Meta business verification for a brokerage: documents, display name and the blue tick
Registry papers, a display name clients recognise, two-step verification: what Meta checks before a brokerage number can scale, and what the badge is worth.
How a brokerage loses its WhatsApp number to a SIM swap, a phished code or a linked device — the settings that stop it, and what POPIA requires afterwards.
It rarely announces itself. The brokerage number simply goes quiet for an hour on a Friday afternoon, and by the time someone notices, three clients have been asked to send their renewal premium to a new account “because our banking details have changed”. The messages come from the number your clients have saved under the firm’s name, in a thread that already contains years of legitimate conversation. That history is exactly what makes the fraud work.
Account takeover is now a routine attack against South African businesses, and a brokerage is a rich target: the thread holds ID numbers, medical questionnaires, vehicle details, claim documents and a standing habit of discussing money. SABRIC publishes the industry picture in its annual crime statistics; what follows is the operational side for a firm whose client channel is a WhatsApp number.
| Route | How it works | What you notice first |
|---|---|---|
| SIM swap or port-out | The attacker persuades the mobile operator to move the number to a SIM they hold, then registers WhatsApp on their own device with the SMS code | The handset loses signal and service; WhatsApp signs out on the office phone |
| Phished registration code | Someone on the team is contacted, told there is a verification problem, and forwards the six-digit code that has just arrived | An abrupt sign-out with no loss of mobile signal |
| Silently linked device | A staff member scans a code or follows a link that adds the attacker as a companion device or web session; the account keeps working normally | Nothing — until a client mentions a message nobody sent |
The third is the one brokerages miss, because it does not interrupt service. The account carries on working while a stranger reads every new conversation and answers some of them.
On the WhatsApp Business app, the account lives on a handset and depends on a SIM: whoever controls the number and the incoming code controls the account. That is the model most small brokerages start on, and it is the model our comparison of a personal number versus a brokerage number warns about.
On the WhatsApp Business Platform the number is registered to a WhatsApp Business Account inside Meta’s business tooling, and re-registering it requires a six-digit PIN. Meta’s Cloud API reference is explicit: the two-step verification endpoint exists to “set up two-step verification for your phone number to require a 6-digit PIN when registering the phone number”, and there is no endpoint to disable it once set. A SIM swap on its own therefore does not hand an attacker the account.
What it does is move the risk. The account is now only as safe as the administrator identities that control the business portfolio — personal Facebook logins, in practice, belonging to a principal, an IT contractor and possibly a former marketing agency. Two-factor authentication on every one of those, a deliberately short admin list, and same-day removal when someone leaves are the controls that matter. Setting the number up properly in the first place is covered in our guide to WhatsApp Business setup for a South African brokerage.
Speed matters more than diagnosis. In order: contact the mobile operator to reclaim the number and note the reference; re-register the number on a device you control and set a new PIN; log out every linked device and web session; warn clients through another channel, in plain terms, that no change of banking details is genuine; tell the insurers and underwriting agencies whose payment references may have been faked; and preserve evidence — screenshots with timestamps, the operator reference, the list of devices you removed — before anyone starts tidying up.
Then reconstruct what the attacker could see. On the app, that is the message history on the device. On the Platform, conversations sit in the brokerage’s system rather than on a handset, which is also what makes the FAIS position defensible: your record-keeping obligations do not pause because a phone was compromised, and a firm whose only copy of five years of advice conversations was on that phone has a second problem on top of the first.
Section 22 of POPIA requires a responsible party to notify the Information Regulator, and the affected data subjects, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. There is no materiality threshold and no 72-hour deadline as under the GDPR: notification must be made as soon as reasonably possible after discovery, allowing only for the legitimate needs of law enforcement and the measures needed to determine the scope and restore the integrity of your systems. The Regulator prescribes Form SCN1 for the notification and publishes guidelines on completing it; using the wrong format can render the notification non-compliant.
For a brokerage the content of the compromised thread usually raises the stakes. Health questionnaires, medical scheme details and biometric or ID information fall within the special personal information regime, and a claims conversation routinely contains banking details. Notification to clients has to be specific enough for them to protect themselves — which, in this scenario, means telling them plainly that payment instructions received on that number during a stated window cannot be trusted. Our POPIA definition sets out the wider duties.
The prevention side is largely structural. A brokerage that runs client conversations through a business platform rather than a handset — the number owned by the firm, access by named user rather than by possession of a device, an audit log of who did what, opt-outs and consent held centrally — is not immune to a compromised administrator, but it removes the SIM from the attack path and leaves an evidence trail when something does go wrong. That is the model ORIS is built on, and the walkthrough shows what the access and audit side looks like.
Yes. Phishing a verification code is quicker than persuading an operator, and adding a linked device is quieter than either — the account keeps working while the attacker reads and sends messages. Treat an unexplained sign-out and an unrecognised linked device as the same category of incident.
It removes the SIM from the attack path, because re-registering the number requires the six-digit PIN rather than an SMS to a handset. It replaces that exposure with administrator identities in Meta’s business tooling, so two-factor authentication on every admin, a short admin list and prompt removal of leavers become the controls that matter.
Both, where personal information has been accessed or acquired by an unauthorised person. Section 22 requires notification to the Information Regulator and to the affected data subjects, unless their identity cannot be established. In a takeover you know exactly who was messaged, so the second limb is not optional.
By reconstructing from a system rather than a phone. If conversations, consents and documents live in the brokerage’s platform, you can state which threads were exposed and over what period. If they lived only on the handset, the honest answer to the Regulator is that you do not know — which is itself a finding.
No. It moves the same risk onto an individual, breaks the record trail and creates a second channel clients cannot verify. Keep one firm-owned number, a documented recovery path, and a non-WhatsApp way to reach clients when that number is unavailable.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
Registry papers, a display name clients recognise, two-step verification: what Meta checks before a brokerage number can scale, and what the badge is worth.
Meta bills WhatsApp per message delivered. Which of a broker’s messages are charged, which are free inside the service window, and how to budget a month.
Half the premium reminders did not send. What a WhatsApp messaging limit counts, how tiers and quality rating work, and how to run a month-end batch safely.