WhatsApp flaw could let anyone lock your account — what you need to know

whatsapp
(Image credit: Anadolu Agency / Getty Images)

WhatsApp users beware: There’s a hole in the app’s security that could let attackers suspend your WhatsApp account. All they need is your phone number.

The scary thing is that the method an attacker could use isn’t all that difficult. The only upside is that the attack doesn’t expose your account or any personal information. So the only reason they’d want to do it would be pure malice.

The first stage of the attack is for the attacker to install WhatsApp on a brand new device and use your number to activate the app. Since they don’t have access to your phone, they won’t be able to verify the number belongs to them and actually access your WhatsApp account.

The bad news here is that repeatedly sending out two-factor authentication codes, and failing to enter them correctly, will lead to your own login being locked for 12 hours.

The second stage is a little bit more difficult, but isn’t all that hard. Once the account is locked, the attacker can email WhatsApp support claiming to be you, and declare your phone has been either lost or stolen and the WhatsApp app on it needs to be deactivated. 

Because WhatsApp doesn’t ask for an email address when you sign up, this gets “verified” with whatever email the attacker messaged support with. Then your account is suspended by an automated process. Should the attacker repeat the process multiple times, it can lead to a semi-permanent lock on your entire account.

whatsapp security flaw

A visual example of what a locked WhatsApp account looks like (Image credit: Forbes)

Thankfully there are no reports of this attack actually being used out in the world. Instead it’s a proof of concept from security researchers Luis Márquez Carpintero and Ernesto Canales Pereña (via Forbes).

However the security hole does exist, and it isn’t particularly complicated. To make matters worse, Whatsapp has not confirmed whether it has any plans to fix the problem. That's an issue, considering your account can be deactivated anonymously, with no way of identifying which malicious actors are responsible.

If it happens, the only thing you can do is get in touch with WhatsApp support, and try to get hold of a human being.

Obviously the problem needs fixing, and we can only hope WhatsApp is actively working on a fix, as at the time of writing, this security hole is ripe for exploitation.

TOPICS
Tom Pritchard
UK Phones Editor

Tom is the Tom's Guide's UK Phones Editor, tackling the latest smartphone news and vocally expressing his opinions about upcoming features or changes. It's long way from his days as editor of Gizmodo UK, when pretty much everything was on the table. He’s usually found trying to squeeze another giant Lego set onto the shelf, draining very large cups of coffee, or complaining about how terrible his Smart TV is.

Read more
How to tell if you've been blocked on WhatsApp
The best WhatsApp alternatives in 2025
iPhone 15 Pro Max shown in hand
iMessage under attack from scammers sending phishing messages — don’t fall for it
Green skull on smartphone screen.
Hackers are spreading info-stealing malware and taking over accounts using fake wedding invitations — how to stay safe
Find My iPhone
Apple Find My hack turns any Bluetooth device into a secret AirTag — what we know
A hacker typing on a computer
FBI issues serious warning to iPhone and Android users — stop doing this ASAP
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Latest in Instant Messengers
How to delete TikTok
8 TikTok alternatives — where to go if the app gets banned
How to tell if you've been blocked on WhatsApp
New WhatsApp green screen bug is making the app unusable
The WhatsApp logo on a screen in front of a laptop
WhatsApp starts rolling out Events planning feature for group chants — here’s how it works
The WhatsApp logo on a screen in front of a laptop
WhatsApp looking to add AirDrop-esque feature to iPhones — what we know
The WhatsApp logo on a screen in front of a laptop
WhatsApp drops surprise design update — it's rounder and darker now
WhatsApp logo on iPhone
How to rejoin a group chat on WhatsApp
Latest in News
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Apple iPhone 16 & 16 Plus hands-on.
iPhone 17 just tipped for this long overdue Pro feature in new report
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how