WhatsApp voting scam exploits linked device access

A WhatsApp account takeover scam is spreading through messages that ask users to vote for a friend or relative in an online competition, before covertly linking the victim’s account to a device controlled by criminals.

The attack often begins with a message from a familiar contact whose account has already been compromised. The recipient is asked to support someone participating in a dance contest, school competition, pet show or similar event. The personal connection makes the request appear credible and encourages the target to act without checking the details.

Victims who follow the link are directed to a counterfeit voting page. The site may request a mobile number and display instructions involving a QR code or numerical pairing code. Those steps do not register a vote. Instead, they authorise a new device to access the victim’s WhatsApp account through the platform’s legitimate linked devices feature.

ADVERTISEMENT

Once pairing is completed, the attacker can open the account from a computer, tablet or companion phone. The criminal may gain access to conversations, photographs, videos, contact information and other material available to the linked device. The victim’s main phone can continue operating normally, allowing the intrusion to remain unnoticed.

The method differs from account theft schemes that depend on stealing a one-time password or transferring a telephone number to another SIM card. It relies on persuading users to approve access themselves. This use of social engineering can bypass suspicion because the request appears to come from someone already stored in the recipient’s contacts.

Attackers can then impersonate the victim and send the same voting request to friends, relatives and colleagues. Each hijacked account provides another trusted identity from which the campaign can expand. The chain-like pattern allows the fraud to spread quickly through personal and professional networks.

Financial fraud may follow the initial takeover. Criminals can study conversations, identify close contacts and request urgent payments while posing as the account holder. They may claim to need money for a medical problem, travel emergency, business transaction or temporary cash shortage. Some attackers could also use private messages or media for blackmail and extortion.

The scam exploits WhatsApp’s multi-device function, which permits one account to work across several connected devices. Each linked device can communicate independently while messages and calls remain protected by end-to-end encryption. Encryption prevents outsiders from intercepting communications, but it cannot protect an account when its owner is manipulated into approving an attacker’s device.

ADVERTISEMENT

Users can inspect connected sessions by opening WhatsApp, selecting Settings or the three-dot menu and choosing Linked devices. Any computer, browser, tablet or phone that is not recognised should be logged out immediately. The listed activity information can also help users identify devices added without their knowledge.

Security specialists advise users not to scan QR codes or enter pairing numbers after following unsolicited links. WhatsApp codes used to connect devices should be treated with the same caution as passwords and banking credentials. A genuine voting page has no reason to request permission to link a messaging account to another device.

Messages from trusted contacts should also be verified through a separate channel when they involve links, payments, codes or unusual requests. Calling the sender directly can establish whether the message is genuine. A compromised account may still show the correct profile photograph, name and previous conversation history.

Two-step verification can add a personal identification number to the account registration process, although it may not by itself stop a user from authorising a malicious companion device. Regular checks of the linked devices menu therefore remain important. Users should also install WhatsApp updates promptly and enable available biometric or device-level protections.

Anyone whose account has been compromised should disconnect unknown devices, warn contacts not to respond to suspicious messages and review conversations for unauthorised requests. Banking providers should be contacted without delay if money has been transferred. Screenshots, telephone numbers, web addresses and transaction details can be preserved for a cybercrime complaint.

The campaign reflects a broader shift towards attacks that misuse legitimate platform features rather than software flaws. Criminals increasingly combine convincing personal messages, fake websites and authentic security processes to make fraudulent actions appear routine.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com