Your WhatsApp could be being read right now – how Kazakhstanis can check this
How scammers gain access to your WhatsApp
Many people believe that if their smartphone is always with them, it is impossible to hack their WhatsApp. However, this is not the case.
"WhatsApp has a feature that allows you to use one account on several devices simultaneously: for example, on a smartphone, computer, tablet, or a second phone. Typically, all it takes is opening WhatsApp Web or the app on another device and confirming the connection by scanning a QR code or entering a special code," TSARKA specialists say.
Once confirmed, the new device becomes one of the account's authorized devices. It gains the ability to view chat history, receive new messages, and send them on behalf of the owner. This is precisely what scammers often exploit.
Phishing pages
According to experts, one of the most common schemes works like this: a user attempts to open WhatsApp Web on a computer but lands on a fake (phishing) copy instead of the official site.
"Visually, such a page is almost indistinguishable from the real one. A QR code is displayed on the site. The user, certain they are connecting their own computer, scans it via WhatsApp without suspicion. In reality, however, they are authorizing a connection for the attacker's device," a specialist explained.
Photo: depositphotos.com/ itchaz.gmail.com
Polls and contests
Many other equally common schemes operate on a similar principle. For instance, a person is sent a link and asked to:
vote for a child, an acquaintance, or a colleague;join a private chat or group;confirm participation in a contest;receive a gift, compensation, or social benefit;open a work document;undergo an account verification;verify their identity;connect to an online meeting.
To do this, the user is asked to scan a QR code, provide their phone number, and then share or manually enter a code received via WhatsApp.
"This code is used to link a new device to the account. As soon as the person confirms the operation, the scammers gain access to their WhatsApp," TSARKA noted.
Remote access and malicious extensions
TSARKA explains that even if a user opens the official WhatsApp Web site to link their phone, there is still a risk of granting access to scammers.
"If a work or home computer is infected with malicious software, unauthorized parties can gain access to the account," the specialists warn.
For example, a computer may harbor:
remote access software;malicious browser extensions;
Trojans or other data-stealing software;a compromised Chrome or Edge profile;a saved session of another user;remote administration tools that the owner is completely unaware of.
"In such a situation, the user might see a perfectly familiar work laptop in the 'Linked Devices' section. However, in reality, an attacker has already gained access to the account through it," noted the Center for Analysis and Investigation of Cyberattacks.
Owners often notice nothing for a long time
Once an additional device is connected, the center's specialists explain, scammers gain the ability to read correspondence and send messages on behalf of the account owner. Meanwhile, WhatsApp on the primary phone continues to function as usual: the user can still send and receive messages, unaware that someone else has gained access to their account.
The reason is that WhatsApp does not disconnect the primary device after a new one is linked. Therefore, the user continues to use the messenger as usual and may not immediately notice that their account is being used from another device.
Two-step verification and why it doesn't always help
Many believe that enabling two-step verification with a PIN makes their WhatsApp account completely hack-proof. However, this is not entirely the case.
While two-step verification significantly enhances security, its primary purpose is to prevent someone from registering your phone number on a different device. This protection does not cover instances where scammers have already gained access to an active, authorized session.
For example, two-step verification will not help if:
an attacker is already using an active WhatsApp Web session;a secondary device was previously linked to the account;the user unwittingly authorized a third-party device by scanning a fake QR code or entering a confirmation code;scammers gained access to a computer where WhatsApp Web was already open.
What to do if scammers gain access
If you notice suspicious devices, messages you didn't send, or other signs of account takeover, it is critical to act quickly. The sooner you terminate unauthorized access, the less likely attackers are to defraud your contacts or steal additional information.1. Document the incident
Before disconnecting devices or changing settings, save information about the breach. This can help identify how access was obtained and may be useful when contacting support or during an investigation.
Take screenshots of:
the list of linked devices;suspicious messages sent in your name;the "last active" timestamps for devices;payment details or banking info requested by scammers;login notifications or new device connection alerts.
Do not delete chats immediately, as they may contain vital evidence regarding the attackers' activities.2. Strengthen security settings
After disconnecting unauthorized devices, you must review and update your account's security parameters.
Experts recommend the following:
change your WhatsApp two-step verification PIN;verify the email address linked to the account;change your email password;enable multi-factor authentication (MFA) for your email account;enable WhatsApp biometric lock (Fingerprint or Face ID);ensure the phone itself is secure with a password, PIN, or other screen lock.
3. Disconnect all suspicious sessions
Go to: WhatsApp → Settings → Linked Devices.
If you see an unrecognized device, log it out immediately.
If you cannot identify which connection is suspicious, it is best to disconnect all linked devices and re-authorize only those you use. This will revoke access for any previously established malicious sessions.4. Regularly monitor linked devices
Even if you believe your account is secure, experts recommend periodically reviewing your list of linked devices. It takes only a few minutes and helps detect suspicious activity early.
Pay close attention to:
unknown devices;old computers you no longer use;browsers that haven't been used for WhatsApp in a long time;devices with suspicious activity timestamps.
If you find such connections, log them out immediately.
5. Warn your contacts
If messages have already been sent in your name requesting money, link clicks, or personal data, you must warn your contacts as soon as possible.
Prioritize those whom the scammers have already contacted directly.
Inform them that you did not send the previous messages and instruct them not to follow any requests for transfers or link clicks.
Users who receive such messages should also exercise caution. If an acquaintance unexpectedly asks you to transfer money or follow a link, it is best not to respond immediately. Instead, contact them directly by phone to verify whether the request actually came from them.6. Check your computer
If you suspect that access was gained via WhatsApp Web, you must check the computer used to log in.
Particular attention should be paid to:
malware;remote access software;unknown browser extensions;active user sessions;suspicious processes;potential browser profile compromise.
It is recommended not to reinstall the system or clear logs before conducting a check, as this may destroy evidence of the incident.7. Check other accounts
If a computer or phone has been compromised, the problem may not be limited to WhatsApp. Attackers could potentially gain access to other services, especially if passwords or active sessions are saved on the device.
Check your:
email;banking apps;social media accounts;cloud services;corporate accounts;passwords saved in the browser.
It is recommended to change passwords only from a trusted device that has been scanned for malware.
How to avoid becoming a victim of "account hijacking"
The main rule to remember is: a WhatsApp QR code is not just an image, it is an authorization method..
This is why any request to scan a QR code should be treated with the same caution as a request for a password or an SMS confirmation code.1. Never scan QR codes if you are asked to do so:
to vote for an acquaintance, child, or colleague;to receive a gift, compensation, or cash payout;to join an unknown group or private chat;at the request of someone claiming to be a technical support employee;when following links in messages or emails;if you do not understand exactly which device is connecting to your account.
Before scanning a QR code, make sure you are on the official WhatsApp website and are indeed connecting your own computer or another device you own to your account. If you have even the slightest doubt, it is better to refuse the scan and verify the information through other means.2. Always end your session
If you have logged into WhatsApp Web from someone else's, a public, or a work computer, remember to log out when you are finished. Simply closing the browser tab may not be enough — the active session may persist.
To revoke access to your account, you must log out of WhatsApp Web, open the "Linked Devices" section on your phone, and ensure the session has actually ended.
What other data should not be shared with third partiesTo avoid losing access to your WhatsApp account, under no circumstances should you provide others with data used for login and transaction confirmation.
Such data includes:
WhatsApp registration SMS code — the code received during a login attempt or number re-registration;Two-step verification PIN — an additional password that protects the account;Device linking code — information required to connect a new device to WhatsApp;Recovery codes — backup codes that allow you to restore access to your account.
As previously reported, WhatsApp is testing a "Scam Alert" feature to help users identify potentially dangerous messages from unknown contacts. The tool will analyze conversations directly on the device and warn of possible signs of fraud without transmitting message content to servers, thus maintaining end-to-end encryption.
The feature is currently under development. WhatsApp has not disclosed a specific launch timeline, but it is expected to be released in a future update following beta testing.
