The message looked routine. A financial firm’s WhatsApp account had sent what appeared to be an important document to team members, asking them to open it on their computers, not their phones. The sender’s name was familiar. Across India, financial advisers and wealth managers have been encountering a version of the same incident over the past several weeks. A WhatsApp account belonging to the firm, a senior executive, or a trusted colleague gets compromised through malware downloaded on a linked laptop. The account then sends malicious files to contacts, wrapped in the credibilit of a name the recipient already trusts. A compliance notice, a GST document or a statement of account. Something you would normally open without thinking twice. Ajay Sehgal, Director at Allegiance Financial, a wealth management firm that serves over 1,000 clients, was among those who encountered this. One of his team members, while downloading documents for research, inadvertently installed malware on a company laptop that was connected to a WhatsApp account as a secondary device. The attacker slipped in through that gap. “The person on the other side immediately gained access to the WhatsApp,” Sehgal says. The firm caught it before the file reached clients, isolating the
Read More











