WhatsApp "Vote for My Friend" Scam: How Linked Devices Hijack Your Account and How to Take It Back

Reviewed by IT Cares technicians · Updated October 1, 2026

Smartphone with a padlock icon linked by a light beam to a second unknown laptop, illustrating a WhatsApp linked devices hijack
The vote for my friend scam does not steal a password. It gets you to approve the attacker's device.

Quick fix (4 steps)

  1. Open WhatsApp on your phone, go to Settings, Linked devices, and log out every device you do not recognise.
  2. Do not click the voting link again and never type a code from a website into WhatsApp.
  3. Warn your contacts that messages from you may be scams (template here).
  4. Turn on two-step verification with a recovery email. Locked out? See register your number again.

How the "vote for my friend" WhatsApp scam works

The scam starts with a normal-looking message from someone you know, asking you to vote for a friend in an online contest. The link leads to a fake page that walks you through "verifying" or "connecting" your WhatsApp, and if you complete it, you authorize the attacker's device to be linked to your account. No password is stolen, because WhatsApp does not use one. The attacker simply becomes an extra device on your account.

Malwarebytes researcher Pieter Arntz described this pattern in a report published on August 3, 2026. According to that report, the message typically says something like "please vote for my friend" in a contest such as a ballet, dog show or school event. The link can look trustworthy because it may use the legitimate wa.me domain, and it then sends the victim to a fake page that imitates a WhatsApp-related connection or verification step. In some variants, the victim is told to open WhatsApp manually, go to the connected devices screen, and type in a code supplied by the scammer.

Once the link is made, Malwarebytes reports that the attacker can read messages, send messages as the victim, follow conversations in real time, forward the scam to the victim's contacts, ask those contacts for money or sensitive information, and harvest personal data. The compromise stays hidden because there is no password-reset email and no obvious alert.

This article is a practical response guide. It explains the mechanism in plain language, shows you how to check and cut off unknown devices, what to do if you typed a code, how to warn your contacts without panic, and how to harden the account so a second attempt fails. We have a separate guide on the older takeover method where criminals steal a six-digit registration code, and we link to it where the two overlap: how to recover a hacked WhatsApp account.

The scam in five steps

  1. A contact (often already compromised) sends: "Please vote for my friend, it only takes a second."
  2. You tap the link. The page looks like a contest or a WhatsApp verification screen.
  3. The page asks you to enter your phone number, scan a QR code, or type a pairing code into WhatsApp.
  4. You approve it. The attacker's browser or phone is now a linked device on your account.
  5. The attacker messages your contacts as you, and the cycle repeats with your friends.

Why this scam works even on careful people

It works because it borrows trust twice: first from a friend's name on the message, and then from the familiar look of WhatsApp's own device-linking flow. Most people have linked WhatsApp to a laptop or tablet at least once, so the steps feel routine. The scammer only has to make the routine feel like a requirement for casting a vote.

Three psychological levers do most of the work. The first is social proof: the sender is someone you know, so your guard is down. The second is low stakes: voting for a child, a pet or a charity photo contest feels harmless, and refusing feels rude. The third is urgency and curiosity: "it only takes a second" and "the deadline is tonight" discourage the pause that would let you notice something is off.

There is also a design reality behind the scam. Linking a device to a WhatsApp account is a legitimate, built-in feature. Attackers do not need to break encryption or find a software flaw. They need you to press the approve button yourself, which is why this kind of attack is classed as social engineering, not hacking in the movie sense. For a wider look at how modern lures are written, see our guide to AI-generated phishing and how to spot it, since fluent, personalised messages are now cheap to produce.

What the lure can look like

The wording changes between waves, but the shape rarely does. Common versions include a request to vote for a niece in a dance competition, a plea to help a friend win a local photo prize, a "school talent show" poll, or a charity fundraiser ranking. The Malwarebytes report lists ballet and dog contests and school events as examples. Expect the topic to follow the news and the season: back-to-school, holidays, sports finals.

Why this is not a password hack (and why that matters)

A password was never stolen, so changing passwords will not help. The attacker holds a legitimate session on your account that you approved, and the only fix is to revoke that session from your phone's linked devices list. This single idea explains why victims feel confused: nothing looks broken, no email arrived, and the account still opens normally.

WhatsApp identifies your account by your phone number and confirms it with a one-time code sent by SMS or call. When you link a companion device, your phone approves the new device, using either a QR code or a numeric pairing code. After approval, that device receives your chats and can send messages, according to how WhatsApp describes linked devices on its Help Center (we could not load the Help Center page during our verification pass, so check the current wording on WhatsApp's site).

This has practical consequences:

That last point deserves emphasis. People hear "turn on two-step verification" as a universal cure. Malwarebytes recommends it, and so do we, but it solves a different part of the problem. We cover both layers in the sections below.

Signs your WhatsApp is linked to someone else's device

The clearest sign is an unfamiliar entry in the linked devices list. The softer signs are friends telling you that you sent them something strange, messages marked as read that you never opened, and chats that look changed. Because the takeover is quiet, most victims learn about it from other people.

One signal that people overlook is the lack of a signal. If you clicked a strange voting link in the last few days and filled in anything about WhatsApp, assume exposure and run the check in the next section. Checking takes under two minutes and costs nothing.

How to check Linked Devices and log out unknown sessions

Open WhatsApp on your phone, go to Settings, tap Linked devices, and look at every entry. Any device you do not recognise should be selected and logged out immediately. Malwarebytes recommends checking Settings, Linked devices regularly and logging out unrecognised sessions. Menu labels can differ slightly between iPhone and Android and between app versions, so read the screen rather than relying on exact wording.

Two-minute linked devices check

  • I opened WhatsApp on my phone and went to Settings, then Linked devices.
  • I counted the devices and matched each one to something I own (my laptop, my tablet, my work PC).
  • I tapped each unknown device and chose to log out.
  • I reopened the list to confirm that it is now empty or shows only my devices.
  • I took a screenshot of the clean list for my own records.
  • I changed nothing else until the list was clean.

On iPhone and on Android

  1. Open WhatsApp. Use the app on your phone, not a link, not a web page.
  2. Find the Settings area. On iPhone it is generally a tab at the bottom; on Android it is generally in the three-dot menu. Look for the entry named Linked devices.
  3. Read the list. Each entry usually shows a browser or device name and when it was last active. A browser you never used, an operating system you do not own, or a "last active" time during a day your laptop was closed are all red flags.
  4. Select an unfamiliar entry and log out. Repeat for every unknown one. When in doubt, log out everything: you can re-link your own laptop in thirty seconds.
  5. Check again after five minutes. If an unknown device returns, someone still has your phone number's access in another way, and you should go straight to the recovery sections of this guide.

Logging a device out removes its access to future messages. It does not undo what it already read or sent. That is why the later steps on warning contacts and tightening the account matter. If you want a deeper walk through of related takeover paths and the older code-theft variant, our guide on recovering a hacked WhatsApp account covers them in detail.

Do not skip the "my own devices" part

Do not log out only the strange ones and leave an old laptop that you gave away, sold or left at the office. Old sessions are the same risk as hostile ones. Treat every device you cannot physically find as unknown.

What to do if you already entered a pairing code or scanned a QR code

Act in this order: open Linked devices and log out every unknown session, warn your contacts, enable two-step verification, and then review the rest of your accounts. Speed matters most in the first hour because the attacker is already messaging people as you. The good news is that the damage window closes the moment the session is revoked.

  1. Stay calm and do not reply to the scam sender. Do not click the link again, do not "test" the page, and do not enter any more information.
  2. Revoke the sessions. Follow the Linked devices check above. If your phone still opens WhatsApp and shows the list, you have not been locked out, which is the easier situation.
  3. Tell your contacts. A short broadcast to family and close friends, plus a note in any group you administer, will stop the second wave. A template is in the next section.
  4. Turn on two-step verification and add a recovery email inside WhatsApp so the number cannot easily be re-registered by someone else.
  5. Review what the attacker could have seen. Think of banking details, one-time codes, photos of ID, addresses or passwords you may have typed in chats. Change anything that is sensitive and appears in your history.
  6. Check other apps you connected. If the page asked you to sign in with another service, change that password and enable multi-factor authentication there too. Our guide on how to set up two-factor authentication walks through common services.
  7. Report it. The reporting section below explains where in Canada and how to flag the message inside WhatsApp.

If you were also asked to type a numeric code that arrived by SMS, treat that as the other takeover method. A code sent by SMS from WhatsApp is the key to your number. Never share it, even with a friend. Never read it out on a call. If you did, move quickly to the "taken over" section, where we explain how to register again on your own phone.

Where a "lost the race" scenario usually leads

If the attacker was fast and you cannot open WhatsApp, or the app says your number is registered on another phone, it usually means the registration was moved, not that a device was linked. This is a different attack. The recovery is to register your number again using the verification code sent to you, which WhatsApp describes as the way to take the account back (we could not open the Help Center page during verification, so follow the current on-screen instructions). That sequence is covered step by step below.

Illustration of a phone connected by a dotted line to unknown devices with a warning shield and magnifying glass

Linked-device hijack versus registration-code theft

In a linked-device hijack you stay logged in on your own phone while someone else watches and speaks through your account. In registration-code theft you lose access, because the attacker registers your number on their phone. The fix and the warning signs differ, so identify which one you have before acting.

QuestionLinked-device hijack ("vote for my friend")Registration-code theft
What did the victim hand over?Approval of a device (pairing code, QR scan)The six-digit SMS code
Does the victim stay logged in?Yes, usuallyNo, often logged out
First signFriends say you messaged them; unknown entry in Linked devices"Your number is registered on another phone"; unexpected SMS code
Main fixLog out unknown devices, warn contactsRegister again, set a two-step PIN
Does two-step verification stop it?Not by itself; you must still review devicesYes, it is the main defence
Typical lure"Vote for my friend," fake contest page"I sent my code to you by mistake, can you send it back?"

Some attackers combine both approaches. Do not assume one fix is enough: always check the linked devices list, always set a PIN, and always warn your contacts.

How to warn your contacts without causing panic

Send a short, calm message from your own phone telling people not to click the voting link, not to send codes, and to check their own Linked devices list. Keep it factual and ask them to pass it on. The goal is to stop the chain: each victim becomes a sender, and speed matters more than polish.

Use a broadcast or send individually to the people the attacker most likely reached: recent chats, family groups, and any group where you are an admin. If a group exists for a club, a class or a team, post once and pin the message. Avoid long explanations. People read the first two lines.

Copy and paste template

"Warning: my WhatsApp was used to send a message asking you to vote for a friend. Please do not click that link and do not enter any code or phone number on the page. I have removed the unknown device from my account. If you opened that link, go to WhatsApp, Settings, Linked devices, and log out anything you do not recognise. Please share this with your contacts."

If the message came from a friend's account and you are the receiver, do not just ignore it. Contact that friend by phone or in person, in a way the attacker cannot intercept, and tell them their account is likely being used. A friend who learns this early is a friend whose contacts are protected.

What not to do

Turn on two-step verification and add a recovery email

Two-step verification adds a PIN that WhatsApp asks for when your number is registered again. Turn it on, pick a PIN that is not a birthday, and add a recovery email you can actually access, because that email is how you reset a forgotten PIN. Malwarebytes recommends enabling two-step verification as part of its guidance on this scam.

The setting is generally found in Settings, Account, Two-step verification, though labels may change between versions (we could not open the WhatsApp Help Center page when verifying, so confirm the current path on your screen). The idea is simple. When someone later tries to register your number on a new phone, WhatsApp requires the PIN in addition to the SMS code. A scammer who talks you into reading out the SMS code still cannot finish without the PIN.

  1. Create a PIN of six digits that you will remember but nobody else can guess. Avoid your birth year, your phone number, 123456 or repeated digits.
  2. Add a recovery email. Choose an address that has its own strong password and two-factor protection. If this email is hijacked, the PIN reset can be abused. See our guide on recovering a hacked email account if that address is already doubtful.
  3. Store the PIN in a password manager or in a sealed note at home. Do not store it in the notes app on the same phone if someone shares that phone.
  4. Expect the occasional PIN prompt. WhatsApp may ask for the PIN from time to time to help you remember it. That is normal. Never type your PIN into a website or give it to a contact.

What two-step does and does not cover

It covers: someone registering your number on another phone using the SMS code. It does not cover: you approving a linked device on a fake voting page, an unlocked phone in someone else's hands, or malware that reads your screen. That is why the linked devices check is a separate monthly habit, not a one-time task.

Other protections worth setting up this week

The most useful extra protections are a screen lock on your phone, a SIM PIN with your carrier, regular reviews of linked devices, and a rule that no website ever gets a WhatsApp code. Each takes minutes, and together they close the common paths into your account.

If you manage the phone of a parent or a grandparent, do the linked devices check together and explain the rule in one sentence: "WhatsApp will never ask you to vote, and no website needs a code from your phone." For a related safety net at home, our back-to-school tech safety checklist includes account-hardening steps for teens, who are common targets of contest lures.

Is it only WhatsApp, or is the whole phone compromised?

In the vote scam, the phone itself is usually not infected, because the attacker gained access through an approved device link, not through malware. If other accounts behave oddly, apps you do not recognise appear, or the battery and data usage jump, then check the phone as well. Do not assume the worst, but do not dismiss odd behaviour either.

Look for apps you did not install, accessibility or device-admin permissions granted to unfamiliar apps, and profile or configuration settings you did not add. Update the phone, run the built-in security scan if your platform has one, and review the apps that have access to SMS and notifications. Our guide on what to do if your phone is hacked provides a full checklist for that deeper situation.

Also think about what you typed on the fake page. If it asked for a phone number only, the main exposure is that number. If it asked for an email, a password, a card number or a "voting fee", then the page was phishing in the classic sense, and the other accounts need attention. A contest that charges a "small fee" to cast a vote is a payment trap. If you entered card details, call your card issuer, ask to block and replace the card, and review the statement for the next several weeks.

If you are locked out: register your number again

If WhatsApp no longer opens on your phone or says your number is registered elsewhere, install or open WhatsApp on your own phone, enter your number, and request a new verification code. A successful registration on your phone should end the other phone's access. WhatsApp's Help Center describes this as the main way to regain control, but we could not load that page during verification, so follow the on-screen steps and check the Help Center for your version.

  1. Keep your SIM active and in your phone. The code arrives by SMS or by a phone call, so you need working service. If your SIM was swapped, call your carrier first.
  2. Open WhatsApp and enter your full number. Request the six-digit code. Type it only into the WhatsApp app screen, never anywhere else.
  3. If the app asks for a two-step PIN you did not set, the attacker may have set one. WhatsApp's recovery flow includes a waiting period before a PIN can be bypassed in some cases; we have not verified the length of that wait for 2026, so check the Help Center and do not rely on a number from memory or from a forum.
  4. Once in, immediately open Linked devices and log out everything unknown.
  5. Set your own two-step PIN and recovery email right away.
  6. Message your contacts with the template from earlier.

When the code does not arrive or WhatsApp says "try again later"

Repeated attempts may trigger a temporary limit on code requests. Wait, try again later, and use the "call me" option if offered. Avoid clicking "forgot PIN" repeatedly, as attempts can add delays. If nothing works after a day, use the in-app support option to contact WhatsApp, describe the problem factually, and include your full number with country code. Be careful of look-alike "WhatsApp support" accounts found through search ads or social media: genuine help comes from inside the app and the official Help Center.

If you cannot regain access, tell your contacts by another channel (phone, email, social media) that the account is compromised. This is the one situation where public announcements are a legitimate fallback.

