Back to blog
Security7 min read

Why Sharing Files Over WhatsApp or Slack Is Riskier Than Email

Casual file sharing over WhatsApp, Telegram, and Slack feels safer than it is. Here’s what Wall Street’s SEC fines reveal about the real risk — and what actually fixes it.

Email gets blamed for most confidential-document mishaps, but a lot of sensitive files never touch email at all anymore — they get pasted straight into a WhatsApp group, a Telegram chat, or a Slack channel, because it’s faster and feels more casual. That feeling is the problem. The risk didn’t go away when the file moved from an attachment to a chat message — it got less visible.

What actually happens when a file lands in a chat app

Once a document is sent as a real attachment in WhatsApp, Telegram, or Slack, it behaves exactly like an email attachment, minus the paper trail. It can be forwarded into another group with two taps. It gets saved automatically to a phone’s camera roll on many default settings. It sits in that chat’s media history indefinitely, on every device in the conversation, with no record of who opened it, when, or whether it was ever passed along further.

This isn’t a hypothetical — it’s already cost real companies real money

Multiple Wall Street banks have paid well over $2 billion in SEC and CFTC fines across several enforcement rounds since 2021, specifically for conducting business communications over WhatsApp, Signal, and iMessage. It’s worth being precise about what these fines were actually for: not a file leaking, but a recordkeeping failure. Regulated financial firms are legally required to archive and monitor business communications, and once that communication happens on an unmonitored consumer chat app, the firm has no way to produce a record of it — which is itself the violation. The lesson generalizes well beyond finance: any organization that can’t account for where its sensitive files went, on any platform, has the same underlying governance gap. Regulators just happened to put a number on it first.

The part most companies get wrong: they focus on which app is “secure enough”

WhatsApp and Telegram’s encryption in transit is genuinely solid — that’s not the vulnerability. The vulnerability is everything that happens after the message arrives: no audit trail, no way to revoke access, no NDA gate, and forwarding that takes less effort than typing a reply. Debating whether one chat app is more secure than another misses the actual gap, because the gap is the same regardless of which app is used.

What actually closes the gap

The fix isn’t picking a “more secure” messaging app — it’s not sending the file into the chat app at all. Share a link instead of the file itself, and require identity verification before that link does anything. The chat app becomes a delivery channel for a pointer, not a copy of the document:

- The recipient still verifies with a one-time password before anything loads. - An NDA or disclaimer, if required, still has to be accepted first. - The file opens in a secure viewer, not a download that lands in a camera roll. - Every access attempt is still logged, no matter which app carried the link.

The practical shift

Nobody’s going to stop using WhatsApp, Telegram, or Slack for quick coordination — that’s not realistic, and it’s not the point. The point is that the file doesn’t need to be the thing that travels through those apps. A FileLink shared over WhatsApp or Slack [works everywhere you already communicate](/anywhere) — it carries the exact same security as one shared over email: OTP verification, NDA gating, watermarking, revocation, and a full audit trail — regardless of which app the link was pasted into.

For a deeper look at the [security architecture](/security) behind OTP verification, watermarking, and audit trails, the principles are the same no matter which platform carried the link.

See FileLink on your own files.