Urgent WhatsApp Security Warning: How This 6-Digit Code Scam Bypasses Passwords
Updated August 6: This article, originally published August 4, has been updated to include further advice from WhatsApp on how to keep your account safe from scammers using attack methods such as the “vote for my friends” campaign, along with additional details of the attack flow from Malwarebytes Labs.
Everyone knows that passwords need to be strong and unique, and they should be kept secret. But what if I were to tell you that a current WhatsApp attack campaign uses a combination of social engineering and a six-digit code to bypass the need for a password at all? Security experts at Malwarebytes Labs have confirmed that they are receiving ongoing reports of the attacks, which have been identified as “vote for my friend” scams, and have warned WhatsApp users to be alert. A successful compromise, the Malwarebytes report said, “allows the attacker to gain access to the victim’s WhatsApp account, enabling them to send messages, read chats, and harvest personal information.”
Pieter Arntz, a malware intelligence researcher at Malwarebytes Labs, has detailed how the attackers are bypassing the need for your password by using a legitimate WhatsApp device linking feature and basic phishing methodologies to persuade users to authorize a new linked session “that gives the attacker access to your WhatsApp account.”
The Malwarebytes Labs team has confirmed what the typical “vote for my friends” attack flow looks like, which might prove helpful in better understanding the threat.
- You tap the “vote” link.
- A page opens that appears to be related to WhatsApp.
- You’re prompted to complete a connection or verification step.
- That action links your WhatsApp account to a device controlled by the attacker.
The WhatsApp Voting Scam Dissected
WhatsApp has a handy feature called device linking, which, as the name suggests, allows you to link multiple devices to a single account. The process is straightforward and secure. You go to the Linked devices option in your WhatsApp app, verify your identity using your biometrics, scan a QR code using the device to be linked and confirm you want to make the link. However, it is also possible to link a device using a phone number and a one-time code. And this, as you might have guessed, is where the new scam warning comes into play.
Although the theme of the original scam message used in the WhatsApp attack will vary, it will always be related to an online voting request for a contest of some kind. Arntz said that Malwarebytes has seen variations including ballet competitions, best dog, and, of course, school prizes. “The wording is casual,” Arntz said, “sometimes urgent, and designed to get a quick click.” These messages leverage trust as they appear to come from a friend or relative, but the truth is that the person’s account has already been compromised.
If the recipient falls for the ruse, and it’s really easy to do so when a friend is asking for such seemingly harmless help and clicks on the voting link, they are taken to a page “that appears to be related to WhatsApp,” Arntz warned, “often involving the legitimate wa.me domain, where the real attack begins.” You’re prompted to complete a connection or verification step, which is where the six-digit code comes in. Entering this is, in fact, providing the agreement to link your WhatsApp account to the device that is asking you to do so. A device that is controlled by the attacker.
Once that connection is made, the threat actor can access your conversations until the device is unlinked. This means that they can impersonate you and forward more copies of the scam to your contacts, which is how the attack has been gaining traction. Of course, they can also employ other scams such as requesting money in “an emergency,” or simply harvest as much personal and sensitive information as possible about you.
Arntz also warned, however, that not all versions of the scam that have come to the attention of Malwarebytes have followed the same attack flow as described earlier in this article. Some, Arntz said, take a much less direct route. “Instead of sending victims to a fake voting page, the message or the landing page instructs victims to open WhatsApp, go to Connected Devices, and enter a code supplied by the scammer.”
Remember, this bypasses the need to know your password. It doesn’t require a password reset that would trigger a notification and your suspicion.
Mitigating The WhatsApp Voting Attack Campaign Threat
Malwarebytes recommends that WhatsApp users stay alert to the threat posed by such scammers and never, ever, share a WhatsApp verification code, “even if the request appears to come from someone you know.” Indeed, always verify any request to vote for someone with the sender directly, using a different method of communication than WhatsApp itself. Arntz added that users should enable WhatsApp two-step verification for extra protection as “it adds a PIN that can prevent attackers from taking over your account even if they obtain the SMS verification code.” WhatsApp advised that when you enable two-step verification, you are able to opt whether to use your phone number, password, or email address for additional authentication. It also recommended considering using a passkey that links your account to your device’s security system, fingerprint, face, or screen lock. “Passkey allows you to log in faster when two-step verification is enabled,” WhatsApp said.
Meta said that in order to help mitigate such device-linking scams, “WhatsApp will now alert you when behavioral signals suggest a linking request might be suspicious.” The new alerts will display the origin of the request and warn that it could be dangerous. A WhatsApp spokesperson said: “Users should never share their six-digit code with others, and we provide an overview of WhatsApp privacy settings .” It is also recommended that you report the sender of the message. Doing so will send WhatsApp five of the most recent messages they have sent, which will enable them to see the scam pattern in full, as it is unlikely you are the only recipient. You can do this using iOS by clicking the Safety Tools option after opening the message in question, and then the Report Contact option. Full details for reporting on any platform can be found here .
Although this particular scam campaign is not what I would call a particularly sophisticated cyber attack by any means, it does employ a combination of basic social engineering tricks, already compromised accounts and legitimate tooling. Many of these are, it must be said, rolled into the more advanced and targeted attacker playbook. Which brings me to the final defensive option that WhatsApp offers: Strict Account Settings . This feature enables a number of privacy and security controls, although WhatsApp said it should only be turned on “if you think you may be a target of a sophisticated cyber campaign.” The reason being that it is something of a nuclear approach that limits vulnerability by limiting functionality. If you really are someone at such risk, a journalist, political activist or a very high-profile user, then it might be worth considering. Before enabling it though, do bear in mind that it does the following: switches on 2FA, enables and locks security notifications, disables link previews, high volume unknown account messages are blocked, only contacts can see your profile photo, about details, and online/last seen information, and only known contacts or a pre-established, more-selective list of people can add you to groups. Sounds like heaven to me, but your security posture mileage may vary!
Loading article...