For SIM-swap suspicions (your phone suddenly has no service while others receive your messages), call your mobile provider from another phone straight away and ask them to lock your number and review recent changes.

WhatsApp Business accounts and small businesses

A business that runs customer service on WhatsApp should treat linked devices as a staff access list: one named owner reviews it weekly, former employees are removed the same day, and nobody approves a link they did not start. The same scam works on a business phone, but the stakes include customer data, quotes and payment details.

Many small companies share one number across several staff, which means many linked devices. That is legitimate, but it makes an extra unknown entry easy to miss. Set a rule: every entry in the list must be matched to a named person and device on a short internal sheet. If an entry cannot be matched, log it out first and ask questions after.

In Canada, a business that holds personal information and discovers that unauthorised people accessed it may have breach-reporting duties under privacy law (PIPEDA federally, and Law 25 in Quebec). The rules depend on the facts and the risk of harm, so confirm with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or a lawyer instead of relying on a blog. For fraud aimed at your staff more broadly, our guides on spear phishing and protecting employees and executive impersonation fraud show how a hijacked chat is used for money requests.

Scam variations to expect

Expect the same trick with different bait: QR codes, fake support, fake job offers, family-emergency messages and fake security alerts. The common thread is that you are asked to approve something or read out a code. Learn the thread and you can recognise new versions.

VariationWhat you seeWhat the scammer wantsSafe response
Vote or contest link"Please vote for my friend" and a linkA device link via number, code or QRIgnore, call the sender, check Linked devices
QR code lureA page or image showing a QR to "continue"You scan it in the WhatsApp device linking screenNever scan a QR from a website in WhatsApp's link screen
Fake support"WhatsApp Security" says your account will be bannedYour SMS code or device approvalReal help comes from inside the app only
Code-by-mistake"I sent you my code by accident, send it back"Your own registration codeNever forward any code
Family emergencyMessage from a "new number" claiming to be a childMoney transferCall the person on the known number
Job or investment offerCold message with a link and a chat inviteFees, data, further accessDo not click; verify the company independently

The QR variation deserves a note. Our article on QR code phishing (quishing) explains why a QR code is only an encoded link or instruction, and why scanning it inside a sensitive screen hands over authority. The rule is simple: in WhatsApp's device-linking screen, only scan a QR code displayed by a device that you personally started and are holding.

Text-message cousins of this scam also exist. A text claiming that your account will be suspended unless you "verify" falls under SMS phishing, which we explain in what smishing is. And if a caller claims to be from "WhatsApp" or from your phone's maker and asks you to install a remote tool, see tech support scam warning signs.

The Malwarebytes report mentions that attackers rely on content that feels harmless. In the same period, press coverage elsewhere (for example Malaysia's communications regulator discussing hacked and blocked WhatsApp accounts with Meta in late September 2026, which we could only see in a search snippet and did not read in full) suggests the problem is wider than one country. We treat that as context, not as a proven statistic.

Three realistic scenarios (illustrative)

The scenarios below are invented for illustration, not real cases. They show how the same scam plays out for a parent, a small business and a retiree, and which step would have changed the outcome. Amounts are examples to give a sense of scale.

Realistic scenario 1: The dance-recital vote

A parent in Laval receives "Please vote for Emma, she's in the finals" from another parent in the recital group chat. The link opens a page asking her to "connect WhatsApp to confirm you are human." She enters her number, gets a code on the page, and types it into her linked devices screen. Nothing seems to happen. Two days later, six relatives reply to a message she never sent, which asked them to vote too and mentioned an urgent loan of 400 dollars.

What fixed it: she opened Settings, Linked devices, found a browser session she did not recognise, and logged it out. She posted the warning template in the recital group and turned on two-step verification. Total cost: about 20 minutes and one awkward group message. What would have prevented it: knowing that a code from a website must never be typed into the linked devices screen.

