Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number

A recent account takeover campaign known as the GhostPairing Attack targets WhatsApp users . This attack enables unauthorized access to messaging accounts through social engineering and WhatsApp's device linking feature, without exploiting technical…

A recent account takeover campaign known as the GhostPairing Attack targets WhatsApp users . This attack enables unauthorized access to messaging accounts through social engineering and WhatsApp's device linking feature, without exploiting technical vulnerabilities or stealing passwords.

The attack, initially detected in Czechia, has demonstrated scalability across various countries. Attackers utilize reusable kits, allowing operations in multiple languages.

The attack commences with victims receiving messages from known contacts, usually suggesting they have found a photo. The message includes a link that mimics a Facebook content viewer.

Upon clicking the link, users are directed to a fake Facebook-themed page that requests verification. This familiar interface fosters trust, prompting users to complete the process without verifying its legitimacy.

A recent account takeover campaign known as the GhostPairing Attack targets WhatsApp users .
Vanessa Ray · Thehackingpost

Researchers from Gen Digital have identified that the attack leverages WhatsApp's device pairing feature, which permits additional devices like web browsers and desktop applications to link to user accounts. Attackers deceive users into approving unauthorized device connections.

The attack's effectiveness stems from WhatsApp's phone number and numeric pairing code flow. When victims input their phone numbers on the fake page, the attacker's infrastructure intercepts the request and forwards it to WhatsApp's legitimate device linking endpoint.

WhatsApp generates a pairing code intended for the account owner, but the attacker's site displays this code, instructing victims to enter it into WhatsApp to complete the login verification. This process appears akin to standard two-factor authentication . Once entered, the victim unknowingly authorizes the attacker's browser as a linked device.

Advertisement

The attacker gains persistent access to all historical conversations, incoming messages, and shared sensitive information, remaining undetected by the account holder.

Regularly check linked devices in WhatsApp Settings and remove unknown sessions. Treat external requests to scan QR codes or enter pairing codes as suspicious. Enable Two-Step Verification for additional account security.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories