Back to Blog

Cybersecurity

Phishing, Fraud, and a Hijacked WhatsApp Account: The Cybersecurity Threats Hitting Zambian SMEs Right Now

Windhelm Digital·23 July 2026
Phishing, Fraud, and a Hijacked WhatsApp Account: The Cybersecurity Threats Hitting Zambian SMEs Right Now

The Morning the Shop's WhatsApp Stopped Being the Shop's

A boutique owner in Kabwata wakes up to find she cannot log into her business WhatsApp. Three years of customer conversations, order histories, and payment confirmations, gone from her screen in an instant. By the time she borrows a friend's phone to check, her contacts have already received messages "from her" asking them to send deposits to a new mobile money number for a stock clearance sale that does not exist.

She did not click a suspicious link. She did not install strange software. The night before, a message arrived that looked like it came from a friend, saying a verification code had been sent to her number by mistake and asking her to forward it back. She forwarded it. That single, ordinary act of helpfulness is all it took.

This is not a rare, unlucky story. It is one of the most common ways small Zambian businesses are losing money and reputation right now, and it is only one of several threats worth understanding properly.

Why Zambian SMEs Are Suddenly a Target

For years, cybersecurity felt like a large-company problem, something banks and mines worried about while small businesses got on with their day. That assumption no longer holds.

INTERPOL's 2025 Africa Cyberthreat Assessment recorded suspected scam notifications surging by nearly 3,000% in some African countries, with Zambia named alongside Egypt and Kenya as one of the markets showing the sharpest spikes. Phishing alone now accounts for over a third of all reported cyber incidents across the continent. Locally, a 2025 joint fraud awareness campaign involving the Bank of Zambia, ZICTA, MTN, Airtel, Zamtel, and Zed Mobile reported that nearly 80% of Zambians were targeted by some form of digital fraud in the past year.

Even Zambia's largest institutions are not immune. In November 2025, the ransomware group Clop claimed an attack on Zambia National Commercial Bank, threatening to leak sensitive data unless a ransom was paid. If a bank with a dedicated IT security team can end up in that position, a small business running its finances through a personal laptop and a WhatsApp Business account is a far softer target.

The attackers are not necessarily more sophisticated than they used to be. They are simply more numerous, more automated, and more willing to go after smaller, less defended targets because smaller targets are easier to hit at scale.

Threat One: The WhatsApp Business Hijack

For most Zambian SMEs, WhatsApp is not a side channel. It is the shopfront, the order book, and the customer relationship all in one app. That makes it an extremely attractive target.

The most common method is painfully simple. A scammer, often using an account they have already hijacked from someone in your contacts, messages you claiming they accidentally sent their verification code to your number and asking you to forward it. Moments later, a genuine SMS from WhatsApp arrives with a six digit code. If you forward that code, you have just handed the scammer everything they need to register your account on their own device and lock you out of it.

A newer variant, security researchers call it GhostPairing, works differently but reaches the same result. Instead of asking for a code, the scammer manipulates a victim into scanning a QR code or approving a device link request that looks routine. Once approved, the attacker has ongoing access to the account without ever touching a password, and the victim often has no idea anything is wrong until customers start receiving strange requests.

Once a business account is compromised, the damage compounds quickly. The attacker can message every customer and supplier in the chat history, impersonating the business owner with full knowledge of past orders and conversations, asking for deposits, top ups, or gift cards. Customers who trust the number, because it is the same number they have ordered from for years, often pay before they think to question it.

Threat Two: Mobile Money Fraud That Does Not Need a Hacker

Mobile money is the backbone of commerce for most Zambian SMEs, and fraudsters know it. The same 2025 awareness campaign put annual losses from mobile money scams in Zambia at over K120 million, while the free *707# fraud reporting line saved Zambians more than K21 million in a single year simply by giving people a fast way to flag suspicious transactions.

SIM swap fraud is a particularly serious version of this threat. A criminal convinces or bribes someone at a network provider, or exploits weak identification checks, to move your registered number onto a SIM card they control. From there, they can reset your mobile money PIN, drain your till or agent float, and intercept the one time codes meant to protect your account. Across Africa, SIM swap attacks account for a major share of the continent's mobile money fraud losses, estimated in the billions of dollars annually. ZICTA has responded by deactivating tens of thousands of SIM cards linked to fraud, including 49,000 in a single eight month period in 2024, but the scale of the problem means vigilance at the business level still matters enormously.

