Wednesday, February 11, 2026
26.1 C
New Delhi

THIS WhatsApp Scam Lets Hackers Read Your Chats Without OTP Or Password

A new and dangerous scam is targeting WhatsApp users by misusing the app’s device-linking feature. Cybersecurity experts have flagged this attack, called GhostPairing, as highly deceptive because it does not involve stealing passwords, SIM cards, or verification codes. Instead, users are tricked into approving access themselves. The scam spreads quietly through trusted contacts and is hard to notice once activated.
Experts warn that this method exposes serious risks in how people understand device-pairing features on popular messaging apps.

GhostPairing WhatsApp Scam Explained: How Accounts Get Hijacked

According to cybersecurity researchers at Gen Digital, the scam starts with a harmless-looking message from a known contact. Messages like “Hey, I just found your photo!” are designed to spark curiosity. The message includes a link that appears with a Facebook-style preview inside WhatsApp, making it look safe.

When the link is clicked, users are taken to a fake webpage that looks like a Facebook photo viewer. Before showing the image, the page asks users to “verify” their identity. This is where the trap is set. The page secretly initiates WhatsApp’s official device-linking process.

Users are asked to enter their phone number, after which WhatsApp generates a numeric pairing code. The fake site then tells users to enter this code in WhatsApp, claiming it is a normal security step. Once the code is entered, the attacker’s device is approved without the victim realising it.

This gives hackers full WhatsApp Web access. They can read chats, download photos and videos, send messages, and receive new messages in real time. The victim’s phone keeps working normally, making the attack very difficult to detect.

WhatsApp Security Alert: Why GhostPairing Is Hard To Detect

Experts say GhostPairing is especially dangerous because it does not break encryption or exploit software bugs. Everything works exactly as designed. The scam relies purely on social engineering and human trust.

The campaign was first noticed in Czechia, but researchers warn it can spread globally. Once an account is compromised, attackers send the same fake link to the victim’s contacts and group chats, allowing the scam to spread fast through trusted networks.

Linked devices stay connected until users manually remove them. This means attackers can maintain access for long periods without being noticed.

To stay safe, users should regularly check Settings > Linked Devices, remove unknown sessions, avoid entering pairing codes from websites, enable two-step verification, and double-check unexpected messages, even from known contacts. Vigilance remains the strongest defence against such trust-based scams.

Go to Source

Hot this week

Drunk Father Burns Daughter’s Schoolbooks, Police Buy Her A New Set

Fearing further interference with her education, she called the...

FWICE urges the industry to offer financial, moral support to Rajpal

Actor Rajpal Yadav, who surrendered to Tihar Jail authorities on Thursday, is currently grappling with a debt of Rs 9 crore. Read More

Himani Shivpuri lauds Ranbir Kapoor’s ‘sanskar’

Veteran actress Himani Shivpuri recently met Ranbir Kapoor, praising his ‘sanskar’ and their Broadway memories from ‘Aa Ab Laut Chalen’. On Instagram, she shared a photo, captioning his warmth and foot-touching gesture. Read More

Russia to honour expired nuclear treaty if US does the same, says foreign minister

Russia will observe New START missile and warhead limits as long as the US does, Foreign Minister Sergei Lavrov said after the treaty expired last week, leaving both nuclear giants without formal constraints for the first time in decades. Read More

UK Drops ‘His Majesty’ In Official Communications, Opposition Slams Starmer Govt

The UK government changed its logo from “HM Government” to “UK Government,” prompting Conservative criticism over tradition and Labour’s monarchy views. Read More

Topics

Drunk Father Burns Daughter’s Schoolbooks, Police Buy Her A New Set

Fearing further interference with her education, she called the...

FWICE urges the industry to offer financial, moral support to Rajpal

Actor Rajpal Yadav, who surrendered to Tihar Jail authorities on Thursday, is currently grappling with a debt of Rs 9 crore. Read More

Himani Shivpuri lauds Ranbir Kapoor’s ‘sanskar’

Veteran actress Himani Shivpuri recently met Ranbir Kapoor, praising his ‘sanskar’ and their Broadway memories from ‘Aa Ab Laut Chalen’. On Instagram, she shared a photo, captioning his warmth and foot-touching gesture. Read More

Russia to honour expired nuclear treaty if US does the same, says foreign minister

Russia will observe New START missile and warhead limits as long as the US does, Foreign Minister Sergei Lavrov said after the treaty expired last week, leaving both nuclear giants without formal constraints for the first time in decades. Read More

UK Drops ‘His Majesty’ In Official Communications, Opposition Slams Starmer Govt

The UK government changed its logo from “HM Government” to “UK Government,” prompting Conservative criticism over tradition and Labour’s monarchy views. Read More

Has Kerala’s Left taken a Right turn?

AI-generated image Kerala chief minister Pinarayi Vijayan condemned his Assam counterpart Himanta Biswa Sarma’s “point-blank” video, terming it “communal hate mongering”. Read More

‘India stands in solidarity with Canada’: PM Modi offers condolences after 10 die in British Columbia school shooting

Prime Minister Narendra Modi (PTI image) NEW DELHI: Prime Minister Narendra Modi on Wednesday expressed shock over the deadly school shooting in Canada that claimed 10 lives and offered condolences to the victims’ families. Read More

‘Sadak chaap language’: BJP slams Rahul Gandhi’s speech in Lok Sabha

NEW DELHI: The Bharatiya Janata Party (BJP) on Wednesday denounced Rahul Gandhi’s comments during the Budget Session as “non-parliamentary”. Read More

Related Articles