Smishing and Fake WhatsApp Requests: How Small Businesses Can Stop Impersonation Scams
What would you do if your boss texted you and said they needed something right away?
Maybe they are in a meeting.
Maybe they are traveling.
Maybe they tell you they cannot talk and need you to handle something quickly.
The message might even include their name, job title, or other information that makes it seem real.
But there is one problem.
It may not be your boss at all.
Scammers are increasingly using text messages and messaging apps such as WhatsApp to impersonate executives, managers, coworkers, vendors, and other trusted people.
For a small business, one convincing message can lead to stolen money, exposed information, or compromised accounts.
The good news?
You do not need complicated cybersecurity tools to stop many of these attacks.
You need a simple verification process that your employees know how to use.
Over the past two years, I have seen more smishing attempts targeting employees, including messages pretending to come from company leaders. I have also seen suspicious requests sent through messaging apps such as WhatsApp, including requests involving documents and signatures.
These attacks are not theoretical. They are reaching real employees in real workplaces.
What Is Smishing?
You have probably heard of phishing, where criminals send fake emails designed to trick you.
Smishing is phishing through text messages.
The name combines SMS and phishing.
Instead of sending an email, the attacker sends a text message designed to make you click a link, provide information, send money, or take another action.
But these scams are not limited to standard text messages.
Attackers can also use:
WhatsApp
Microsoft Teams
Slack
Facebook Messenger
Instagram messages
Other messaging platforms
The technology may change, but the trick is usually the same:
Pretend to be someone you trust and create enough urgency that you act before you verify.
Finding someone's contact information may be easier than you think. Employees sometimes make phone numbers or email addresses public on LinkedIn, social media, business websites, or other online accounts.
Contact information can also be exposed in a data breach and later circulated or sold online. A scammer who obtains a person's name, employer, email address, or phone number may have enough information to make an impersonation attempt much more believable.
The scammer does not need to know everything about you. They just need enough information to earn your trust.
The “Hi, This Is Your Boss” Scam
A common business impersonation scam starts with a simple message.
The employee receives a text from an unfamiliar number.
The message might say something like:
“Hi, this is Sarah. This is my new number. Are you available?”
Sarah happens to be the company president.
The employee responds.
Now the attacker knows they have the right person.
The conversation may continue slowly at first. The scammer might ask whether the employee is working, whether they are busy, or whether they can help with something.
Then comes the real request.
The attacker might ask the employee to:
Buy gift cards
Send gift card numbers or photos
Make a payment
Send sensitive documents
Provide employee information
Change banking information
Share login information
Click a link
Move the conversation to WhatsApp
Contact someone else on the executive's behalf
Why does this work?
Because the request appears to come from someone with authority.
Employees may worry that questioning the request will make them look difficult or unhelpful.
I have seen employees follow unusual requests because they genuinely believed they were helping a C-level executive. When someone believes the CEO, CFO, or another senior leader needs their help, their first instinct may be to respond quickly instead of stopping to question the request.
That desire to be helpful is exactly what the attacker is trying to exploit.
That is exactly what the attacker is counting on.
Why These Messages Can Look So Convincing
Scammers do not always have to hack your company to learn about it.
Think about how much information is publicly available.
Your website might list:
Company leadership
Employee names
Job titles
Departments
Office locations
Email addresses
Recent company news
LinkedIn and other social media platforms may reveal even more.
An attacker might discover that Maria works in accounting and that John is the company president.
They do not need access to John's phone.
They simply need Maria to believe they are John.
That is an important distinction.
Impersonation does not always require an account to be hacked. Sometimes the attacker only needs a believable story.
WhatsApp Can Make the Scam Feel More Personal
WhatsApp and other messaging apps can make impersonation attempts feel more convincing because people often associate messaging apps with direct, personal communication.
A scammer may use:
A person's name
A copied profile photo
A company logo
A familiar-looking message
Information found online
But a name and profile picture are not proof of identity.
If someone contacts you from a new number claiming to be a coworker, executive, vendor, or business partner, treat the request as unverified until you confirm it another way.
Remember, a scammer may be able to find someone's phone number through public information or exposed data. Knowing the phone number associated with someone does not mean the scammer controls that person's real WhatsApp account. They may simply use the information they found to create a convincing impersonation attempt.
Watch for These Warning Signs
One unusual message does not automatically mean someone is trying to scam you.
But several warning signs together should make you stop.
1. A New or Unfamiliar Number
Someone claims to be a coworker or executive but contacts you from a number you do not recognize.
2. Unexpected Urgency
The person says something must happen immediately.
You may see phrases such as:
“I need this right away.”
“I'm going into a meeting.”
“Don't call me.”
“Can you handle this quickly?”
“This is confidential.”
Urgency gives you less time to think.
3. An Unusual Request
Your CEO suddenly wants you to buy gift cards.
A vendor asks you to change their bank account through a text message.
A manager asks for employee tax information over WhatsApp.
Ask yourself:
Is this how we normally handle this type of request?
If the answer is no, verify it.
4. Pressure to Keep the Request Secret
Be cautious when someone tells you not to involve another employee.
Attackers often want to isolate the person they are targeting.
5. A Request to Bypass Normal Procedures
This is one of the biggest warning signs.
If your company normally requires approval before sending money or changing payment information, an urgent text message should not override that process.
The Most Important Rule: Verify Using Another Method
Imagine someone knocks on your front door and says they are from your bank.
Would you hand them your bank password simply because they knew your name?
Probably not.
You would verify who they are.
Businesses should do the same thing with digital messages.
