Back to all lessons
Awareness Lessons
2 months ago

WhatsApp Introduces On-Device AI to Flag Scam Messages

This development highlights the growing threat of social engineering and messaging-based scams targeting everyday users who may not recognise fraudulent communication patterns. WhatsApp's on-device machine learning approach is notable because it analyses messages locally without compromising end-to-end encryption, preserving user privacy while adding a protective layer. The root issue is a widespread lack of user awareness around scam tactics delivered via trusted communication platforms. As attackers increasingly exploit personal messaging apps to conduct phishing, fraud, and impersonation attacks, platform-level safeguards alone are insufficient without complementary user education and vigilance.

Tactical Insight

Immediate actions

  • Enable any available scam detection or suspicious message warning features within your messaging applications.
  • Train employees and users to scrutinise messages from unknown contacts, especially those requesting personal information or urgent action.

Long-term improvements

  • Embed regular social engineering awareness training into your organisation's security awareness programme.
  • Establish clear organisational policies for verifying the identity of contacts before sharing sensitive information over messaging platforms.
  • Encourage users to report suspected scam messages using built-in platform tools to improve collective detection models.

Detection measures

  • Monitor for patterns of phishing or scam-related incidents reported by staff and track them through an incident log.
  • Implement mobile device management (MDM) policies that enforce the use of up-to-date, security-patched messaging applications across the organisation.