WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
ID: 83504885-1d08-5f3a-bc71-ccf0a624286d
STIX ID: report--83504885-1d08-5f3a-bc71-ccf0a624286d
Feed Name: cybersecurityNews.com
GhostPairing is a social-engineering campaign that tricks WhatsApp users into approving an attacker-controlled companion device via the legitimate device-linking workflow, allowing persistent access to chats without credentials; attackers can read messages, impersonate victims, commit payment/business fraud, and target contacts. The report highlights recent cases, explains the attack flow, and recommends reviewing Linked Devices, enabling two-step verification, using device screen locks, verifying urgent requests via independent channels, and reporting suspicious sessions to WhatsApp.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
