Why phishing is moving to WhatsApp — and why email-only simulation misses it
This is an analysis of a shift documented across public threat reporting — INTERPOL's African Cyberthreat Assessment (2024), GSMA mobile-industry research, and consumer-protection advisories from African regulators and banks — rather than an account of any single incident.
The pattern
Security programmes were built around email because that is where business communication lived. In much of Africa, it no longer exclusively does. Messaging apps — WhatsApp above all — carry a large share of real business conversation: supplier coordination, internal team groups, customer service, even payment confirmations. Attackers follow attention, and the threat reporting reflects it: INTERPOL's 2024 assessment highlights the prominence of online scams propagated through messaging and social platforms, and banks and regulators across the continent issue a steady stream of warnings about WhatsApp-based impersonation of executives, HR departments and customer support.
The structural reasons favour the attacker. A WhatsApp message arrives with a profile photo and a first name, on a personal device, outside every email security gateway the organisation has bought. There is no spam folder, no banner saying "external sender", no security team copy. And the medium's culture is speed: messages are expected to be answered in minutes, which is precisely the pressure social engineering needs.
How it plays out
The documented lures map closely onto email phishing, translated into chat:
Executive impersonation. A message from an unknown number with the CEO's photo: "I'm in a meeting, I need you to handle something discreetly." The ask escalates from a reply to gift cards, payment approvals or credential disclosure.
Fake HR and IT. Payroll updates, benefit forms, "security verifications" that walk an employee through approving an MFA prompt or sharing a code — including the WhatsApp verification code itself, which lets the attacker hijack the account and pivot into every group the victim belongs to.
Job and procurement scams. Fraudulent offers and tender invitations that harvest personal data or advance fees, frequently impersonating well-known African employers.
Account hijack chains. Each compromised account seeds the next: messages now arrive from a genuinely known contact, which defeats the "do I know this sender?" heuristic entirely.
Who it targets
Everyone with a phone — which, unlike email, genuinely means everyone in the organisation, including field staff, drivers, agents and frontline workers who may not even have a corporate mailbox. Finance staff and executive assistants remain the highest-value targets, but the entry point is often the least protected colleague.
Breaking the pattern
- Extend awareness training beyond the inbox. Staff should recognise executive-impersonation and verification-code scams as sharply as they recognise a phishing email.
- Set a channel policy: payment instructions and credential requests are never valid over WhatsApp, full stop — and make the policy known so refusal is safe.
- Teach code hygiene: the WhatsApp verification code is never shared with anyone, including "support".
- Give people a reporting path for suspicious messages on personal devices, and treat reports as wins.
- Test the channel you actually use. If your simulations are email-only, your metrics measure a shrinking share of your real exposure.
Sources
- INTERPOL, African Cyberthreat Assessment Report (2024)
- GSMA, mobile industry and mobile money research (2024)
- Public fraud advisories from African banks, telecom operators and consumer-protection regulators
Because this gap is real, AfriPhish includes WhatsApp-based simulation alongside email, so your programme measures the channel your people actually use — and our free Human Risk Maturity Assessment will show you where to start.