WhatsApp Business

SIM swap and account takeover: protecting the number your clients message

How a brokerage loses its WhatsApp number to a SIM swap, a phished code or a linked device — the settings that stop it, and what POPIA requires afterwards.

Published on 7 min readFCB.ai
Contents
  1. Three ways the number leaves your control
  2. What the Business Platform changes, and what it does not
  3. Controls worth writing into the operations file
  4. The first hour after a takeover
  5. It is a POPIA incident, not just an IT problem
  6. Frequently asked questions

It rarely announces itself. The brokerage number simply goes quiet for an hour on a Friday afternoon, and by the time someone notices, three clients have been asked to send their renewal premium to a new account “because our banking details have changed”. The messages come from the number your clients have saved under the firm’s name, in a thread that already contains years of legitimate conversation. That history is exactly what makes the fraud work.

Account takeover is now a routine attack against South African businesses, and a brokerage is a rich target: the thread holds ID numbers, medical questionnaires, vehicle details, claim documents and a standing habit of discussing money. SABRIC publishes the industry picture in its annual crime statistics; what follows is the operational side for a firm whose client channel is a WhatsApp number.

Three ways the number leaves your control

RouteHow it worksWhat you notice first
SIM swap or port-outThe attacker persuades the mobile operator to move the number to a SIM they hold, then registers WhatsApp on their own device with the SMS codeThe handset loses signal and service; WhatsApp signs out on the office phone
Phished registration codeSomeone on the team is contacted, told there is a verification problem, and forwards the six-digit code that has just arrivedAn abrupt sign-out with no loss of mobile signal
Silently linked deviceA staff member scans a code or follows a link that adds the attacker as a companion device or web session; the account keeps working normallyNothing — until a client mentions a message nobody sent

The third is the one brokerages miss, because it does not interrupt service. The account carries on working while a stranger reads every new conversation and answers some of them.

What the Business Platform changes, and what it does not

On the WhatsApp Business app, the account lives on a handset and depends on a SIM: whoever controls the number and the incoming code controls the account. That is the model most small brokerages start on, and it is the model our comparison of a personal number versus a brokerage number warns about.

On the WhatsApp Business Platform the number is registered to a WhatsApp Business Account inside Meta’s business tooling, and re-registering it requires a six-digit PIN. Meta’s Cloud API reference is explicit: the two-step verification endpoint exists to “set up two-step verification for your phone number to require a 6-digit PIN when registering the phone number”, and there is no endpoint to disable it once set. A SIM swap on its own therefore does not hand an attacker the account.

What it does is move the risk. The account is now only as safe as the administrator identities that control the business portfolio — personal Facebook logins, in practice, belonging to a principal, an IT contractor and possibly a former marketing agency. Two-factor authentication on every one of those, a deliberately short admin list, and same-day removal when someone leaves are the controls that matter. Setting the number up properly in the first place is covered in our guide to WhatsApp Business setup for a South African brokerage.

Controls worth writing into the operations file

  1. Two-step verification on, everywhere. On the app, that is the PIN WhatsApp asks for when the number is registered on a new device. On the Platform, it is the registration PIN. Store it in the firm’s password manager, known to at least two people, never in a note on the phone that holds the number.
  2. Ask the operator for SIM-swap and port-out protection. Every South African network offers notification or additional verification on the business account; the ten minutes it takes to arrange is the cheapest control on this list.
  3. Review linked devices weekly, and on every departure. The app allows up to four companion devices; anything you do not recognise is logged out immediately, and the review is a named person’s task, not an intention.
  4. Write the code rule down. Nobody at the firm ever forwards, reads out or types a WhatsApp verification code into anything. Attackers rely on a helpful junior; a one-line policy that everyone has seen removes the ambiguity.
  5. Keep a second route to your clients. If the only way you can reach your book is the number under attack, the fraud runs unchallenged. An up-to-date email or telephone field on every client record is a security control, not admin.
  6. Separate the number from a person. A number registered to the firm, on a device the firm owns, with the recovery email on a firm domain, survives a resignation, a lost phone and a takeover. A number on an adviser’s personal handset survives none of them.

The first hour after a takeover

Speed matters more than diagnosis. In order: contact the mobile operator to reclaim the number and note the reference; re-register the number on a device you control and set a new PIN; log out every linked device and web session; warn clients through another channel, in plain terms, that no change of banking details is genuine; tell the insurers and underwriting agencies whose payment references may have been faked; and preserve evidence — screenshots with timestamps, the operator reference, the list of devices you removed — before anyone starts tidying up.

Then reconstruct what the attacker could see. On the app, that is the message history on the device. On the Platform, conversations sit in the brokerage’s system rather than on a handset, which is also what makes the FAIS position defensible: your record-keeping obligations do not pause because a phone was compromised, and a firm whose only copy of five years of advice conversations was on that phone has a second problem on top of the first.

It is a POPIA incident, not just an IT problem

Section 22 of POPIA requires a responsible party to notify the Information Regulator, and the affected data subjects, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. There is no materiality threshold and no 72-hour deadline as under the GDPR: notification must be made as soon as reasonably possible after discovery, allowing only for the legitimate needs of law enforcement and the measures needed to determine the scope and restore the integrity of your systems. The Regulator prescribes Form SCN1 for the notification and publishes guidelines on completing it; using the wrong format can render the notification non-compliant.

For a brokerage the content of the compromised thread usually raises the stakes. Health questionnaires, medical scheme details and biometric or ID information fall within the special personal information regime, and a claims conversation routinely contains banking details. Notification to clients has to be specific enough for them to protect themselves — which, in this scenario, means telling them plainly that payment instructions received on that number during a stated window cannot be trusted. Our POPIA definition sets out the wider duties.

The prevention side is largely structural. A brokerage that runs client conversations through a business platform rather than a handset — the number owned by the firm, access by named user rather than by possession of a device, an audit log of who did what, opt-outs and consent held centrally — is not immune to a compromised administrator, but it removes the SIM from the attack path and leaves an evidence trail when something does go wrong. That is the model ORIS is built on, and the walkthrough shows what the access and audit side looks like.

Frequently asked questions

Can an attacker take over our number without a SIM swap?

Yes. Phishing a verification code is quicker than persuading an operator, and adding a linked device is quieter than either — the account keeps working while the attacker reads and sends messages. Treat an unexplained sign-out and an unrecognised linked device as the same category of incident.

Does moving to the WhatsApp Business Platform make us safe?

It removes the SIM from the attack path, because re-registering the number requires the six-digit PIN rather than an SMS to a handset. It replaces that exposure with administrator identities in Meta’s business tooling, so two-factor authentication on every admin, a short admin list and prompt removal of leavers become the controls that matter.

Do we have to tell clients, or only the Regulator?

Both, where personal information has been accessed or acquired by an unauthorised person. Section 22 requires notification to the Information Regulator and to the affected data subjects, unless their identity cannot be established. In a takeover you know exactly who was messaged, so the second limb is not optional.

How do we prove what the attacker could see?

By reconstructing from a system rather than a phone. If conversations, consents and documents live in the brokerage’s platform, you can state which threads were exposed and over what period. If they lived only on the handset, the honest answer to the Regulator is that you do not know — which is itself a finding.

Should the principal’s personal number be used as a backup?

No. It moves the same risk onto an individual, breaks the record trail and creates a second channel clients cannot verify. Keep one firm-owned number, a documented recovery path, and a non-WhatsApp way to reach clients when that number is unavailable.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo