Most WhatsApp accounts are not “hacked” in the technical sense. They are taken over because an attacker gets hold of the one-time registration code, either by talking the owner into reading it out, or by collecting it from a voicemail box, or by getting the owner to link the attacker’s device. The best protection is to switch on two-step verification, never share any code, and check your linked devices; the rest of this post explains why each of those works, and how a defender handles a takeover once it has happened.
This is written for people starting a cybersecurity career, so we look at it the way an analyst would: the mechanism, the signals, the response, and what you can practise. We describe techniques at the level you need to defend against them; we do not provide a playbook for attacking anyone. Only test systems and accounts you own or have written permission to test.
How does WhatsApp verify that a phone number is yours?
Everything starts with registration. When you set up WhatsApp on a phone, it sends a six-digit code to your number by SMS or voice call. Whoever enters that code registers the account on their device. According to WhatsApp’s guide to recovering a compromised account, re-registering with that code logs out every device that was logged in to the account.
From a security point of view, that code is a possession factor: it proves you can receive messages for that number at that moment. It does not prove you are the person who owns the account. That gap is what every technique below exploits.
WhatsApp adds an optional second check, two-step verification, described in its FAQ About registration and two-step verification. With it on, registering the number on a new phone also needs a secret only you know. Historically this was a six-digit PIN; WhatsApp has been moving users to a longer password, so follow whatever your app shows under Settings, Account (Two-step verification or Password).
Attack 1: the verification-code social-engineering scam
This is by far the most familiar pattern.
How it works:
- Someone tries to register your number on their phone. WhatsApp sends the six-digit code to you.
- At the same moment, you get a message, often from a contact’s account that has already been taken over: “Sorry, I sent you a code by mistake, please can you forward it?” Variants pose as a WhatsApp support agent, a delivery firm, a church or alumni group admin, or a competition you supposedly won.
- You forward the code. The attacker enters it, your WhatsApp is registered on their phone, and your app logs you out.
- If you have not set up two-step verification, the attacker sets it up. Now, when you try to re-register, you are asked for a PIN or password you never set.
- The attacker messages your contacts asking for urgent money transfers, or asks for their codes, and the chain continues.
Why it works: the message comes from a trusted contact, creates urgency, and asks for something that looks harmless. The SMS from WhatsApp itself says not to share the code, but people read the request, not the warning.
In MITRE ATT&CK terms, the analyst would describe this as social engineering to obtain an authentication code, closest to Multi-Factor Authentication Interception (T1111), followed by Impersonation (T1656) when the hijacked account is used against the victim’s contacts. Mapping incidents to a shared vocabulary like this is a habit worth building early.
Attack 2: voicemail-PIN abuse
This one needs no conversation with the victim at all.
How it works:
- The attacker starts registering your number and chooses the voice call option for the code.
- If you don’t answer, the automated call can go to your voicemail.
- The automated call goes to your voicemail, which records the code.
- Many mobile networks let you check voicemail remotely by dialling an access number and entering a voicemail PIN. If yours still uses a default or easily guessed PIN, the attacker can listen to the message and retrieve the code.
Why it works: voicemail is an old service that many people never configure. A default voicemail PIN quietly turns your voicemail box into a second inbox for your WhatsApp code.
Defence: set a strong, non-default voicemail PIN with your network, or ask your network whether you can disable voicemail if you don’t use it. Two-step verification also blocks this route, because the code alone is no longer enough to register.
Attack 3: linked-device abuse
WhatsApp lets one primary phone link up to four other devices, such as WhatsApp Web, the desktop app or a tablet. Linking is normally done by scanning a QR code with your primary phone, or by entering a linking code on the phone. This route does not re-register your number, so you are not logged out. The attacker gets a silent copy of your new messages instead.
How it works:
- Brief physical access. Someone borrows or picks up an unlocked phone for a minute and scans their own WhatsApp Web QR code with it.
- Tricked linking. A fake “verify your account” or “vote for my niece” page shows a genuine linking QR code or code from the attacker’s session and asks the victim to scan it or type it into WhatsApp. The victim thinks they are logging in to a website; they are actually linking the attacker’s browser to their account.
Why it is dangerous: the victim keeps using WhatsApp normally and may not notice for weeks.
