Your staff have learned to distrust email. They hover before clicking, they check the sender domain, some of them report suspicious messages. Then their phone buzzes with a WhatsApp message from Mum asking for help, or from a colleague's personal number about an urgent payment - and every email habit evaporates, because nobody has ever told them that text messages lie too. Training staff to spot WhatsApp impersonation scams closes the trust gap that email training built and messaging apps quietly undo.
TL;DR
- Family impersonation scams overwhelmingly arrive on WhatsApp - Australia's Scamwatch recorded more than 1,150 victims and $2.6 million in reported losses to the so-called "Hi Mum" scam in just the first seven months of 2022.
- The scam works because it arrives on a personal channel nobody associates with fraud, using a real name and sometimes a real photo.
- Train one reflex: a request for money or codes never gets actioned until identity is confirmed on a different channel.
- The same pattern hits businesses - urgent requests that move from email to WhatsApp are a classic payment-fraud escalation.
- Simulations and training should cover the messaging channel, not just the inbox.
Why this matters
Email got so well defended that attackers moved. The mobile messaging channel is where defences are thinnest and trust is highest: no spam folder, no sender domain to inspect, and a contact list of people the user genuinely trusts. The ACCC-run Scamwatch documented the pattern at scale with the "Hi Mum" or family impersonation scam: victims are contacted - most often through WhatsApp - by a scammer posing as a family member or friend, usually with a story about a lost or broken phone and an urgent need for money. In the first seven months of 2022 alone, more than 1,150 Australians fell victim with total reported losses of $2.6 million, and the losses concentrated heavily among older victims - 82 per cent of family impersonation scams were reported by people over 55, accounting for 95 per cent of reported losses.
Two features make this channel unusually effective. First, the attacker borrows real identity: they may use the family member's real photo lifted from social media, which Scamwatch notes makes the scam harder to spot. Second, the personal channel carries no institutional suspicion - people apply security thinking to banks and government, not to their children. For a business, the same mechanics power workplace fraud: an urgent "CEO on my personal phone" message, a supplier whose number has changed, a colleague asking for a quick payment outside the normal system.
Who this is for
MSPs training client workforces, and internal IT or people teams at businesses whose staff handle payments, payroll, or sensitive requests. Also worth covering for every employee, because these scams target people at home - and a workforce trained to spot them protects the business by protecting its people.
What WhatsApp impersonation looks like
Staff should be able to name these patterns on sight:
- The "Hi Mum" opener. An unknown number opens with a warm, vague greeting - "Hi Mum, it's me, I've got a new phone" - and escalates to money: an urgent bill, a fine, a transfer. The unknown number is the tell; the story is the payload.
- The real photo, wrong number. The profile picture is the real family member's, borrowed from a public social media account. Photos prove nothing about who controls the number.
- The executive on a personal number. A message that claims to be a director or CEO, from a number nobody has saved, with urgency and secrecy: an urgent transfer, a gift-card purchase, "don't mention this to anyone yet".
- The supplier number change. A contact who appears to be a known supplier says their number has changed and invoices or bank details will follow on the new thread. Payment-fraud classic.
- The verification-code request. A message asking the recipient to read out a code sent to their phone - the attacker is trying to register the victim's number on a new device or take over an account.
- The platform switch. Any request to continue a conversation off the official channel - moving from email to WhatsApp is a standard escalation in business email compromise, because the move dodges the mail filters and the paper trail.
What all of them share: urgency, money or credentials, and an identity claim that is easy to fake and was never verified.
The reflex: stop, switch channels, confirm
Email training taught the hover-and-check. Messaging needs its own version, and it has three beats:
- Stop at the money. No payment, no code, no gift card, no bank detail is actioned inside the chat that requested it. The moment money or codes enter a conversation, the conversation is over until identity is proven.
- Switch channels. Call the person on the number you already have saved. If it is a work request, use the work system or the work phone book. Attackers cannot intercept a call they do not know about - the different channel is the whole defence.
- Confirm a detail the chat never mentioned. A shared fact - a family name, a reference number, the last invoice paid - proves the real person, not a number claiming to be them.
Two supporting habits round it out:
- Treat the profile as unverified. Photos, display names and even a long chat history prove nothing; a hijacked real account looks exactly like the real person.
- Report, both ways. At work, report suspicious messages to IT or the MSP - especially if the scam impersonated a colleague or executive, because the next person may get the same thread. At home, Scamwatch is the national reporting point, and reports feed the ACCC's disruption work.
How to train it
- Add a messaging module to the programme. Your security awareness training should include the WhatsApp shapes above and the stop-switch-confirm reflex, with real examples. Short, memorable, repeated.
- Cover it at home, not just at work. The highest-risk group for family impersonation scams is people over 55 - which includes many staff and most of their parents. Encourage staff to run the same three-beat check with family; it lands better than an abstract compliance rule.
- Test the reflex. If your platform supports SMS or messaging-based simulations, run one. If it is email-only, run a tabletop: circulate a screenshot of a fake "Hi Mum" or "CEO on personal number" message and ask teams what they would do - then debrief the reflex.
- Set the work-policy boundary. Spell out which requests may be actioned from personal messaging channels: usually none involving money or credentials. Make the rule positive - "we confirm on a second channel" - rather than "never reply", because staff will need to reply to genuine messages.
- Fold it into the reporting culture. The metric that matters is reports, not clicks. A staff member who forwards a suspicious WhatsApp to IT has done exactly what the phishing simulations programme exists to produce.
Common training mistakes
- Treating this as a consumer problem. The business payment-fraud variant uses the identical pattern; finance teams and accounts payable need it most.
- Teaching "never trust WhatsApp". Staff use it daily for real life. The teachable rule is about requests, not platforms: money and codes get confirmed elsewhere, always.
- One-and-done. Like all social engineering training, this decays. Keep it in the rotation of the annual programme and the simulation calendar.
- Skipping the home angle. The emotional hook - protecting Mum - is what makes the lesson stick. Use it.
What to do next
If the client has no policy on personal-channel payment requests, start there - it is one paragraph and it closes the most expensive variant. Then put the training behind it and measure it with human risk reporting, so the messaging-channel risk sits next to email risk on the same dashboard. If the wider programme needs a business case, a gap assessment shows where the human layer is thinnest.
FAQ
What is the "Hi Mum" scam?
A family impersonation scam where the attacker messages - most often on WhatsApp - posing as a family member or friend, usually claiming a new or broken phone, then asks for urgent money. Scamwatch recorded more than 1,150 victims and $2.6 million in reported losses in the first seven months of 2022 alone.
The profile photo looked exactly like the real person - how is that possible?
Scammers lift real photos from public social media profiles. A photo proves what the account displays, not who controls it.
What should staff do if they get a suspicious message from a work contact's personal number?
Do not action anything. Confirm on the work system, the work phone book, or the number already saved. If it claims to be an executive, report it to IT - it may be the same thread sent to others.
Are WhatsApp verification codes ever legitimately shared?
No. Codes that arrive by SMS or app are for the recipient's own account and are never shared with anyone - including people claiming to be from the platform, a bank or IT.
Where do we report these scams in Australia?
Report to Scamwatch (the ACCC's reporting service); if a loss occurred and the perpetrator is believed to be in Australia, also report to ReportCyber. Internally, report to IT or the MSP as well.
Can we simulate WhatsApp scams in training?
If your platform supports messaging-based simulations, yes. If not, a screenshot-based tabletop drill with a debrief works well and costs nothing.
One last thing
Check the client's payment-change procedure. If bank details can be changed on the strength of one message - from any channel - no amount of training will hold. A second-channel confirmation requirement on every payment change is the control this whole article is defending.