
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

The message looked routine.
Summary
A financial firm’s WhatsApp account had sent what appeared to be an important document to team members, asking them to open it on their computers, not their phones. The sender’s name was familiar. Across India, financial advisers and wealth managers have been encountering a version of the same incident over the past several weeks.
A WhatsApp account belonging to the firm, a senior executive, or a trusted colleague gets compromised through malware downloaded on a linked laptop. The account then sends malicious files to contacts, wrapped in the credibilit of a name the recipient already trusts. A compliance notice, a GST document or a statement of account.
Something you would normally open without thinking twice. Ajay Sehgal, Director at Allegiance Financial, a wealth management firm that serves over 1,000 clients, was among those who encountered this. One of his team members, while downloading documents for research, inadvertently installed malware on a company laptop that was connected to a WhatsApp account as a secondary device.
The attacker slipped in through that gap. “The person on the other side immediately gained access to the WhatsApp,” Sehgal says.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 4 other articles touching the same topic (whatsapp) , see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.