Scammers abuse WhatsApp to steal SMS or in-app verification codes, hijack your chats, and then message your contacts as “you.” Variants include fake Meta/WhatsApp Support, “verify your number” scripts from buyers or relatives, and cloned chats that push gift cards, crypto, or Zelle. WhatsApp and Meta do not cold-call or text asking you to read a six-digit code so they can “keep your account active.”
This guide is WhatsApp-ATO–specific. Broader login theft: Phishing and account takeover. Phone-code cousins: Fake Google Voice verification scams. Landscape: Credit and debt scams.
How WhatsApp account takeover works
| What you see | What is actually happening |
|---|---|
| “WhatsApp Support” or “Meta Security” asks for the code that just arrived by SMS | Impersonation; that code registers your number on their device |
| A contact (or “your bank”) messages from a new WhatsApp number asking for money | Your friend’s account was taken over, or the scammer cloned their display name |
| A buyer, landlord, or dating match asks you to read them a WhatsApp verification code | They are registering WhatsApp (or another service) using your phone number |
| Urgent “your account will be deleted in 15 minutes” with a link to a login page | Credential phishing; lookalike domains, not whatsapp.com / the official app |
| Caller wants AnyDesk / TeamViewer “to restore WhatsApp” | Remote-access theft (Fake tech-support refund scams) |
WhatsApp is a legitimate Meta product. The scam is the code handoff, the fake support channel, or the payment demand—not the app itself.
Common WhatsApp ATO scripts
- Stolen registration code. You get an SMS: “Your WhatsApp code is 123-456.” An inbound caller, SMS, or chat claims to be support and asks you to read it. Reading it often moves your account to their phone within minutes.
- Hijacked contact asks for money. After takeover, scammers message your family: “Locked out of my bank—send gift cards / Zelle / Cash App.” Payment rails: Gift cards and prepaid debit risks and Zelle and P2P payment scams.
- Fake “business verification” or KYC portals. Lookalike sites ask for phone + code + ID selfies. Real businesses verify inside official apps, not gift-card PINs.
- Two-device / linked-device tricks. Scammer walks you through “linking a computer for backup” that is actually their session. Check Linked devices in WhatsApp Settings and log out unknowns.
- SIM-swap adjacent pressure. Attacker already controls SMS; they push you to approve a WhatsApp re-registration prompt you did not start.
Worked example
Priya gets a call: “Meta WhatsApp Security—fraud on your account. We just texted a code; read it so we can freeze the hacker.” She reads 482-913. Her phone loses WhatsApp; a backup chat opens on someone else’s device. Twenty minutes later her sister receives: “Priya here—send $400 in Apple cards, I’ll pay you back tonight.” Sister almost buys cards. Healthy version: sister calls Priya on a known number (not WhatsApp), confirms the ask is fake, and Priya recovers via the official re-verify flow after securing her SIM and email.
Hard rules that prevent most losses
- Never read a WhatsApp, SMS, authenticator, or email one-time code to an inbound caller, chat, or “buyer.”
- Meta and banks do not ask for gift-card PINs or remote-access apps to restore WhatsApp.
- Open WhatsApp only from the official app store build; ignore “whatsapp-support-secure.com” links.
- Turn on two-step verification (PIN) inside WhatsApp Settings → Account → Two-step verification.
- If a relative’s WhatsApp suddenly asks for money, verify on a phone call or in person before you send anything.
If you already shared a code or paid
- On a clean network, re-register WhatsApp with your number; set a new two-step PIN; review Linked devices and log out unknowns.
- Tell contacts on another channel that your WhatsApp was hijacked—do not rely on the compromised chat.
- If gift cards or P2P payments went out, contact the issuer/retailer and your bank fraud lines immediately; file ReportFraud.ftc.gov.
- Treat shared remote-access sessions as full compromise: Phishing and account takeover.
- Reject “recovery agents” who charge a second fee to undo the first loss.
Checklist
- Treat unsolicited WhatsApp / Meta “support” as hostile until you verify in-app.
- Never forward or read verification codes to strangers.
- Enable WhatsApp two-step verification and review linked devices.
- Confirm money requests from “family” on a known voice call.
- Refuse gift-card, crypto, or wire “restore” fees.
- Report attempts even when you walked away.
Educational only. Not legal, security, or fraud-recovery advice. Meta, carrier, and bank policies change; verify contacts through official apps and statements.