CYBER WELFARE

Protect your Digital Privacy

Contacts scammed in your name: what happens when messages come from your number

The risks of your account being used for spam describe what happens to the account: conversations read by others, your address book copied, messages written in your name. The consequences describe what happens to people: the client who pays into the wrong account, the work that grinds to a halt, the phone calls that have to be made, the trust that starts to crack.

When contacts are scammed in your name, the damage has one particular feature: it does not fall on you first, but on the people who trusted you. That is why it is worth looking at closely, calmly and without dramatising, but also without downplaying it.

This post expands on the recommendation on checking messages sent in your name.

A realistic scenario

John runs a small joinery workshop. He works to order: kitchens, fitted wardrobes, the occasional window frame. He talks to his clients almost entirely through a messaging app, from the same phone number he has had for years. That is where he sends quotes, photos of finished jobs and the bank details for deposits.

One Tuesday morning the app asks him to verify his number again. John assumes it is an update and decides to deal with it in the evening. In the meantime, messages go out from his account to a few clients with a job in progress: “Good morning, because of a problem with the bank, payments now need to go to these new bank details. Thank you, and sorry for the trouble.”

The tone is his, the earlier conversations are all there, and the message arrives from the usual number. One client pays the deposit for a kitchen into the new account. Another, fortunately, rings John to check.

How things get to that point is explained in the post on messaging account takeover. Here we are interested in what happens next. And the consequences spread across five planes.

1. Operational consequences: when your work channel breaks down

A practical example

John can no longer use the app as before: the account shows as active on another device, or the verification asks for a security PIN he never set. Meanwhile his clients keep writing to him, but he either cannot see their messages or no longer knows which ones are genuine.

Possible effects

  • the main channel with clients and suppliers stays unreliable for hours or days;
  • quotes, photos and agreements made in chat are out of reach exactly when they are needed;
  • every client has to be contacted another way, one by one;
  • deliveries and site visits slip, because the day is spent putting things right;
  • account settings, linked devices and protections have to be rebuilt from scratch.

Why it matters

For many small businesses, the messaging app effectively is the sales office. When that channel can no longer be trusted, work does not stop because of a technical fault: it stops because nobody knows which messages to believe any more. It is a disruption that never appears on an invoice, but you feel it straight away.

2. Financial consequences: when the payment ends up in the wrong place

A practical example

The client who paid the deposit into the new account tells John a few days later, receipt in hand. John has received nothing. The client has paid, but not him.

Possible effects

  • money paid into accounts that belong neither to the client nor to John;
  • expected income that never arrives, with knock-on effects on a small business’s cash flow;
  • jobs put on hold until the situation is cleared up;
  • indirect costs: time, technical support, possibly professional advice;
  • in some cases, money that cannot be recovered.

Why it matters

A bank transfer that has already gone through is usually hard to recall. The payer’s bank may try to recall it or flag it, but the outcome is not guaranteed and depends a great deal on how much time has passed. That is why noticing early and warning your contacts straight away matters more than anything else. Nothing happens automatically: talking about a “guaranteed” refund would be a promise nobody can make in advance.

3. Legal consequences: when the question becomes “who pays?”

A practical example

The client believes the deposit has already been paid. John believes he never received it. Both have a point, and both were deceived by the same message. Meanwhile, whoever took control of the account may also have seen other clients’ addresses, phone numbers and job details.

Possible effects

  • an open question with the client about who should bear the loss, which depends on the specific circumstances;
  • good reason to report the matter to the police and to keep evidence: messages, receipts, times, screenshots;
  • reports to make to the bank and to the messaging platform;
  • if the chats held clients’ personal data, the need to assess whether this is a data breach to be handled under data protection rules.

Why it matters

Who is responsible for a loss caused by a fake message cannot be decided in the abstract: it depends on what was written, how it was checked, what had been agreed and which law applies. This section describes the general picture and is not legal advice, nor does it promise any outcome on liability or refunds: in a real case it is worth speaking to a professional and, if clients’ personal data is involved, to your data protection contact.

4. Reputational consequences: when your name becomes the bait

A practical example

The message with the new bank details reached several people. Some ignored it, one paid, another mentioned it to a neighbour who was waiting for a quote. In a small town, news travels fast.

Possible effects

  • clients who, from then on, ask for confirmation of every message;
  • doubts about how reliable the business is, even though John did nothing wrong;
  • having to explain what happened several times, to different people;
  • pending quotes that go cold;
  • a name that someone else has used to deceive.

Why it matters

In scams carried out in your name, your reputation is precisely the tool used against your contacts: the message works because they trust you. Trust cannot be repaired with a password change. It is rebuilt through openness and over time, which is why a clear, prompt warning to your contacts is part of the solution, not an admission of guilt.

5. Personal consequences: when it weighs on the person

A practical example

John spends the evening on the phone with his clients. He feels he owes something to the one who paid, even though he never wrote that message. He keeps reopening old chats to work out what else has been read.

Possible effects

  • a sense of guilt towards the people who were harmed;
  • stress and the feeling of having lost control of an everyday tool;
  • personal time swallowed up by calls, checks and reports;
  • private and family conversations read by strangers;
  • distrust of a tool that used to be used without a second thought.

Why it matters

This is the least visible consequence, but often the longest-lasting. It is worth saying clearly: if this has happened to you, it is not because you were naive. These scams are designed to look ordinary, and they target precisely the people whose contacts trust them. Feeling responsible is understandable; blaming yourself helps neither you nor the people who were scammed.

PlaneWhat changesHow long it lasts
OperationalWork channel unreliable, clients to be contacted one by oneHours to days
FinancialPayments into other people’s accounts, missed income, indirect costsWeeks, not always recoverable
LegalQuestions about who bears the loss, police report, possible client dataVariable, with formal steps
ReputationalClients’ trust to be rebuilt, word of mouthMonths
PersonalGuilt, stress, private life exposedVariable, often the longest

The cost no one budgets for: time

You know the amount that ended up in the wrong account. The time spent putting things back in order is much harder to see, and it is almost always the heaviest item.

An indicative estimate, based on how these cases usually unfold:

ActivityIndicative time
Regaining control of the account and removing unknown linked devicesUnder an hour to several days, depending on the platform
Warning clients, suppliers and contacts another way1–3 hours
Talking to the bank and to the client who paidA few hours, often spread over several days
Gathering evidence and reporting to the police1–2 hours
Checking your phone, other accounts and security settings1–2 hours
Answering clients’ doubts over the following weeksOngoing

These are hours that were never on the calendar, taken away from the workshop and from family, and packed into days when you are already under pressure.

The comparison speaks for itself: protecting the account and agreeing with your clients how payments are confirmed takes less than an hour, and you only have to do it once.

The consequences that fall on other people

In this kind of incident, the people most exposed are not the account holder but those who receive the messages.

  • Clients receive a convincing request from the usual number, and some of them pay. At that point, the financial loss is theirs.
  • Suppliers may receive requests for advance payments or information they have no reason to doubt.
  • Family and friends receive messages, links or requests for “codes sent by mistake” in turn, which are used to take over their accounts too.
  • Your contacts’ contacts: one hijacked account can become the starting point for the next, and the scam spreads from one address book to another.
  • The people whose data was in the chats — addresses, photos of their homes, documents — face an exposure they did not choose.

This is why, in the Cyber Welfare Framework, the security of an account is not treated as a purely private matter: protecting your number also protects everyone who trusts that number.

How this ties back to the recommendation

All of these consequences have one thing in common: the time that passes between the first fake message and the moment the account holder notices.

The shorter that time, the fewer people receive the message and the fewer payments go out. Often the first to notice is a contact who writes: “Did you send me a strange message?” Taking that question seriously, checking sent messages and active sessions, and acting straight away is exactly what recommendation R29 asks you to do.

To know which clues to look for, see the post on the signs of messages you did not send, which sits alongside the general guide on how to tell if your account was hacked for any kind of account.

How to reduce the risk

  1. Take every warning from your contacts seriously. A “was that really you?” is often the first and most reliable sign that something is wrong.
  2. Agree a rule with your clients: bank details never change by message. If they genuinely do change, it is confirmed by voice, by calling a number you already know. Stating this on invoices or quotes helps everyone.
  3. Turn on multi-factor authentication — a second proof of identity on top of your password — and, on messaging apps, the two-step verification PIN. See protecting accounts with a second factor.
  4. Check the linked devices on messaging apps every now and then, and remove any you do not recognise.
  5. Turn on account login alerts, so that a new sign-in does not go unnoticed.
  6. Never pass on verification codes, not even to a contact who asks for one “sent by mistake”.
  7. If it happens, follow a clear order: the post on what to do if your account is sending messages sets out the steps, including checking your phone and spotting the signs of malware.

Quick checklist

  • ☐ I know which clients or contacts I would warn first if my account sent fake messages
  • ☐ I have a second way to reach them that does not depend on the messaging app
  • ☐ I have told my clients that my bank details never change by message
  • ☐ I have turned on the two-step verification PIN and multi-factor authentication wherever possible
  • ☐ I check my linked devices and sent messages every now and then

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that a hijacked account becomes a tool for deceiving the people who trust you
SkillsTelling the five planes of consequence apart and knowing which contacts to warn first
Secure BehaviourAgreeing rules for confirming payments and responding at once to warnings from contacts

Reference level: FL2 — Beginner. This is the level at which security stops being an abstract rule and becomes a choice with a clear reason behind it, including out of respect for other people.

Conclusion

A messaging account taken over by someone else does not produce “a cyber problem.” It produces a client who paid the wrong person, difficult phone calls, a name used as bait, and the feeling of having to answer for something you did not do.

The good news is that most of these consequences can be reduced with habits within anyone’s reach: protecting the account with a second factor, agreeing with clients that payments are confirmed by voice, and listening to the contact who asks “was that really you?”. If you would like to see where you stand with your digital habits more generally, you can take the digital resilience self-assessment.

Something to think about. If a client received a message from your number tomorrow with different bank details, what would make them stop and call you before paying?

Related resources

Short explainers from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.