back to top
18.9 C
Johannesburg
spot_imgspot_img
More
    spot_img

    Date:

    Share:

    Kaspersky warns of WhatsApp account hijacking scam involving fake voting

    Kaspersky has uncovered a new phishing campaign targeting WhatsApp users through a fraudulent voting scheme. This attack lures victims with a voting page allegedly featuring young athletes, but other voting topics are being exploited as well. The method can be easily tuned for different scenarios, and the ultimate goal of the attackers is to hijack WhatsApp accounts.

    The scam begins with users being directed to a seemingly legitimate webpage claiming to host a voting contest. For instance, the page can feature photos of athletes, each accompanied by a “Vote” button and real-time counters displaying alleged vote totals and the number of users who have participated. These elements create a false sense of authenticity, encouraging user engagement. The page also claims that anyone can participate in the contest after “authorisation”, with winners getting prizes from “sponsors”.

    Upon clicking either “Vote” or “Authorise” buttons, users are redirected to a fraudulent webpage that encourages users to “quickly and simply” authorise via WhatsApp. Users are prompted to enter their WhatsApp-associated mobile phone number. Attackers then use the WhatsApp feature to login into the messenger’s web interface via a one-time code: they input the victim’s phone number to login to WhatsApp Web and the system gives out a 6-digit code which the scam website then mirrors. When the user inputs this code in the app on their smartphone, the web session that the attackers initiated goes live, allowing them to spy on the victim, write messages and eventually take over the account.

    “We see that online contests that include voting are very popular now, and this is used by attackers who exploit trust in this seemingly harmless activity. By combining social engineering with convincing fake interfaces, attackers are weaponising user engagement to steal sensitive data. Awareness and vigilance are critical to staying safe,” comments Tatyana Shcherbakova, Web Content Analyst at Kaspersky.

    To be protected from such hijacking scams, Kaspersky recommends:

    • Enable two-step verification: Activate WhatsApp’s two-step verification feature to add an extra layer of security, requiring a PIN for account access.
    • Verify website authenticity: Avoid entering personal information on unfamiliar websites, especially those reached via unsolicited links. Always check the URL for legitimacy.
    • Never share verification codes: WhatsApp will never ask for your verification code. Do not share it with anyone, or accept it from anyone, even if prompted by a seemingly trusted source.
    • Use trusted and proven security software to detect and block malicious websites and links.
    spot_img
    spot_img

    ━ More like this

    Kaspersky detected a fivefold surge in QR code phishing attacks in the second half of 2025

    Kaspersky has reported a spike in phishing emails containing malicious QR codes. Detections for these jumped from 46,969 in August 2025 to 249,723 in...

    Corr-Serve strengthens South Africa’s cybersecurity market through expanded Seceon partnership

    Corr-Serve, a South African value-added distributor of cybersecurity solutions, has strengthened its long-standing partnership with Seceon, a global provider of advanced cybersecurity technology, expanding local...

    Kaspersky detected a scam exploiting OpenAI’s teamwork features

    Kaspersky has detected a scam tactic leveraging the OpenAI platform. Attackers are abusing OpenAI's organisation creation and team invitation features to send spam emails...

    Kaspersky issues warning about crypto phishing following BlockFi bankruptcy

    Kaspersky has detected a wave of phishing attacks preying on former customers of the bankrupt crypto lending platform BlockFi. These scams leverage the ongoing...

    AI-driven shopping and privacy: What the retail and e-commerce sector should expect in 2026

    In 2025, the retail and e-commerce sector continued to face intense pressure from cybercriminals. According to Kaspersky data, 14,41%* of users in the global retail sector...
    spot_img