Realistic scenario 2: The plumbing company's shared number

A small plumbing company with four employees uses a single WhatsApp Business number for quotes. A technician approves a link that was sent by a "supplier" in a contest invitation. The attacker watches customer chats for a week and then sends a message from the company number to three clients with a new "payment link" for pending invoices of about 1,800 dollars each. Two clients ask by phone whether it is real; one pays.

What fixed it: the owner reviewed the linked devices list, found two unknown entries, logged them out, reset the PIN and sent an email to all customers. The paid invoice had to be traced with the client's bank. Lessons: a named owner for the number, weekly device reviews, and a written rule that payment details are never changed by chat alone.

Realistic scenario 3: The grandparent who lost access

A retiree receives a message from a "granddaughter" with a link to vote in a school talent show, and a follow-up from a stranger who says she "sent a code by mistake" and asks him to read it back. He reads out the six digits. His WhatsApp then asks him to register again, and his contacts begin to receive requests for gift cards.

What fixed it: his granddaughter helped him register his number again on his phone, set a PIN and a recovery email, and log out the unknown device. They called relatives to explain. Because he had never used the PIN feature, the second attack path was open. Lesson: the SMS code is the key to the number, and it should never be shared.

What it costs in Canada: DIY versus paying a technician

Doing the recovery yourself costs nothing but time, usually 15 to 45 minutes. Paying for professional help makes sense when you are locked out, when the business is affected, or when you suspect the phone itself is compromised. The real cost of the scam is not the cleanup but the money and trust lost by your contacts.

OptionTypical cost (CAD)TimeBest when
Do it yourself with this guide0 $15 to 45 minYou can still open WhatsApp and see Linked devices
Ask a family member to help0 $30 to 60 minYou are not comfortable with phone settings
IT Cares Expert Consultation (remote)119.99 $ for 60 minutesUp to 60 minYou are locked out, own a business number, or suspect other accounts were touched
Fraud losses if you ignore itVaries widelyWeeks to resolveNever worth the risk

Do not pay anyone who contacts you first and promises to "unlock WhatsApp" or "recover your account" for a fee. Meta does not charge for account recovery, and offers found through ads or direct messages are a common second scam. If you do want help, call a business you chose yourself.

The indirect costs are worth planning for. If the attacker asked your contacts for money, tell them to contact their bank, and if a payment already left, ask the bank to attempt a recall quickly. Time matters more than anything else for payment recalls.

Your 10-point protection checklist

Print or screenshot this list and review it once a month. Every item takes less than a minute and together they close the paths used in this scam.

WhatsApp protection checklist

  • I checked Settings, Linked devices and every entry is mine.
  • I logged out old devices I no longer use.
  • Two-step verification is on, with a PIN that is not a birthday.
  • The recovery email is current, protected and mine.
  • My phone has a screen lock and a SIM PIN.
  • I never type a code from a website into WhatsApp.
  • I never share my SMS verification code, even with a friend.
  • I treat "vote for my friend" and contest links as suspicious until confirmed by voice.
  • My family has a code word for emergencies.
  • I know how to report a scam message and who to call in Canada.

How to protect parents, grandparents and teens

The most effective family protection is one clear rule and one shared habit: no website ever needs a code from WhatsApp, and the whole family checks Linked devices on the first of each month. Scams exploit shame as much as ignorance, so make it easy to say "I clicked something" without blame.

Teens are often targeted with contest, giveaway and "free skin" lures. The back-to-school guide linked earlier suggests a short family agreement for these situations. For older relatives, pair this guide with our article on recovering a hacked Facebook account, since the same contacts are frequently targeted on both platforms.

Reporting the scam in Canada

In Canada, report fraud and scams to the Canadian Anti-Fraud Centre (CAFC) through its website, antifraudcentre-centreantifraude.ca, and report the same incident to your local police if money or identity information was lost. Also report the message inside WhatsApp so the sending account can be reviewed. Reporting helps investigators see patterns even when your own loss is small.

We did not verify the CAFC telephone line during this research pass, so we do not list a number here; use the website, which carries the current contact options. