Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
ProtectionAI-assisted

GhostPairing Attack Exposes WhatsApp Accounts to Full Takeover via Phone Numbers

Cybersecurity Overview of the GhostPairing Attack A recent campaign known as the "GhostPairing Attack" has been identified, allowing unauthorized access to WhatsApp accounts without the need for password theft or SIM swaps. This attack leverages WhatsApp's device pairing feature to…

GhostPairing Attack Exposes WhatsApp Accounts to Full Takeover via Phone Numbers

Cybersecurity

Overview of the GhostPairing Attack

A recent campaign known as the "GhostPairing Attack" has been identified, allowing unauthorized access to WhatsApp accounts without the need for password theft or SIM swaps. This attack leverages WhatsApp's device pairing feature to gain control over user accounts.

Technical Details

The attack initiates with a misleading message sent via WhatsApp. Users receive messages appearing to be from known contacts, containing a link that resembles a Facebook preview. Upon clicking, users are directed to a page mimicking Facebook's login interface, prompting them to verify their identity. This page acts as a control panel for the attacker, forwarding the user's information to WhatsApp's legitimate device linking system.

The attacker intercepts the authentication code generated by WhatsApp, which is then presented to the victim as part of the verification process. This results in the attacker's device being registered as a linked device to the victim's account, effectively allowing the attacker access to the account.

This attack leverages WhatsApp's device pairing feature to gain control over user accounts.
Mark Jensen · Thehackingpost

Infrastructure and Impact

Initially detected in Czechia, the attack uses a series of similar domains, such as photobox[.]life and postsphoto[.]life, indicating a scalable and adaptable threat. Once attackers link their device, they can access historical conversations, real-time messages, and media. They can also propagate the attack by sending lures to the victim's contacts.

This access remains until the victim manually removes the unauthorized devices from their account settings.

Advertisement

Recommendations for Protection

  • Regularly review linked devices in WhatsApp Settings → Linked Devices and remove any unrecognized sessions.
  • Be cautious of external requests to scan QR codes or input numeric codes.
  • Enable WhatsApp's Two-Step Verification for additional security.
  • Share awareness of the GhostPairing attack with contacts to reduce susceptibility.

It's important to note that similar attacks could target other platforms utilizing device pairing and authentication codes. Enhanced transparency and visibility of connected sessions are essential for preventing such account compromises.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories