Explorer

EXPLAINED | WhatsApp Vulnerability Can Allow Hackers To De-Activate Your Account By Just Using Your Phone Number

Shockingly enough, this can be exploited even if you have enabled two-factor authentication (2FA) for your WhatsApp account.

New Delhi: A vulenrablity was found in the instant messaging app WhatsApp which can allow a cyber criminal to shut you out of your account. First discovered by Luis Márquez Carpintero and Ernesto Canales Pereña, a cyber criminal just need your phone number and a little over 12 hours to deactivate your account and keep you from re-activating it. 

Shockingly enough, this can be exploited even if you have enabled two-factor authentication (2FA) for your WhatsApp account.

ALSO READ: OnePlus 9: Just Weeks After Launch OxygenOS Gets Updates; Fixes Bugs

First reported by Forbes, a hacker can use their own device to attempt to log in to the your WhatsApp account. If the two-factor authentication (2FA) for your account, WhatsApp would send you a six-digit code via call/SMS. The hacker will the purposefully will guess the code and after failed attempts WhatsApp will ask to try after 12 hours. In the meanwhile, the cyber criminal can send an email WhatsApp support saying something like the phone was stolen and request and ask to suspend the account for which WhatsApp will request for your mobile phone which the hacker can give.  

WhatsApp doesn't verify the email, from which the request is sent and doesn't follow up with questions to confirm your ownership of the phone number.

As of now, there is no way for a person to keep themselves from falling prey to cybercriminals. 

According to Gadgets360, a WhatsApp spokesperson said, “Providing an email address with your two-step verification helps our customer service team assist people should they ever encounter this unlikely problem. The circumstances identified by this researcher would violate our terms of service and we encourage anyone who needs help to email our support team so we can investigate."

Even if the victim successfully re-registers and recovers their WhatsApp account, just one email from the cybercriminal could get them back to square one and the countdown will show count down "-1 seconds" instead of 12 hours.

Read more
Sponsored Links by Taboola

Top Headlines

'Desh Me Do Namoone...': Yogi Adityanath Attacks Oppn, Akhilesh Hits Back With Delhi-Lucknow 'Rift' Jibe
'Desh Me Do Namoone...': Yogi Adityanath Attacks Oppn, Akhilesh Hits Back With 'Rift' Jibe
Bangladesh Leader Shot In Broad Daylight In Khulna; Police Deployed As Tensions Simmer
Bangladesh Leader Shot In Broad Daylight In Khulna; Police Deployed As Tensions Simmer
Air India Delhi-Mumbai Flight Returns After Technical Issue, Engine Shutdown Suspected
Air India Delhi-Mumbai Flight Returns After Technical Issue, Engine Shutdown Suspected
India-New Zealand FTA Signed: 95% Tariff-Free Trade And Better Student Visas
India-New Zealand Trade Deal Explained: 95% Tariff-Free Access And Easier Student Visas

Videos

West Bengal Politics: Humayun Kabir Launches ‘Janta Unnayan Party’ in Murshidabad, Targets TMC and BJP Ahead of 2026 Polls
Delhi NCR: Battles Toxic Air as AQI Stays Above 400 Amid Cold Wave and Dense Fog
Aviation Breaking: Air India Flight AI-887 Returns to Delhi After Engine Oil Pressure Drops to Zero
SP Stages Protest Outside UP Assembly Over Codeine Syrup Case Ahead of Key Legislative Agenda
Breaking: 18-Year-Old Girl Pushed from Moving Local Train in Navi Mumbai, Accused Arrested

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget