logo

WhatsApp API flaw let researchers scrape 3.5 billion accounts

ID: d9118613-b5ba-5036-8d93-f02ac3557c72

STIX ID: report--d9118613-b5ba-5036-8d93-f02ac3557c72

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-22

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Researchers abused WhatsApp's unrate-limited contact-discovery and related APIs to enumerate 3.5 billion active accounts and collect profile photos, 'about' text, device information and public keys; the operation scanned up to 100 million numbers per hour from a single server and downloaded 77 million profile photos in a US test. The study — conducted by the University of Vienna and SBA Research and reported responsibly to WhatsApp, which subsequently implemented rate limiting — illustrates how unprotected APIs enable large-scale scraping and parallels prior massive leaks (Facebook, Twitter, Dell), highlighting prolonged privacy risks from aggregated phone-number datasets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.