Beware of the GhostPairing WhatsApp scam! Hackers exploit device-linking to hijack accounts. Tips to detect and prevent this risky fraud.
WhatsApp users are the target of a brand-new, risky fraud that abuses the device-linking functionality of the service. Because it doesn’t entail collecting passwords, SIM cards, or verification codes, cybersecurity experts have identified this technique, known as GhostPairing, as extremely dishonest. Users are duped into granting access on their own instead. Once triggered, the scam is difficult to detect and spreads covertly through trusted individuals.
Experts caution that this approach offers significant dangers to users’ comprehension of popular messaging apps’ device-pairing functionalities.
An explanation of the GhostPairing WhatsApp Scam: How Accounts Are Hijacked
Gen Digital cybersecurity researchers claim that the scam begins with a seemingly innocuous message from a familiar contact. The purpose of messages like “Hey, I just found your photo!” is to pique interest. The message contains a link that shows on WhatsApp with a preview similar to Facebook, giving the impression that it is secure.
Users are directed to a phony webpage that mimics a Facebook photo viewer when they click the link. The page requests that users “verify” their identities before displaying the image. In this location, the trap is set. The page covertly starts the official device-linking procedure for WhatsApp.
Also read : Samsung One UI 8.5 Beta 2 Brings Back Single Take & Dual Rec for Camera Enthusiasts
After users provide their phone number, WhatsApp creates a numerical pairing code. The phony website then instructs visitors to input this code into WhatsApp, stating that it is a standard security measure. Without the victim’s knowledge, the attacker’s device is authorized after the code is entered.
Hackers now have complete access to the WhatsApp Web. They can send and receive messages in real time, read chats, and download images and videos. The attack is extremely difficult to identify since the victim’s phone continues to function normally.
WhatsApp Security Warning: The Difficulty of Identifying GhostPairing
Because GhostPairing doesn’t crack encryption or take advantage of software flaws, experts warn it’s particularly dangerous. Everything functions precisely as intended. The fraud solely depends on human trust and social engineering.
Researchers caution that although the campaign was initially observed in Czechia, it may spread throughout the world. Once an account has been hijacked, the fraud can quickly spread through trusted networks by the attackers sending the same phony link to the victim’s contacts and group chats.
Until users voluntarily disconnect them, linked devices remain connected. This implies that attackers can continue to have access without being discovered for extended periods of time.
Users should disable two-step verification, avoid entering pairing codes from websites, often check Settings > Linked Devices, delete unfamiliar sessions, and double-check strange messages—even from known contacts—to keep safe. The best defense against these trust-based schemes is still vigilance.