Quick fix (4 steps)
- Open WhatsApp on your phone, go to Settings, Linked devices, and log out every device you do not recognise.
- Do not click the voting link again and never type a code from a website into WhatsApp.
- Warn your contacts that messages from you may be scams (template here).
- Turn on two-step verification with a recovery email. Locked out? See register your number again.
How the "vote for my friend" WhatsApp scam works
The scam starts with a normal-looking message from someone you know, asking you to vote for a friend in an online contest. The link leads to a fake page that walks you through "verifying" or "connecting" your WhatsApp, and if you complete it, you authorize the attacker's device to be linked to your account. No password is stolen, because WhatsApp does not use one. The attacker simply becomes an extra device on your account.
Malwarebytes researcher Pieter Arntz described this pattern in a report published on August 3, 2026. According to that report, the message typically says something like "please vote for my friend" in a contest such as a ballet, dog show or school event. The link can look trustworthy because it may use the legitimate wa.me domain, and it then sends the victim to a fake page that imitates a WhatsApp-related connection or verification step. In some variants, the victim is told to open WhatsApp manually, go to the connected devices screen, and type in a code supplied by the scammer.
Once the link is made, Malwarebytes reports that the attacker can read messages, send messages as the victim, follow conversations in real time, forward the scam to the victim's contacts, ask those contacts for money or sensitive information, and harvest personal data. The compromise stays hidden because there is no password-reset email and no obvious alert.
This article is a practical response guide. It explains the mechanism in plain language, shows you how to check and cut off unknown devices, what to do if you typed a code, how to warn your contacts without panic, and how to harden the account so a second attempt fails. We have a separate guide on the older takeover method where criminals steal a six-digit registration code, and we link to it where the two overlap: how to recover a hacked WhatsApp account.
The scam in five steps
- A contact (often already compromised) sends: "Please vote for my friend, it only takes a second."
- You tap the link. The page looks like a contest or a WhatsApp verification screen.
- The page asks you to enter your phone number, scan a QR code, or type a pairing code into WhatsApp.
- You approve it. The attacker's browser or phone is now a linked device on your account.
- The attacker messages your contacts as you, and the cycle repeats with your friends.
Why this scam works even on careful people
It works because it borrows trust twice: first from a friend's name on the message, and then from the familiar look of WhatsApp's own device-linking flow. Most people have linked WhatsApp to a laptop or tablet at least once, so the steps feel routine. The scammer only has to make the routine feel like a requirement for casting a vote.
Three psychological levers do most of the work. The first is social proof: the sender is someone you know, so your guard is down. The second is low stakes: voting for a child, a pet or a charity photo contest feels harmless, and refusing feels rude. The third is urgency and curiosity: "it only takes a second" and "the deadline is tonight" discourage the pause that would let you notice something is off.
There is also a design reality behind the scam. Linking a device to a WhatsApp account is a legitimate, built-in feature. Attackers do not need to break encryption or find a software flaw. They need you to press the approve button yourself, which is why this kind of attack is classed as social engineering, not hacking in the movie sense. For a wider look at how modern lures are written, see our guide to AI-generated phishing and how to spot it, since fluent, personalised messages are now cheap to produce.
What the lure can look like
The wording changes between waves, but the shape rarely does. Common versions include a request to vote for a niece in a dance competition, a plea to help a friend win a local photo prize, a "school talent show" poll, or a charity fundraiser ranking. The Malwarebytes report lists ballet and dog contests and school events as examples. Expect the topic to follow the news and the season: back-to-school, holidays, sports finals.
- A short message with one link and no context. A real friend usually adds a name, a photo or a detail only they would know.
- A link that opens a page asking for your phone number. A normal poll never needs your WhatsApp number.
- A page that mentions WhatsApp, verification, "confirm you are human" or "connect to continue." Voting sites do not need to touch your WhatsApp account.
- Instructions to open WhatsApp settings and type a code. This is the strongest warning sign of all. Never type a code from a website into your linked devices screen.
Why this is not a password hack (and why that matters)
A password was never stolen, so changing passwords will not help. The attacker holds a legitimate session on your account that you approved, and the only fix is to revoke that session from your phone's linked devices list. This single idea explains why victims feel confused: nothing looks broken, no email arrived, and the account still opens normally.
WhatsApp identifies your account by your phone number and confirms it with a one-time code sent by SMS or call. When you link a companion device, your phone approves the new device, using either a QR code or a numeric pairing code. After approval, that device receives your chats and can send messages, according to how WhatsApp describes linked devices on its Help Center (we could not load the Help Center page during our verification pass, so check the current wording on WhatsApp's site).
This has practical consequences:
- Resetting your email password does nothing. The attacker never touched your email.
- Uninstalling and reinstalling WhatsApp may not clear the problem cleanly. Treat the linked devices list as the first thing to inspect, then verify again after any reinstall.
- Antivirus will not flag it. There is no malware on your phone in this scenario. The access lives on WhatsApp's side as an approved device.
- Two-step verification helps with registration-code theft, but it does not by itself stop you from approving a device. It protects the number from being re-registered elsewhere. Linked devices need a separate habit: checking the list.
That last point deserves emphasis. People hear "turn on two-step verification" as a universal cure. Malwarebytes recommends it, and so do we, but it solves a different part of the problem. We cover both layers in the sections below.
Signs your WhatsApp is linked to someone else's device
The clearest sign is an unfamiliar entry in the linked devices list. The softer signs are friends telling you that you sent them something strange, messages marked as read that you never opened, and chats that look changed. Because the takeover is quiet, most victims learn about it from other people.
- Friends reply to messages you do not remember sending. This is the most common first clue.
- You see sent messages in chats that you did not write. The attacker's device can send from your account, and the messages appear in your phone's history.
- Chats appear read or marked in ways you did not do. This is a hint, not proof, as it can have innocent causes.
- Your linked devices list shows a browser, a computer or a device name you do not recognise, or a session you never started. This is the definitive check.
- Contacts report requests for money, gift cards, votes, codes or "urgent help" coming from your number.
- You receive an unexpected WhatsApp verification code by SMS. That points to the separate registration-code scam, not to this one, but it deserves attention too.
One signal that people overlook is the lack of a signal. If you clicked a strange voting link in the last few days and filled in anything about WhatsApp, assume exposure and run the check in the next section. Checking takes under two minutes and costs nothing.
How to check Linked Devices and log out unknown sessions
Open WhatsApp on your phone, go to Settings, tap Linked devices, and look at every entry. Any device you do not recognise should be selected and logged out immediately. Malwarebytes recommends checking Settings, Linked devices regularly and logging out unrecognised sessions. Menu labels can differ slightly between iPhone and Android and between app versions, so read the screen rather than relying on exact wording.
Two-minute linked devices check
- I opened WhatsApp on my phone and went to Settings, then Linked devices.
- I counted the devices and matched each one to something I own (my laptop, my tablet, my work PC).
- I tapped each unknown device and chose to log out.
- I reopened the list to confirm that it is now empty or shows only my devices.
- I took a screenshot of the clean list for my own records.
- I changed nothing else until the list was clean.
On iPhone and on Android
- Open WhatsApp. Use the app on your phone, not a link, not a web page.
- Find the Settings area. On iPhone it is generally a tab at the bottom; on Android it is generally in the three-dot menu. Look for the entry named Linked devices.
- Read the list. Each entry usually shows a browser or device name and when it was last active. A browser you never used, an operating system you do not own, or a "last active" time during a day your laptop was closed are all red flags.
- Select an unfamiliar entry and log out. Repeat for every unknown one. When in doubt, log out everything: you can re-link your own laptop in thirty seconds.
- Check again after five minutes. If an unknown device returns, someone still has your phone number's access in another way, and you should go straight to the recovery sections of this guide.
Logging a device out removes its access to future messages. It does not undo what it already read or sent. That is why the later steps on warning contacts and tightening the account matter. If you want a deeper walk through of related takeover paths and the older code-theft variant, our guide on recovering a hacked WhatsApp account covers them in detail.
Do not skip the "my own devices" part
Do not log out only the strange ones and leave an old laptop that you gave away, sold or left at the office. Old sessions are the same risk as hostile ones. Treat every device you cannot physically find as unknown.
What to do if you already entered a pairing code or scanned a QR code
Act in this order: open Linked devices and log out every unknown session, warn your contacts, enable two-step verification, and then review the rest of your accounts. Speed matters most in the first hour because the attacker is already messaging people as you. The good news is that the damage window closes the moment the session is revoked.
