Skip to main content

Scam could let hackers lock you out of WhatsApp

WhatsApp
(Image credit: guteksk7 / Shutterstock)

A recently discovered WhatsApp scam could result in you being locked out of your account permanently.

For so many of us, WhatsApp has become an integral part of keeping in touch with friends, family, colleagues and more. Being unable to access it would have serious ramifications – and a newly discovered scam could do just that.

With access to just your phone number, a hacker can orchestrate an attack that could result in your account being deactivated. What's more, it doesn't matter if you have two-factor authentication (2FA) enabled or not.

While slightly convoluted, the attack is surprisingly simple to carry out, and takes advantage of a feature which is actually supposed to keep users secure. As described in detail by Forbes, which was first to report it, the scam uses two separate attack vectors, starting off with an attacker who knows your phone number requesting to activate WhatsApp on a different phone using your details.

WhatsApp will then attempt to verify the log in attempt by asking you for confirmation, In the meantime, the attacker can enter invalid confirmation codes at their end, ultimately resulting in your account being locked for 12 hours.

The second part of the attack sees the perpetrator contacting WhatsApp claiming to be you, reporting that their phone has been lost or stolen and that the account should be deactivated. WhatsApp automatically obliges, effectively locking you out of your account with a process that can be repeated time and time again.

What you should do

Even though the attack can be carried out on accounts that have 2FA enabled, WhatsApp says that the issues is unlikely to affect many people.

A spokesperson told both Forbes and TechRadar: "Providing an email address with your two-step verification helps our customer service team assist people should they ever encounter this unlikely problem. The circumstances identified by this researcher would violate our terms of service and we encourage anyone who needs help to email our support team so we can investigate."

The company advised TechRadar that if you suspect your WhatsApp account is under attack, you can send reports to inside the app by going to Settings > Help > Contact us. You can also email support@whatsapp.com for assistance.

Via Android Authority