WhatsApp Accounts Vulnerable: How Scammers Access Chats in Kazakhstan
Translated from English, summarized and contextualized by DistantNews.
At a glance
- Scammers can access WhatsApp accounts by tricking users into scanning QR codes on fake websites.
- This allows them to link their device to the victim's account, viewing and sending messages.
- Users can also be vulnerable if their computer has malicious software or extensions.
Kazakhstanis are being warned about a prevalent scam that allows criminals to read their WhatsApp messages. Experts from TSARKA explain that scammers exploit WhatsApp's feature allowing simultaneous use on multiple devices. The common tactic involves luring users to fake phishing websites that mimic the official WhatsApp Web login page. When a user scans the displayed QR code, believing they are connecting their own computer, they inadvertently authorize the scammer's device to access their account. This grants the attacker the ability to view chat history, receive, and send messages as if they were the account owner. Scammers use various pretexts, such as fake polls, contests, or requests to vote, to trick individuals into scanning QR codes or sharing verification codes received via WhatsApp. Even if users access the legitimate WhatsApp Web site, a risk remains if their computer is infected with malicious software, remote access tools, or harmful browser extensions. These can silently grant unauthorized parties access to the account, often without the owner noticing for an extended period. The Center for Analysis and Investigation of Cyberattacks highlights that such compromised devices can appear as legitimate 'Linked Devices' within the user's WhatsApp settings, masking the attacker's presence.
WhatsApp has a feature that allows you to use one account on several devices simultaneously: for example, on a smartphone, computer, tablet, or a second phone.
Originally published by Tengrinews in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.