Not every mobile money loss involves a hacker at all. A significant share comes from far more ordinary routes: a till operator who shares a PIN with a "helpful" stranger, a fake promotional message claiming your network is giving away free airtime or cash in exchange for a small registration fee, or an employee quietly leaking customer numbers to a third party. These insider and social engineering risks rarely make headlines, but they drain far more money from small businesses over time than any single dramatic hack.

Threat Three: Phishing and the Fake Supplier Invoice

The classic phishing email, badly spelled, obviously fake, is becoming rarer. What is replacing it is far more dangerous for a business: a well written email or message that appears to come from a genuine supplier, bank, or government office, asking you to update payment details, click a link to "verify" an account, or approve an invoice.

This pattern, known internationally as business email compromise, is now responsible for billions of dollars in reported losses every year, and Africa is squarely within the trend that INTERPOL's assessment tracked. The mechanics are almost always the same. A business receives what looks like a routine invoice or payment request from a supplier it already works with, except the bank account details have been quietly changed. By the time anyone notices the mismatch, the money has already moved.

What makes this threat particularly dangerous for Zambian SMEs is how little it depends on technical sophistication. It depends entirely on a busy staff member trusting a message that looks familiar and acting on it quickly, which is exactly the kind of pressure small businesses operate under every day.

What the Law Now Says

Zambia's Cyber Security Act and Cyber Crimes Act, both passed in April 2025, established the Zambia Cyber Security Agency and created a formal legal framework for prosecuting exactly the kinds of offences described above, from account hijacking to fraud conducted through digital platforms. The practical effect for an SME owner is straightforward: these crimes are now clearly defined offences with a dedicated agency behind them, and reporting incidents through official channels, including the *707# line for mobile money fraud, feeds into a system that is actively being used to deactivate fraudulent SIM cards and build cases against repeat offenders.

The law gives you somewhere to turn. It does not, however, undo a stolen deposit or a hijacked WhatsApp account after the fact. That part is still on you.

What You Should Actually Do About It

None of the protections below require a large budget or a dedicated IT department. They require consistency.

  • Turn on two step verification in WhatsApp settings for every business account, and make sure more than one trusted staff member knows the PIN in case the primary owner is unreachable.
  • Never forward a verification code to anyone, no matter how convincingly the request is framed or how well you seem to know the person asking.
  • Verify any request to change payment or banking details with a phone call to a known, previously used number, never a number provided in the same message making the request.
  • Set a strict PIN policy for mobile money tills and agent lines, and treat any request from a stranger to "confirm" a PIN or OTP as an automatic red flag, regardless of the story attached to it.
  • Register more than one admin on shared business accounts where the platform allows it, so a single compromised device does not mean total lockout.
  • Train staff briefly but regularly on these specific scam patterns rather than relying on a single onboarding session years ago. Threats evolve, and so should the reminders.
  • Report suspicious activity immediately through *707# for mobile money and through your network provider for SIM related concerns. Speed matters far more than most people assume.

The common thread across all of these threats is urgency and trust. Every scam described in this article works by making a Zambian business owner feel that acting fast, without pausing to verify, is the safe choice. Building in that single pause, one phone call, one second admin, one policy that nobody skips, is usually enough to stop the loss before it happens.

Where Windhelm Digital Fits In

Most Zambian SMEs do not need an expensive security operations centre. They need a sensible, practical baseline: properly configured devices, clear policies staff actually follow, and someone who understands both the technology and the way Zambian businesses really operate day to day. That combination is what our IT consultancy work is built around at Windhelm Digital.

If you are unsure whether your business's current setup, from your shared devices to your WhatsApp Business account to how your staff handle supplier payments, would hold up against the threats described above, that is exactly the kind of assessment we carry out. Get in touch with us to talk through your specific situation, or look through the full range of our IT consultancy and support services to see how we work with businesses across Zambia.

The fraud is not slowing down. The businesses that build small, consistent habits now are the ones that will still be trusted by their customers a year from now.