Criminals might use ‘GhostPairing’ to hijack your WhatsApp account – here’s how to stop them

  • A new WhatsApp scam called ‘GhostPairing’ has been discovered
  • This tricks users into giving a criminal access to their account
  • The attacker can then commit identity theft and scam others

There’s no shortage of ways that hackers and other criminals will attempt to gain access to online accounts, but now another has just been discovered, and this specifically relates to WhatsApp.

Gen Digital (via Bleeping Computer) has discovered a WhatsApp account takeover approach that it’s dubbing ‘GhostPairing’ – and when a criminal successfully carries this out, it gives them full access to your WhatsApp account, potentially without you even realizing. So it’s worth knowing what to look out for.

The attempt starts by the victim being sent a message from one of their contacts, generally saying something like “Hey, I just found your photo”, followed by a link. That link will appear with a Facebook-like preview, as you can see in the image below, but the link itself won’t actually take you to Facebook.

A GhostPairing WhatsApp scam message

A GhostPairing WhatsApp scam message (Image credit: Gen Digital)

Instead, it will take you to a page hosted by the criminals that’s designed to look like Facebook, and will ask you to log in to your account before you can see the content.

That process will involve providing your phone number and then either scanning a QR code or entering a numeric code into WhatsApp, but in either case, what it’s actually doing is using WhatsApp’s device linking function to link the criminal’s device to your WhatsApp account.

During this process your WhatsApp account should alert you that another device is attempting to access to your account, which will hopefully be enough of a red flag for most people, but inevitably some will miss this.

Those who do follow the steps on the fake Facebook page will give the criminal full access to their WhatsApp account from a linked device – that includes conversation histories, shared media, and of course the ability to message a user’s contacts.

A GhostPairing scam page imitating Facebook

A GhostPairing scam page imitating Facebook (Image credit: Gen Digital)

With this, the attacker can attempt to impersonate a user and commit fraud or extortion, and of course they can also then play the same trick on any of the user’s contacts.

If they’re careful enough, they could even remain unnoticed in the user’s account for a long time.

Remove and prevent access

There is a way to check whether this has happened to you – just open WhatsApp and head to Settings > Linked devices, from where you’ll be able to see a list of any devices linked to your account. If there are any that you don’t recognize, you can revoke their access.

As far as avoiding falling victim to GhostPairing in the first place, you should always be wary of being sent links, even from friends and family, and especially if they include just a vague message that seems designed to motivate you to click.

Look carefully at the URLs too, since in this case they’re pretending to be Facebook but the actual URLs used are very different. And finally, if you do click a link, think twice before entering any sensitive details (or scanning a QR code) on any page it sends you to. In this case, WhatsApp will actually tell you what the code you’re entering does, so make sure to carefully read anything involved in the process too.

And while this attack is specifically for WhatsApp, similar methods have been used for other messaging apps too, so be wary whatever you’re using.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Bungie’s Marathon shooter launches on March 5th

Bungie is putting an official date on Marathon today, its delayed extraction shooter. The slick-looking shooter from the makers of Halo and Destiny was...

A second US Sphere could come to Maryland

Sphere Entertainment, the company behind the eye-catching interactive venue in Las Vegas, has announced its "intent to develop" another Sphere in Maryland that will...

Musk claims Tesla will restart work on its Dojo supercomputer

Elon Musk posted on X that Tesla will be restarting work on Dojo3, the third generation of its in-house supercomputer project. The Dojo team...

Bungie’s Marathon arrives on March 5

Marathon, Bungie's long-awaited extraction shooter, will arrive on March 5, the studio announced today. Alongside a definitive release date, Bungie shared a new gameplay...

More malicious browser extensions uncovered – Chrome, Firefox, and Edge all affected

LayerX found 17 malicious browser extensions with 840,000+ downloads Extensions hijacked affiliate links, injected tracking, and enabled ad fraudAll extensions removed, but users must...

The world’s first Gemini-powered EV lands this week, but the Volvo EX60 needs to be better than Alexa+ on the BMW iX3

The Volvo EX60 will be the first to ship with Google Gemini built-inVolvo is promising "natural conversation" between man and machineLatest hardware from Nvidia...

MIO: Memories in Orbit is a pleasant stroll after the brutal ultramarathon of Hollow Knight: Silksong — and I’m here for it

When I booted up last year’s tough-as-nails and long-awaited Hollow Knight: Silksong, I knew I had to focus up and lock in – this...

Tour Down Under 2026 Free Streams: TV Channels, Schedule & Preview of UCI WorldTour Opener

Stream Tour Down Under 2026 completely *FREE* on 7Plus (AUS)Use NordVPN to watch from anywherePrologue: January 20 — Adelaide → Adelaide (3.6km)Start Time: 6pm...

How to watch The Secret of Me on Channel 4 — it’s *FREE*

Watch The Secret of Me for free on Channel 4 (UK restricted)Watch The Secret of Me for free on ABC iView (AUS restricted)Abroad? Watch...

ChatGPT now has ads, and before long Gemini might too – here’s what we can learn from Netflix, Prime Video, and other streaming services

The time has come, OpenAI has finally announced the thing we all knew was coming but didn't want to believe: ChatGPT is getting ads.The...