all WhatsApp sessions and formatted every infected device, without waiting to assess the extent of the damage. “We didn’t wait to see the damage. We formatted all our systems,” he says. “We also realised that we have no filter when it comes to WhatsApp; people are okay sending us bank statements, income tax statements, anything and everything.”
Drawing a line
Pawan Agarwal, QPFP®️, Founder - GoodMoneyMan Associates, which works with about 1,267 clients, had long followed a policy borrowed from his father’s pre-WhatsApp instincts: important client details, documents, and bank account information should only travel over email. WhatsApp was a communication channel, not a verification or transaction channel. Even so, the firm’s office number was taken over. Clients received a ZIP file asking them to share it with their finance manager. “All of a sudden I saw a few clients just calling back-to-back,” Agarwal says.The difference was that the communication compromise did not automatically become a transaction compromise. The firm’s response was layered: they immediately contacted clients from a different number, posted warnings on WhatsApp status, implemented two-step verification for all business numbers, began checking linked devices every three days and restricted WhatsApp Business access to a single registered company computer on the company network. A draft email, ready to send to the entire client list, now sits in the firm’s email account. “Calling 1,200-1,500 people will take time, not easy. But email is the fastest thing that can be sent across,” Agarwal says.
A complete transaction
Bhushan Wani, QPFP®️, Director, Crescent Mutual Fund Distributors, which serves 6,147 clients, follows a three-step rule. If a client sends a WhatsApp message asking to redeem, the sales team calls the client on their personal number to confirm. The team then processes the transaction through the NSE Mutual Fund platform, and the client receives an email for approval. “We will not do any transaction only with the WhatsApp communication,” Wani says. Two of Wani’s clients have experienced WhatsApp-based fraud unrelated to investments. One, a well-educated engineer, was socially engineered through a combination of a birthday call, a fake parcel story and escalating pressure, ultimately transferring around Rs.20 lakh.Separately, another client’s administrative employee received a WhatsApp call from what appeared to be the business owner’s account, complete with the owner’s display picture, and transferred Rs.35 lakh.
What if you get hit by a WhatsApp scam?

Never open unexpected ZIP, APK or exectable fules, particularly when the label references a statement, a regulatory body, income tax, KYC or GST.

What should you do differently?
The advisers’ experiences point to a consistent set of investor-side responsibilities.A message from your adviser’s existing WhatsApp number is not sufficient verification for anything that involves money, a new product, changed bank details or an unusual instruction. Bilgrami recommends “stepping outside the WhatsApp conversation and independently verifying the request”, meaning a call to the known number, not a reply in the same thread.
Never open unexpected ZIP, APK or executable files, particularly when the label references a statement, a regulatory body, income tax, KYC or GST. I4C specifically advises against downloading, extracting or opening such files from unknown or unverified sources. Regulators such as the Reserve Bank of India do not distribute account statements or compliance notices as WhatsApp attachments.
Do not share One-Time Passwords (OTP), passwords or authentication credentials over WhatsApp, even if the request appears to come from a trusted adviser. For investment transactions, authenticate through the official platform.
The Securities and Exchange Board of India’s (Sebi) February 2026 circular requires regulated entities and their agents to disclose their registered name and registration number on social-media handles, including WhatsApp. This is a useful identification aid, but it is not proof that a particular message is genuine. Registration disclosure tells you who the account belongs to. It does not tell you who is currently sending from it.
The first hour after a hack
Roy emphasises preparation and speed above response and investigation. “Most compa nies have to plan that they will get hacked through this route,” he says. “If you haven’t planned a Standard Operating Procedure for responding to an attack, you lose time during the golden hour.” Money moved through mule accounts can reach a second or third account within two hours and begin exiting the country.For advisers, the sequence is: isolate the affected device, log out all linked WhatsApp sessions, immediately alert clients not to open recent files, contact the bank if any money has moved, and report simultaneously to the National Cyber Crime Helpline at 1930 or through cybercrime.gov.in. Sebi’s Cybersecurity and Cyber Resilience Framework requires regulated entities to have incident-response plans and defined responsibilities: who switches off the compromised device, who calls clients, and who contacts the bank.
For investors who have already transferred money or opened a suspicious file, Bilgrami says the first call goes to the bank: “If money has been transferred, the bank should be contacted immediately to secure the account and explore whether the transaction can be stopped or traced.”
Use WhatsApp for convenience
The lesson from these incidents is not that advisers should abandon WhatsApp. The lesson is that communication and authentication are different, and mixing them is where the risk lies. WhatsApp can be used to say: please check your email. It can be used to arrange a call, discuss a portfolio, send a reminder. But when money is about to move, the investor should step outside the WhatsApp conversation and into a separate, fully authenticated process.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.
The Economic Times News App for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.