Playbooks · 6 min read
Fintech on WhatsApp: Your Messages Look Like the Scam
Every other business on this channel is asking what it can automate. A fintech has to start somewhere else, with a fact that shapes every decision after it.
Your customers cannot tell your messages apart from a criminal's.
Not because they are careless. Because on a messaging app the visible identity of a sender is a name and a small circular photograph, both of which can be copied in a minute, attached to any number, and sent to anybody. A person who is used to getting messages from you has been trained to expect them, and that training is the attack.
Impersonation is the defining constraint here
Any company that handles money is impersonated. It is not an edge case, it is a standing condition, and it happens most on the channels people trust most.
The pattern is dull and effective: a message that looks like it came from a financial company, some urgency, and an action. Verify your KYC or the account will be frozen. Your payment failed, pay here. Refund pending, share the code. Somebody has an account with you, so the message is plausible, and the app it arrived in is the one their family uses.
You cannot prevent this. What you can do is make your own behaviour so narrow and so consistent that any deviation from it is visible to an ordinary person who is not paying attention.
- Never ask for anything, ever. No OTP, no PIN, no card number, no CVV, no account number, no password, no screenshot of a statement, no document. If your automation never asks, then a message that asks is not you — and that is a rule a customer can actually remember.
- Never send a payment link or a collection request in an automated message. Not for a genuine due amount either. The moment you do it once, every impersonator's version becomes credible.
- Never create urgency. Account suspension, blocking, last chance, act within two hours. Those sentences are the scam's whole mechanism; using them yourself donates your brand to it.
- Say the rule out loud, in the messages themselves. One line, every time: this number never asks for an OTP or a payment. It costs nothing and it is the only defence the customer holds.
- Keep one number and publish it. If everything comes from one verified business number that you list on your own site and in your app, a different number is itself the warning.
Design the automation so that a message asking the customer to do something is, by definition, not from you.
A phone number is not authentication
The second reason to keep this small. On this channel the only thing you know about the sender is which number they are messaging from, and a phone number is a weak identity.
Numbers get recycled by operators and handed to a stranger. Phones get lost, borrowed, shared within a family, and left unlocked. SIM swap is a known fraud, and it targets exactly the accounts a fintech holds. A message arriving from a number on file is evidence of very little.
Which means anything about a specific person's money must not be answered automatically, however easy the lookup is:
Never automate
Safe to automate
Even a notification that seems harmless leaks. "Your payment of the usual amount was received" tells whoever is holding that phone that an account exists and roughly what it does. Keep automated messages free of amounts, of last-four digits, of anything that confirms a relationship to somebody reading over a shoulder.

KYC is not a chat flow
It gets proposed in every fintech planning meeting, because collecting documents over chat feels frictionless.
Do not do it. Identity documents arriving as photographs in a business inbox create a store of exactly the material fraud runs on, in a place that was not designed to hold it and that several employees can open. It also teaches customers that sending a PAN card to a chat is normal, which is the precise behaviour every impersonator needs them to have learned.
Identity verification belongs in your own authenticated app or web flow, where you control the session and the storage.
What the rules require is not something we can tell you
Financial services messaging in India sits under regulators, industry rules and data protection law simultaneously, and requirements differ by what kind of licence or arrangement a company operates under. Those rules change.
We are not qualified to tell you what any regulator currently permits or requires, and no vendor is — any tool advertising that it makes you compliant is selling something that cannot exist. What a tool can honestly offer is mechanics: access control, logs, deletion, and refusals it can evidence. Compliance is a property of how the company operates, and it is a question for your own compliance and legal advisers before a single template is written.
Nothing in this post is financial, legal or regulatory advice.

The narrow, honest use
After all of that, a real use remains, and it is deliberately unglamorous.
Automated messaging can tell people how to reach support, what the hours are, where to find the app, and what the company will never ask for. It can acknowledge that a message arrived and route it to a human quickly. It can be the channel on which you run a standing, repeated education message about impersonation.
That is a smaller product than most fintech teams imagine when they start this conversation. It is also the version that does not end up in a screenshot on a consumer forum.
What we run today
PostEngage answers Instagram comments and DMs on the official Graph API. That is the entire product; there is no WhatsApp in it, on any plan or behind any flag. This post is about the channel because fintech teams search for it and the honest description is more useful than a pitch.
On the channel we do run: seven days to answer a comment, twenty-four hours in a DM thread, restarted only by their own next message. Templated replies are free and unlimited, a credit is spent only when the AI writes new text, the free tier is 100 credits with no card, and packs start at ₹499.
Related: financial services on Instagram, what governs this channel in India, and how business numbers get banned.