Defence: check Settings, Linked devices regularly and log out anything you don’t recognise. Treat any website asking you to scan a WhatsApp QR code or enter a WhatsApp code as hostile unless you started the process yourself on your own computer. Keep a screen lock on your phone and don’t hand it over unlocked.
How do defenders detect a WhatsApp takeover?
Here is the honest part that beginners rarely hear: for a consumer messaging app, a company’s security team usually has no logs of its staff’s personal WhatsApp accounts. Detection is mostly human-reported. That shapes how a SOC or IT team prepares.
Signals that end up in front of an analyst or helpdesk:
- A staff member reports being suddenly logged out of WhatsApp with a message that the number is registered on another phone.
- Colleagues or customers report odd messages from that person: urgent money requests, requests for codes, unusual links.
- The user is asked for a two-step verification PIN or password they never set.
- An unfamiliar entry appears under Linked devices.
- For organisations that use WhatsApp Business for customers, complaints from customers about messages the business did not send.
Because the evidence is in people’s inboxes, not a SIEM, good defence is mostly process: a clear way to report, a fast response, and a warning that goes out to contacts.
How do you recover a hacked WhatsApp account? The defender’s playbook
This is the sequence a security-aware helpdesk would walk a user through, based on WhatsApp’s own compromised-account guidance. Write it as a one-page playbook; it is a good beginner exercise.
1. Re-register immediately. Open WhatsApp on the user’s own phone and register the number again with the six-digit code sent by SMS. This logs out the attacker’s device.
2. If asked for a PIN or password the user never set, the attacker has enabled two-step verification. WhatsApp’s guidance is that the user waits seven days before they can register again without it. During that time, warn contacts through other channels. Being prepared for this delay is one of the strongest arguments for setting up two-step verification before anything happens.
3. Turn on two-step verification as soon as the account is back, with an email address for resets.
4. Check Linked devices and log out everything unfamiliar.
5. Fix the root cause. Change the voicemail PIN if the voice-call route might have been used. If the user’s SIM stopped working around the same time, contact the mobile network: losing service unexpectedly can indicate a SIM swap, which is a separate and more serious incident.
6. Warn contacts through another channel (calls, SMS, email, social media): “My WhatsApp was taken over on [date]. Ignore any money or code requests sent from it.”
7. Record the incident. Time logged out, how the code was obtained if known, what was sent from the account, which contacts were targeted, and whether anyone sent money. If money was lost, the victim should contact their bank immediately and report to the police.
8. Report it to WhatsApp through in-app support, per the FAQ.
What should you do today to protect your WhatsApp from hackers?
The personal checklist, in order of impact:
- Turn on two-step verification (Settings, Account (Two-step verification or Password)) and add an email address. See WhatsApp’s account security tips.
- Create a passkey if your app offers it (Settings, Account, Passkeys). WhatsApp describes passkeys as a way to verify with your device’s screen lock or biometrics instead of an SMS code.
- Never share any code, from WhatsApp or anyone else, with anyone, including friends, family or “support”. WhatsApp’s guidance is never to share it.
- Change your voicemail PIN from any default.
- Check Linked devices once a month.
- Lock your phone with a PIN, pattern or biometrics.
- Verify odd requests out of band. If a friend asks for money or a code on WhatsApp, call them on a number you already have.
If MFA, passkeys and possession factors are new to you, Passwords, passkeys and MFA explained covers the theory behind every item on this list.
What can a cybersecurity beginner practise from this?
You can build real skills here without attacking anyone.
- Write the playbook. Turn the eight-step recovery sequence above into a one-page incident playbook for a fictional company, Acme Fintech, whose sales team uses WhatsApp with customers. Include who the user contacts, the first five minutes, and the contact warning template.
- Run a tabletop exercise. With a study partner, one plays a staff member who has just been logged out, the other plays the helpdesk. Time how long it takes to reach step 4.
- Analyse a scam message safely. Take a screenshot of a code-request scam you have received, remove personal details, and annotate it: pretext, urgency trigger, request, red flags. If it includes a link, follow our workflow in How to analyse a phishing link safely; never open it on your main phone.
- Map it to ATT&CK. Write a short paragraph mapping each attack above to ATT&CK techniques, as we did for attack 1. It’s good interview practice.
- Compare with other account takeovers. Read how account takeovers work and how defenders stop them and note what is common: in almost every case, a single factor that the user could be talked out of.