If you receive an unusual request from your boss, coworker, vendor, or customer:
Do not verify the request by replying to the same message.
Instead:
Call the person using a phone number you already know.
Send them a message through your normal company communication system.
Contact them using information already stored in your company directory.
Ask them directly when possible.
For example:
You receive a WhatsApp message that appears to be from your CEO asking you to purchase gift cards.
Instead of replying:
Call your CEO using the number already saved in your contacts.
That simple step can stop the scam.
Create a “Second Check” Rule for Money
Small businesses should have a simple rule:
Important financial changes require verification through a second channel.
This can apply to:
Wire transfers
ACH payments
Vendor banking changes
Payroll changes
Large purchases
Gift card purchases
Refund requests
Requests for sensitive financial information
For example, if a vendor emails or texts new banking instructions, someone should call the vendor using the phone number already on file.
Do not use the phone number included in the message requesting the change.
Think of this as putting a second lock on the door.
The first message starts the request.
The second check confirms it is real.
Give Employees Permission to Question Unusual Requests
Technology alone cannot solve this problem.
Your employees also need to know that it is okay to stop and verify.
Leadership should make this clear:
No employee should get in trouble for verifying an unusual request.
Even if the message really came from the CEO.
Even if the request really is urgent.
Taking two minutes to confirm a request is much easier than spending days trying to recover stolen money or exposed information.
A healthy security culture does not punish employees for asking:
“Can I verify this first?”
It encourages them to ask.
What Small Businesses Can Do This Week
You do not need a major cybersecurity project.
Start with these five steps:
Tell employees about executive impersonation scams. Show them what a fake text or WhatsApp request might look like.
Require a second verification method for financial requests. Especially payment changes, wire transfers, gift cards, and banking updates.
Define which communication tools your company uses. Employees should know whether executives normally communicate through text, WhatsApp, Teams, Slack, email, or another platform.
Protect employee and executive accounts with MFA or passkeys when available. This helps reduce the risk of an attacker taking over a real account.
Create a simple reporting process. Employees should know exactly who to contact when something feels suspicious.
The goal is not to make employees afraid of every message.
The goal is to create one simple habit:
STOP. VERIFY. THEN ACT.
What If Someone Already Responded?
Do not panic, but do act quickly.
Simply replying to a suspicious message does not necessarily mean your company has been compromised.
The next steps depend on what happened.
If they only replied
Stop communicating with the sender.
Block and report the account or phone number through the messaging platform.
Notify the appropriate person inside your company.
If they clicked a link
Do not continue entering information.
Report the incident internally and determine whether passwords, session information, or other information may have been exposed.
If they entered a password
Change the password immediately from the legitimate website or application.
If that password was reused anywhere else, change it there too.
Review the account for unusual activity and make sure MFA is enabled.
If money was sent
Contact the bank or payment provider immediately.
The faster the company responds, the better the chance of stopping or recovering a fraudulent transaction.
Then preserve the messages and other information related to the incident.
Fast reporting matters more than embarrassment.
Employees should never hide a mistake because they are afraid of getting in trouble.
The Bigger Lesson
Cybersecurity attacks do not always start with sophisticated hacking.
Sometimes they start with:
“Hi, this is your boss.”
That is why small-business cybersecurity cannot focus only on firewalls, antivirus software, and passwords.
People and business processes matter too.
A scammer may be able to copy someone's name.
They may be able to copy their photo.
They may even know where that person works.
But they should not be able to bypass your company's verification process with a single text message.
Make verification normal, and impersonation scams become much harder to pull off.
Quick Win
Take five minutes today and answer this question:
If an employee received a text from the owner asking them to send $2,000, would they know exactly how to verify it?
If the answer is no, create the rule now.
For example:
Any unexpected request involving money, account access, sensitive information, or payment changes must be verified through a second trusted communication method before action is taken.
One sentence can prevent a very expensive mistake.
Keep Learning
Want to strengthen your small business security without making cybersecurity complicated?
Read:
That Microsoft Login Request Could Be a Scam: Understanding Device Code Phishing
Learn how attackers can use legitimate-looking device login codes to trick employees into giving them access to company accounts.
Are Employees Using AI Without Your Knowledge? Understanding Shadow AI
Learn how employees using AI tools without company approval can expose sensitive business information, create security risks, and make it harder for a business to know where its data is going.
You can also download the FREE Small Business Cybersecurity Checklist, a simple 10-minute checkup that helps you review key areas such as passwords, MFA, employee access, devices, backups, phishing protection, and other basic security practices. Use it to quickly spot areas where your business may need stronger protection and identify practical next steps.
Stay safe,
The SimplifySec Team
Simple. Practical. Cybersecurity.
The content on this blog is published by SimplifySec Group LLC for general educational and informational purposes only. It is not legal, financial, or professional cybersecurity advice, and reading a blog post does not create a professional-client relationship between you and SimplifySec.
Cybersecurity risks depend on your specific environment, and recommendations that work for one system or business may not be appropriate for yours. You should evaluate your own circumstances and consult a qualified professional before acting on anything you read here. SimplifySec makes no warranty that the information is complete, current, or error-free, and to the fullest extent permitted by law disclaims liability for any loss arising from your reliance on it.
This blog may link to or reference third-party tools, vendors, or resources for convenience. SimplifySec does not endorse, control, or assume responsibility for those third parties or their content.
© 2026 SimplifySec Group LLC. All rights reserved.
This content may not be copied, reproduced, distributed, republished, stored, or transmitted in any form without prior written permission from SimplifySec Group LLC, except for brief quotations used with proper attribution as permitted by applicable copyright law.

