A newly identified scam called GhostPairing lets attackers hijack WhatsApp accounts without stealing passwords or one-time login codes. The trick abuses WhatsApp’s legitimate device-linking flow through social engineering, so victims often miss the warning signs.
How the GhostPairing scam works
The attack starts with a short message that appears to come from a trusted contact. The message pushes a link that claims to show a photo, video, or document and often uses Facebook-style branding.
After the click, a fake page prompts the user to “verify” to view the content. The page then guides the victim to complete WhatsApp’s device-pairing steps, which links the attacker’s device to the victim’s account.
Why no login codes are required
GhostPairing does not need SIM swaps, intercepted SMS messages, or malware. The victim authorizes the link themselves after the scammer frames the pairing flow as a normal verification step.
WhatsApp treats the action like a standard linked-device setup, so the attacker can slip in without a classic “account takeover” prompt. The phone keeps working normally, which helps the scam stay hidden.
What attackers can access after linking
After linking, attackers can read chats, monitor new messages, and view shared media. They can also send messages as the victim, which helps them spread the same lure across contacts and group chats.
This access can expose private conversations and business discussions if the victim uses WhatsApp for work. Attackers often move fast to reach more targets before the victim notices unusual activity.
Where the scam has been observed
Researchers first flagged campaigns that targeted users in Europe, including reports tied to Czechia. The technique can travel quickly because it relies on deceptive messages and the built-in linking feature, not region-specific exploits.
What users should watch out for
Treat any unexpected “verify to view” page as a red flag, especially when it asks you to perform steps inside WhatsApp. Do not enter codes or follow pairing instructions that come from a link in a chat message.
Check WhatsApp’s linked devices list and remove anything you do not recognize. The sooner you unlink an unknown device, the sooner you cut off access.
What’s next
Security teams expect more scams that exploit trusted features instead of software flaws. Multi-device support keeps improving, so attackers will keep trying to trick users into approving access.
Users can reduce risk by staying skeptical of urgent links, reviewing linked devices regularly, and enabling WhatsApp’s two-step verification. These habits help limit damage even when scammers push convincing lures.



Discussion (0)
Be the first to comment.