Press "Enter" to skip to content

WhatsApp Scam Hijacks Accounts Without Stealing Passwords

Cybersafety brand Avast have uncovered a new WhatsApp scam that convinces users to give attackers access themselves.

We’re calling it a “GhostPairing” attack, here’s how it works:

  1. The scam starts with a message that comes from a trusted contact: “Hey, I found your photo.”
  2. When users tap the link, they’re shown a fake Facebook-style page that asks them to “verify” before viewing the image.
  3. What looks like a harmless security step is actually WhatsApp’s own device-linking flow.

By entering a legitimate pairing code, victims unknowingly add the attacker’s browser as a linked device, giving criminals ongoing access to messages, photos, and contacts, without changing a password or locking the user out of their account.

Why this matters

  • No passwords are stolen: The attack uses WhatsApp exactly as designed, making it harder for users to recognise and harder to detect.
  • The phone keeps working normally: Victims often don’t realise a second device is connected and watching conversations in real time.
  • It spreads through trust: Compromised accounts message friends, family, and group chats, allowing the scam to snowball organically.
  • It enables deeper fraud: Access to private conversations, voice notes, and photos creates opportunities for impersonation, targeted scams, and extortion.

What consumers should know right now

  • Check WhatsApp → Settings → Linked Devices and remove anything unfamiliar
  • Treat any request from a website to scan a WhatsApp QR code or enter a pairing code as suspicious
  • Enable two-step verification and share awareness with family and group chats

 

Please Visit Visit  for more information: www.avast.com

 

Please follow and like us:

Author

Be First to Comment

Leave a Reply

Technology Reseller Magazine & Site is Published by Kingswood Media 2024