How to train staff to spot WhatsApp impersonation scams

How to train staff to spot WhatsApp impersonation scams: the Hi Mum pattern, the stop-switch-confirm reflex, and the workplace payment-fraud variant.

Your staff have learned to distrust email. They hover before clicking, they check the sender domain, some of them report suspicious messages. Then their phone buzzes with a WhatsApp message from Mum asking for help, or from a colleague's personal number about an urgent payment - and every email habit evaporates, because nobody has ever told them that text messages lie too. Training staff to spot WhatsApp impersonation scams closes the trust gap that email training built and messaging apps quietly undo.

TL;DR

Why this matters

Email got so well defended that attackers moved. The mobile messaging channel is where defences are thinnest and trust is highest: no spam folder, no sender domain to inspect, and a contact list of people the user genuinely trusts. The ACCC-run Scamwatch documented the pattern at scale with the "Hi Mum" or family impersonation scam: victims are contacted - most often through WhatsApp - by a scammer posing as a family member or friend, usually with a story about a lost or broken phone and an urgent need for money. In the first seven months of 2022 alone, more than 1,150 Australians fell victim with total reported losses of $2.6 million, and the losses concentrated heavily among older victims - 82 per cent of family impersonation scams were reported by people over 55, accounting for 95 per cent of reported losses.

Two features make this channel unusually effective. First, the attacker borrows real identity: they may use the family member's real photo lifted from social media, which Scamwatch notes makes the scam harder to spot. Second, the personal channel carries no institutional suspicion - people apply security thinking to banks and government, not to their children. For a business, the same mechanics power workplace fraud: an urgent "CEO on my personal phone" message, a supplier whose number has changed, a colleague asking for a quick payment outside the normal system.

Who this is for

MSPs training client workforces, and internal IT or people teams at businesses whose staff handle payments, payroll, or sensitive requests. Also worth covering for every employee, because these scams target people at home - and a workforce trained to spot them protects the business by protecting its people.

What WhatsApp impersonation looks like

Staff should be able to name these patterns on sight:

What all of them share: urgency, money or credentials, and an identity claim that is easy to fake and was never verified.

The reflex: stop, switch channels, confirm

Email training taught the hover-and-check. Messaging needs its own version, and it has three beats:

  1. Stop at the money. No payment, no code, no gift card, no bank detail is actioned inside the chat that requested it. The moment money or codes enter a conversation, the conversation is over until identity is proven.
  2. Switch channels. Call the person on the number you already have saved. If it is a work request, use the work system or the work phone book. Attackers cannot intercept a call they do not know about - the different channel is the whole defence.
  3. Confirm a detail the chat never mentioned. A shared fact - a family name, a reference number, the last invoice paid - proves the real person, not a number claiming to be them.

Two supporting habits round it out:

How to train it

  1. Add a messaging module to the programme. Your security awareness training should include the WhatsApp shapes above and the stop-switch-confirm reflex, with real examples. Short, memorable, repeated.
  2. Cover it at home, not just at work. The highest-risk group for family impersonation scams is people over 55 - which includes many staff and most of their parents. Encourage staff to run the same three-beat check with family; it lands better than an abstract compliance rule.
  3. Test the reflex. If your platform supports SMS or messaging-based simulations, run one. If it is email-only, run a tabletop: circulate a screenshot of a fake "Hi Mum" or "CEO on personal number" message and ask teams what they would do - then debrief the reflex.
  4. Set the work-policy boundary. Spell out which requests may be actioned from personal messaging channels: usually none involving money or credentials. Make the rule positive - "we confirm on a second channel" - rather than "never reply", because staff will need to reply to genuine messages.
  5. Fold it into the reporting culture. The metric that matters is reports, not clicks. A staff member who forwards a suspicious WhatsApp to IT has done exactly what the phishing simulations programme exists to produce.

Common training mistakes

What to do next

If the client has no policy on personal-channel payment requests, start there - it is one paragraph and it closes the most expensive variant. Then put the training behind it and measure it with human risk reporting, so the messaging-channel risk sits next to email risk on the same dashboard. If the wider programme needs a business case, a gap assessment shows where the human layer is thinnest.

FAQ

What is the "Hi Mum" scam?

A family impersonation scam where the attacker messages - most often on WhatsApp - posing as a family member or friend, usually claiming a new or broken phone, then asks for urgent money. Scamwatch recorded more than 1,150 victims and $2.6 million in reported losses in the first seven months of 2022 alone.

The profile photo looked exactly like the real person - how is that possible?

Scammers lift real photos from public social media profiles. A photo proves what the account displays, not who controls it.

What should staff do if they get a suspicious message from a work contact's personal number?

Do not action anything. Confirm on the work system, the work phone book, or the number already saved. If it claims to be an executive, report it to IT - it may be the same thread sent to others.

Are WhatsApp verification codes ever legitimately shared?

No. Codes that arrive by SMS or app are for the recipient's own account and are never shared with anyone - including people claiming to be from the platform, a bank or IT.

Where do we report these scams in Australia?

Report to Scamwatch (the ACCC's reporting service); if a loss occurred and the perpetrator is believed to be in Australia, also report to ReportCyber. Internally, report to IT or the MSP as well.

Can we simulate WhatsApp scams in training?

If your platform supports messaging-based simulations, yes. If not, a screenshot-based tabletop drill with a debrief works well and costs nothing.

One last thing

Check the client's payment-change procedure. If bank details can be changed on the strength of one message - from any channel - no amount of training will hold. A second-channel confirmation requirement on every payment change is the control this whole article is defending.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.