- Stay calm and do not reply to the scam sender. Do not click the link again, do not "test" the page, and do not enter any more information.
- Revoke the sessions. Follow the Linked devices check above. If your phone still opens WhatsApp and shows the list, you have not been locked out, which is the easier situation.
- Tell your contacts. A short broadcast to family and close friends, plus a note in any group you administer, will stop the second wave. A template is in the next section.
- Turn on two-step verification and add a recovery email inside WhatsApp so the number cannot easily be re-registered by someone else.
- Review what the attacker could have seen. Think of banking details, one-time codes, photos of ID, addresses or passwords you may have typed in chats. Change anything that is sensitive and appears in your history.
- Check other apps you connected. If the page asked you to sign in with another service, change that password and enable multi-factor authentication there too. Our guide on how to set up two-factor authentication walks through common services.
- Report it. The reporting section below explains where in Canada and how to flag the message inside WhatsApp.
If you were also asked to type a numeric code that arrived by SMS, treat that as the other takeover method. A code sent by SMS from WhatsApp is the key to your number. Never share it, even with a friend. Never read it out on a call. If you did, move quickly to the "taken over" section, where we explain how to register again on your own phone.
Where a "lost the race" scenario usually leads
If the attacker was fast and you cannot open WhatsApp, or the app says your number is registered on another phone, it usually means the registration was moved, not that a device was linked. This is a different attack. The recovery is to register your number again using the verification code sent to you, which WhatsApp describes as the way to take the account back (we could not open the Help Center page during verification, so follow the current on-screen instructions). That sequence is covered step by step below.

Linked-device hijack versus registration-code theft
In a linked-device hijack you stay logged in on your own phone while someone else watches and speaks through your account. In registration-code theft you lose access, because the attacker registers your number on their phone. The fix and the warning signs differ, so identify which one you have before acting.
| Question | Linked-device hijack ("vote for my friend") | Registration-code theft |
|---|---|---|
| What did the victim hand over? | Approval of a device (pairing code, QR scan) | The six-digit SMS code |
| Does the victim stay logged in? | Yes, usually | No, often logged out |
| First sign | Friends say you messaged them; unknown entry in Linked devices | "Your number is registered on another phone"; unexpected SMS code |
| Main fix | Log out unknown devices, warn contacts | Register again, set a two-step PIN |
| Does two-step verification stop it? | Not by itself; you must still review devices | Yes, it is the main defence |
| Typical lure | "Vote for my friend," fake contest page | "I sent my code to you by mistake, can you send it back?" |
Some attackers combine both approaches. Do not assume one fix is enough: always check the linked devices list, always set a PIN, and always warn your contacts.
How to warn your contacts without causing panic
Send a short, calm message from your own phone telling people not to click the voting link, not to send codes, and to check their own Linked devices list. Keep it factual and ask them to pass it on. The goal is to stop the chain: each victim becomes a sender, and speed matters more than polish.
Use a broadcast or send individually to the people the attacker most likely reached: recent chats, family groups, and any group where you are an admin. If a group exists for a club, a class or a team, post once and pin the message. Avoid long explanations. People read the first two lines.
Copy and paste template
"Warning: my WhatsApp was used to send a message asking you to vote for a friend. Please do not click that link and do not enter any code or phone number on the page. I have removed the unknown device from my account. If you opened that link, go to WhatsApp, Settings, Linked devices, and log out anything you do not recognise. Please share this with your contacts."
If the message came from a friend's account and you are the receiver, do not just ignore it. Contact that friend by phone or in person, in a way the attacker cannot intercept, and tell them their account is likely being used. A friend who learns this early is a friend whose contacts are protected.
What not to do
- Do not reply to the scam message to ask whether it is real. If the account is compromised, the attacker answers you.
- Do not forward the scam link "for awareness" without breaking it, as someone will tap it.
- Do not pay to "recover" or "unlock" the account. Paid recovery services found through ads or DMs are a second scam layer.
- Do not announce it only on social media. The people at risk are in your WhatsApp contacts.
Turn on two-step verification and add a recovery email
Two-step verification adds a PIN that WhatsApp asks for when your number is registered again. Turn it on, pick a PIN that is not a birthday, and add a recovery email you can actually access, because that email is how you reset a forgotten PIN. Malwarebytes recommends enabling two-step verification as part of its guidance on this scam.
The setting is generally found in Settings, Account, Two-step verification, though labels may change between versions (we could not open the WhatsApp Help Center page when verifying, so confirm the current path on your screen). The idea is simple. When someone later tries to register your number on a new phone, WhatsApp requires the PIN in addition to the SMS code. A scammer who talks you into reading out the SMS code still cannot finish without the PIN.
- Create a PIN of six digits that you will remember but nobody else can guess. Avoid your birth year, your phone number, 123456 or repeated digits.
- Add a recovery email. Choose an address that has its own strong password and two-factor protection. If this email is hijacked, the PIN reset can be abused. See our guide on recovering a hacked email account if that address is already doubtful.
- Store the PIN in a password manager or in a sealed note at home. Do not store it in the notes app on the same phone if someone shares that phone.
- Expect the occasional PIN prompt. WhatsApp may ask for the PIN from time to time to help you remember it. That is normal. Never type your PIN into a website or give it to a contact.
What two-step does and does not cover
It covers: someone registering your number on another phone using the SMS code. It does not cover: you approving a linked device on a fake voting page, an unlocked phone in someone else's hands, or malware that reads your screen. That is why the linked devices check is a separate monthly habit, not a one-time task.
Other protections worth setting up this week
The most useful extra protections are a screen lock on your phone, a SIM PIN with your carrier, regular reviews of linked devices, and a rule that no website ever gets a WhatsApp code. Each takes minutes, and together they close the common paths into your account.
- Lock the phone itself. A strong passcode or biometric lock prevents someone with brief physical access from linking a device, which is another way these takeovers happen.
- Set a SIM PIN and ask your carrier about port-out protection. Ask your mobile provider whether it offers extra verification before moving your number. Policies differ between carriers; ask yours directly.
- Use an authenticator app or passkeys on the email account tied to WhatsApp. If you are curious about passwordless options, see our overview of passkeys explained.
- Review your privacy settings. Limit who can add you to groups and who can see your profile photo and "About" text. The fewer strangers who can view them, the less material scammers have to personalise lures.
- Keep WhatsApp and your phone's operating system updated. Updates fix real vulnerabilities, even though this specific scam does not depend on one.
- Set a family code word. A shared word that proves "this really is me" works for voice scams and for chat impersonation alike.
If you manage the phone of a parent or a grandparent, do the linked devices check together and explain the rule in one sentence: "WhatsApp will never ask you to vote, and no website needs a code from your phone." For a related safety net at home, our back-to-school tech safety checklist includes account-hardening steps for teens, who are common targets of contest lures.
Is it only WhatsApp, or is the whole phone compromised?
In the vote scam, the phone itself is usually not infected, because the attacker gained access through an approved device link, not through malware. If other accounts behave oddly, apps you do not recognise appear, or the battery and data usage jump, then check the phone as well. Do not assume the worst, but do not dismiss odd behaviour either.
Look for apps you did not install, accessibility or device-admin permissions granted to unfamiliar apps, and profile or configuration settings you did not add. Update the phone, run the built-in security scan if your platform has one, and review the apps that have access to SMS and notifications. Our guide on what to do if your phone is hacked provides a full checklist for that deeper situation.
Also think about what you typed on the fake page. If it asked for a phone number only, the main exposure is that number. If it asked for an email, a password, a card number or a "voting fee", then the page was phishing in the classic sense, and the other accounts need attention. A contest that charges a "small fee" to cast a vote is a payment trap. If you entered card details, call your card issuer, ask to block and replace the card, and review the statement for the next several weeks.
If you are locked out: register your number again
If WhatsApp no longer opens on your phone or says your number is registered elsewhere, install or open WhatsApp on your own phone, enter your number, and request a new verification code. A successful registration on your phone should end the other phone's access. WhatsApp's Help Center describes this as the main way to regain control, but we could not load that page during verification, so follow the on-screen steps and check the Help Center for your version.
- Keep your SIM active and in your phone. The code arrives by SMS or by a phone call, so you need working service. If your SIM was swapped, call your carrier first.
- Open WhatsApp and enter your full number. Request the six-digit code. Type it only into the WhatsApp app screen, never anywhere else.
- If the app asks for a two-step PIN you did not set, the attacker may have set one. WhatsApp's recovery flow includes a waiting period before a PIN can be bypassed in some cases; we have not verified the length of that wait for 2026, so check the Help Center and do not rely on a number from memory or from a forum.
- Once in, immediately open Linked devices and log out everything unknown.
- Set your own two-step PIN and recovery email right away.
- Message your contacts with the template from earlier.
When the code does not arrive or WhatsApp says "try again later"
Repeated attempts may trigger a temporary limit on code requests. Wait, try again later, and use the "call me" option if offered. Avoid clicking "forgot PIN" repeatedly, as attempts can add delays. If nothing works after a day, use the in-app support option to contact WhatsApp, describe the problem factually, and include your full number with country code. Be careful of look-alike "WhatsApp support" accounts found through search ads or social media: genuine help comes from inside the app and the official Help Center.
If you cannot regain access, tell your contacts by another channel (phone, email, social media) that the account is compromised. This is the one situation where public announcements are a legitimate fallback.
For SIM-swap suspicions (your phone suddenly has no service while others receive your messages), call your mobile provider from another phone straight away and ask them to lock your number and review recent changes.
WhatsApp Business accounts and small businesses
A business that runs customer service on WhatsApp should treat linked devices as a staff access list: one named owner reviews it weekly, former employees are removed the same day, and nobody approves a link they did not start. The same scam works on a business phone, but the stakes include customer data, quotes and payment details.
Many small companies share one number across several staff, which means many linked devices. That is legitimate, but it makes an extra unknown entry easy to miss. Set a rule: every entry in the list must be matched to a named person and device on a short internal sheet. If an entry cannot be matched, log it out first and ask questions after.
- Assign an owner. One person is responsible for the number, the PIN and the recovery email.
- Use a company-controlled recovery email, not a departing employee's personal address.
- Offboard in minutes. When someone leaves, remove their linked device and rotate the PIN if they knew it.
- Warn customers quickly. If the business number was used to message clients, send a notice by email or on your website, not only on WhatsApp.
- Separate personal and business phones where possible. One compromised personal chat should not expose the customer list.
In Canada, a business that holds personal information and discovers that unauthorised people accessed it may have breach-reporting duties under privacy law (PIPEDA federally, and Law 25 in Quebec). The rules depend on the facts and the risk of harm, so confirm with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or a lawyer instead of relying on a blog. For fraud aimed at your staff more broadly, our guides on spear phishing and protecting employees and executive impersonation fraud show how a hijacked chat is used for money requests.
Scam variations to expect
Expect the same trick with different bait: QR codes, fake support, fake job offers, family-emergency messages and fake security alerts. The common thread is that you are asked to approve something or read out a code. Learn the thread and you can recognise new versions.
| Variation | What you see | What the scammer wants | Safe response |
|---|---|---|---|
| Vote or contest link | "Please vote for my friend" and a link | A device link via number, code or QR | Ignore, call the sender, check Linked devices |
| QR code lure | A page or image showing a QR to "continue" | You scan it in the WhatsApp device linking screen | Never scan a QR from a website in WhatsApp's link screen |
| Fake support | "WhatsApp Security" says your account will be banned | Your SMS code or device approval | Real help comes from inside the app only |
| Code-by-mistake | "I sent you my code by accident, send it back" | Your own registration code | Never forward any code |
| Family emergency | Message from a "new number" claiming to be a child | Money transfer | Call the person on the known number |
| Job or investment offer | Cold message with a link and a chat invite | Fees, data, further access | Do not click; verify the company independently |
The QR variation deserves a note. Our article on QR code phishing (quishing) explains why a QR code is only an encoded link or instruction, and why scanning it inside a sensitive screen hands over authority. The rule is simple: in WhatsApp's device-linking screen, only scan a QR code displayed by a device that you personally started and are holding.
Text-message cousins of this scam also exist. A text claiming that your account will be suspended unless you "verify" falls under SMS phishing, which we explain in what smishing is. And if a caller claims to be from "WhatsApp" or from your phone's maker and asks you to install a remote tool, see tech support scam warning signs.
The Malwarebytes report mentions that attackers rely on content that feels harmless. In the same period, press coverage elsewhere (for example Malaysia's communications regulator discussing hacked and blocked WhatsApp accounts with Meta in late September 2026, which we could only see in a search snippet and did not read in full) suggests the problem is wider than one country. We treat that as context, not as a proven statistic.
Three realistic scenarios (illustrative)
The scenarios below are invented for illustration, not real cases. They show how the same scam plays out for a parent, a small business and a retiree, and which step would have changed the outcome. Amounts are examples to give a sense of scale.
Realistic scenario 1: The dance-recital vote
A parent in Laval receives "Please vote for Emma, she's in the finals" from another parent in the recital group chat. The link opens a page asking her to "connect WhatsApp to confirm you are human." She enters her number, gets a code on the page, and types it into her linked devices screen. Nothing seems to happen. Two days later, six relatives reply to a message she never sent, which asked them to vote too and mentioned an urgent loan of 400 dollars.
What fixed it: she opened Settings, Linked devices, found a browser session she did not recognise, and logged it out. She posted the warning template in the recital group and turned on two-step verification. Total cost: about 20 minutes and one awkward group message. What would have prevented it: knowing that a code from a website must never be typed into the linked devices screen.
Realistic scenario 2: The plumbing company's shared number
A small plumbing company with four employees uses a single WhatsApp Business number for quotes. A technician approves a link that was sent by a "supplier" in a contest invitation. The attacker watches customer chats for a week and then sends a message from the company number to three clients with a new "payment link" for pending invoices of about 1,800 dollars each. Two clients ask by phone whether it is real; one pays.
What fixed it: the owner reviewed the linked devices list, found two unknown entries, logged them out, reset the PIN and sent an email to all customers. The paid invoice had to be traced with the client's bank. Lessons: a named owner for the number, weekly device reviews, and a written rule that payment details are never changed by chat alone.
Realistic scenario 3: The grandparent who lost access
A retiree receives a message from a "granddaughter" with a link to vote in a school talent show, and a follow-up from a stranger who says she "sent a code by mistake" and asks him to read it back. He reads out the six digits. His WhatsApp then asks him to register again, and his contacts begin to receive requests for gift cards.
What fixed it: his granddaughter helped him register his number again on his phone, set a PIN and a recovery email, and log out the unknown device. They called relatives to explain. Because he had never used the PIN feature, the second attack path was open. Lesson: the SMS code is the key to the number, and it should never be shared.
What it costs in Canada: DIY versus paying a technician
Doing the recovery yourself costs nothing but time, usually 15 to 45 minutes. Paying for professional help makes sense when you are locked out, when the business is affected, or when you suspect the phone itself is compromised. The real cost of the scam is not the cleanup but the money and trust lost by your contacts.
| Option | Typical cost (CAD) | Time | Best when |
|---|---|---|---|
| Do it yourself with this guide | 0 $ | 15 to 45 min | You can still open WhatsApp and see Linked devices |
| Ask a family member to help | 0 $ | 30 to 60 min | You are not comfortable with phone settings |
| IT Cares Expert Consultation (remote) | 119.99 $ for 60 minutes | Up to 60 min | You are locked out, own a business number, or suspect other accounts were touched |
| Fraud losses if you ignore it | Varies widely | Weeks to resolve | Never worth the risk |
Do not pay anyone who contacts you first and promises to "unlock WhatsApp" or "recover your account" for a fee. Meta does not charge for account recovery, and offers found through ads or direct messages are a common second scam. If you do want help, call a business you chose yourself.
The indirect costs are worth planning for. If the attacker asked your contacts for money, tell them to contact their bank, and if a payment already left, ask the bank to attempt a recall quickly. Time matters more than anything else for payment recalls.
Your 10-point protection checklist
Print or screenshot this list and review it once a month. Every item takes less than a minute and together they close the paths used in this scam.
WhatsApp protection checklist
- I checked Settings, Linked devices and every entry is mine.
- I logged out old devices I no longer use.
- Two-step verification is on, with a PIN that is not a birthday.
- The recovery email is current, protected and mine.
- My phone has a screen lock and a SIM PIN.
- I never type a code from a website into WhatsApp.
- I never share my SMS verification code, even with a friend.
- I treat "vote for my friend" and contest links as suspicious until confirmed by voice.
- My family has a code word for emergencies.
- I know how to report a scam message and who to call in Canada.
How to protect parents, grandparents and teens
The most effective family protection is one clear rule and one shared habit: no website ever needs a code from WhatsApp, and the whole family checks Linked devices on the first of each month. Scams exploit shame as much as ignorance, so make it easy to say "I clicked something" without blame.
- Do the check together. Sit with a parent and open the linked devices screen. Seeing a real list makes the risk concrete.
- Agree that unusual requests get a voice call. If a friend or a "granddaughter" asks for votes, money or codes, call back on the known number.
- Teach the sentence. "WhatsApp will never ask me to vote, and no website needs my code."
- Limit group exposure. Set group invitations to contacts only, so a stranger cannot drop a link into a family chat.
- Keep screenshots. If something suspicious arrives, keep a screenshot before deleting; it helps with reports.
- Do not shame. A person who feels foolish will wait before telling you. Early reports limit the harm.
Teens are often targeted with contest, giveaway and "free skin" lures. The back-to-school guide linked earlier suggests a short family agreement for these situations. For older relatives, pair this guide with our article on recovering a hacked Facebook account, since the same contacts are frequently targeted on both platforms.
Reporting the scam in Canada
In Canada, report fraud and scams to the Canadian Anti-Fraud Centre (CAFC) through its website, antifraudcentre-centreantifraude.ca, and report the same incident to your local police if money or identity information was lost. Also report the message inside WhatsApp so the sending account can be reviewed. Reporting helps investigators see patterns even when your own loss is small.
We did not verify the CAFC telephone line during this research pass, so we do not list a number here; use the website, which carries the current contact options. Prepare your report before you file:
- Screenshots of the original message, the link (do not open it again), and the linked devices list before and after cleanup.
- Dates and times of when you clicked, when you approved the link and when you removed the device.
- Names and numbers of the contact whose account sent the message, and of the people who received messages from your account.
- Any payments or card details involved, with amounts, dates and recipients.
Inside WhatsApp, you can generally report a contact or message from the chat's menu, and block the sender. Do this after taking screenshots. If your contacts sent money because of messages from your hijacked account, encourage them to report as well; each victim's own report matters.
Other places to inform
- Your bank or card issuer if any payment or card detail was involved. Ask about blocking cards and recalling transfers.
- Your mobile provider if you suspect a SIM swap or number port.
- Credit bureaus (Equifax Canada and TransUnion Canada) if identity documents or financial details were shared. Ask each about fraud alerts.
- The Office of the Privacy Commissioner if the incident concerns a business holding customers' personal information.
Official resources
For the most reliable, current instructions, use WhatsApp's own Help Center for device linking, account recovery and two-step verification, and use Canadian government sites for reporting fraud. Menu names and waiting periods change between app versions, so confirm details there rather than in forum posts.
- WhatsApp Help Center: pages on linked devices, hacked or stolen accounts, and two-step verification (faq.whatsapp.com). We opened the Malwarebytes report but could not read the Help Center pages, so quote any exact steps from there.
- Malwarebytes report (August 3, 2026): the scam description and advice summarised in this guide.
- Canadian Anti-Fraud Centre: antifraudcentre-centreantifraude.ca for reporting and current scam alerts.
- Office of the Privacy Commissioner of Canada: priv.gc.ca for breach and privacy obligations.
More on account safety from IT Cares: what phishing is, what to do after a fake tech support scam, and the guide to recovering 2FA access if you lose a device while tightening security.
When to stop and call a professional
Call a professional if you are locked out of WhatsApp and the steps above do not restore it, if a business number or customer data is involved, if you entered passwords or card details on the fake page, or if other accounts are behaving oddly. Do not wait for losses to grow. Early help is cheaper than late help, and a calm second pair of eyes often finds the entry you missed.
IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. In a remote session, a technician can sit with you while you review linked devices, set up a PIN and recovery email, secure your email and other accounts, and check the phone for suspicious apps. You see everything we do, and we explain each step so you can repeat it. The Expert Consultation is a single 60 minute session at 119.99 $ CAD.
To talk to someone now, call 1 (888) 711-9428 or book a remote session. Never give a stranger your WhatsApp verification code, even someone who says they are from support: we will never ask for it.
Still stuck? Get a technician on it now
Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.
Frequently asked questions
Related guides
- Recover a hacked WhatsApp account
- How to set up two-factor authentication
- QR code phishing (quishing) explained
- What is smishing (SMS phishing)?
- Phone hacked: what to do
- Facebook account hacked: recovery guide
- AI-generated phishing and how to spot it
- Email account hacked: recovery
- Tech support scam warning signs
- Passkeys explained
Sources and official references
Last verified: October 1, 2026
