A seemingly harmless request for a vote is currently spreading via WhatsApp, but cybersecurity experts warn that it may actually be part of a phishing scheme designed to hijack users’ accounts.
Messages beginning with phrases such as, “Hello, could you please vote for XX?” are drawing attention among WhatsApp users. While the request may appear innocent, it can mark the start of a sophisticated scam.
The fraud tactic, sometimes referred to as “Ghost Pairing,” has been circulating for some time. Scammers typically claim that the vote is important for a friend, family member, or contestant and then thank recipients for their support before sending a link.
Fake Websites Designed to Build Trust
According to warnings from Germany’s Federal Office for Information Security (BSI) and the Austrian Institute for Applied Telecommunications (ÖIAT), users who click the link are often redirected to a fraudulent website.
These sites may be designed to resemble legitimate businesses, such as well-known fashion brands, model agencies, or other trusted organizations. Visitors are then asked to verify their identity by entering personal information, including their phone number.
Cybercriminals can use the submitted phone number to initiate WhatsApp’s device-linking function, allowing them to attempt to connect a new device to the victim’s account.
In some cases, the scammers also use QR codes that imitate WhatsApp Web pairing requests, making the scheme appear even more convincing.
How to Better Protect Your WhatsApp Account
Security experts recommend enabling additional layers of protection within WhatsApp.
1. Activate Two-Step Verification
Navigate to:
Settings → Account → Two-Step Verification
Users should create a secure PIN to add an extra level of protection when logging into their account. It is also strongly recommended to register a recovery email address. Without one, forgetting the verification PIN could result in losing access to the account.
2. Set Up Passkeys
Navigate to:
Settings → Account → Passkeys
Passkeys allow users to authenticate using biometric methods such as fingerprint or facial recognition, or through their device’s security code, providing stronger protection against unauthorized access.
What Happens if an Account Is Compromised?
If the linking process succeeds, attackers may gain access to the victim’s WhatsApp account. This can allow them to read messages, send messages posing as the account owner, or delete content.
One of the more deceptive aspects of the scam is that victims may not immediately realize their account has been compromised. Because the criminals are exploiting an existing WhatsApp feature, the app may continue to function normally.
How to Check for Unauthorized Access
Anyone who has received a suspicious message or clicked on an unknown link should review the devices connected to their WhatsApp account.
To do so, open WhatsApp Settings and select Linked Devices.
If an unfamiliar device appears on the list, it should be logged out immediately. Users should also avoid opening suspicious links or scanning unexpected QR codes. When receiving unusual requests from contacts, it is advisable to verify the message through another communication channel before responding.
Cybersecurity experts stress that a healthy degree of caution remains one of the most effective defenses against account takeover attempts.
- source: vienna.at/picture: pixabay.com
This post has already been read 65 times!
