Warning of electronic fraud compromising WhatsApp accounts

Researchers at cybersecurity firm Malwarebytes have uncovered an active phishing campaign targeting WhatsApp users through a “Vote for my friend” scam, enabling attackers to hijack accounts without ever needing the password. Researcher Peter Arntz explained that the attack exploits the app’s feature for linking trusted devices, combined with simple phishing tactics that trick victims into approving a new session controlled by the attacker.
According to a Malwarebytes report, successful breaches “allow attackers to access the victim’s WhatsApp account, send messages, read conversations, and collect personal information.” The scam typically begins with an invitation to vote in a fake contest, such as a dog beauty pageant or a school competition, sent from a contact whose account has already been compromised.
Arntz noted that some versions of the scam take a less direct approach: victims are asked to open WhatsApp, navigate to the list of linked devices, and enter a six-digit code provided directly by the scammer, thereby bypassing any notifications that might arise from a password reset.
Malwarebytes warned against sharing WhatsApp verification codes with anyone, “even if the request appears to come from an acquaintance,” and advised verifying any voting requests through a communication channel other than the app itself. Arntz also recommended enabling two-step verification, which “adds an extra layer of protection that prevents attackers from hijacking the account even if they obtain the verification code via SMS.”
For its part, Meta, the owner of WhatsApp, stated that it has begun rolling out new alerts to warn users when behavioral indicators suggest that a device-linking request may be suspicious, while also displaying the request’s source. A WhatsApp spokesperson emphasized that users should not share their six-digit verification code with anyone and advised reviewing the app’s privacy settings.
For users at higher risk, WhatsApp recommended enabling “Strict Account Settings,” which automatically activates two-step verification, locks security notifications, disables link previews, and blocks high volumes of messages from unknown accounts. The report stressed that this feature is “nuclear” in its restrictive nature and should only be enabled for those suspected of being targeted by advanced cyber campaigns.