Cookie Consent by Free Privacy Policy Generator

WhatsApp scam hijacks accounts using Linked Devices feature without stealing passwords

Infosecurity Magazine reports that a new WhatsApp scam is hijacking user accounts by abusing the platform's Linked Devices feature, allowing attackers to gain persistent access without needing to steal passwords or intercept SMS codes. The attack works by tricking users into scanning a QR code or clicking a link that registers the attacker's device as a trusted linked device on the victim's WhatsApp account. Once linked, the attacker can read messages, send messages on behalf of the victim, and maintain access even if the victim changes their password. The scam has been observed using social engineering lures such as fake voting campaigns, prize notifications, and urgent security warnings. The technique exploits a legitimate feature designed for convenience, and there is no obvious indication to the victim unless they actively review their linked devices list.

Why this matters for UK organisations

For UK businesses where WhatsApp is used for customer communication, supplier coordination, or internal messaging, this technique represents a significant risk. Unlike traditional account takeover attacks that rely on credential theft, this method exploits a legitimate feature designed for convenience. Once an attacker's device is linked, there is no obvious indication to the victim unless they actively review their linked devices list. The business impact includes potential impersonation, access to sensitive conversations, and the risk that attackers could use compromised accounts to target customers, suppliers, or colleagues with further scams. This is particularly concerning for organisations where WhatsApp is used for business-critical communication, such as coordinating deliveries, confirming payments, or sharing sensitive information. The attack also highlights a broader challenge: many communication platforms include convenience features that can be abused if users do not understand how they work or how to review them.

What to review

Review whether staff understand how WhatsApp's Linked Devices feature works, and ensure that awareness training covers QR code scams and unexpected linking requests. Consider whether WhatsApp is appropriate for business-critical communication without additional controls, such as verification procedures for sensitive requests or alternative channels for confirming instructions. Encourage staff to regularly review their linked devices list in WhatsApp settings, and to remove any devices they do not recognise. Organisations should also consider whether business communication should be conducted on platforms with stronger administrative controls, audit logging, and centralised management. This incident is a reminder that convenience features can introduce risk, and that user awareness is a critical part of defending against social engineering attacks that exploit legitimate functionality.

Source: Infosecurity Magazine

News and blog posts
The UK's AI Safety Institute and the National Cyber Security Centre have issued...
Microsoft has published detailed analysis of ChainDrop, a credential-stealing...
Infosecurity Magazine reports that a new WhatsApp scam is hijacking user...
The Register reports that cybersecurity researchers have demonstrated how...