Scam could let hackers lock you out of WhatsApp

WhatsApp
(Image credit: guteksk7 / Shutterstock)

A recently discovered WhatsApp scam could result in you being locked out of your account permanently.

For so many of us, WhatsApp has become an integral part of keeping in touch with friends, family, colleagues and more. Being unable to access it would have serious ramifications – and a newly discovered scam could do just that.

With access to just your phone number, a hacker can orchestrate an attack that could result in your account being deactivated. What's more, it doesn't matter if you have two-factor authentication (2FA) enabled or not.

While slightly convoluted, the attack is surprisingly simple to carry out, and takes advantage of a feature which is actually supposed to keep users secure. As described in detail by Forbes, which was first to report it, the scam uses two separate attack vectors, starting off with an attacker who knows your phone number requesting to activate WhatsApp on a different phone using your details.

WhatsApp will then attempt to verify the log in attempt by asking you for confirmation, In the meantime, the attacker can enter invalid confirmation codes at their end, ultimately resulting in your account being locked for 12 hours.

The second part of the attack sees the perpetrator contacting WhatsApp claiming to be you, reporting that their phone has been lost or stolen and that the account should be deactivated. WhatsApp automatically obliges, effectively locking you out of your account with a process that can be repeated time and time again.

What you should do

Even though the attack can be carried out on accounts that have 2FA enabled, WhatsApp says that the issues is unlikely to affect many people.

A spokesperson told both Forbes and TechRadar: "Providing an email address with your two-step verification helps our customer service team assist people should they ever encounter this unlikely problem. The circumstances identified by this researcher would violate our terms of service and we encourage anyone who needs help to email our support team so we can investigate."

The company advised TechRadar that if you suspect your WhatsApp account is under attack, you can send reports to inside the app by going to Settings > Help > Contact us. You can also email support@whatsapp.com for assistance.

Via Android Authority

TOPICS
Sofia Elizabella Wyciślik-Wilson
Freelance writer

Sofia is a tech journalist who's been writing about software, hardware and the web for nearly 25 years – but still looks as youthful as ever! After years writing for magazines, her life moved online and remains fueled by technology, music and nature.

Having written for websites and magazines since 2000, producing a wide range of reviews, guides, tutorials, brochures, newsletters and more, she continues to write for diverse audiences, from computing newbies to advanced users and business clients. Always willing to try something new, she loves sharing new discoveries with others.

Sofia lives and breathes Windows, Android, iOS, macOS and just about anything with a power button, but her particular areas of interest include security, tweaking and privacy. Her other loves include walking, music, her two Malamutes and, of course, her wife and daughter.

You can find her on Twitter and Mastodon.

Read more
Man holding a mobile phone with warning notification and spam message icon
Scammers have a new phishing trick for iPhone users – here’s how to avoid falling victim
Trojan
WhatsApp patches security flaw which let hackers install spyware
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
WhatsApp China VPN
Paragon spyware campaign targeting journalists disrupted by WhatsApp
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Russian criminal gang Star Blizzard found hitting WhatsApp accounts
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras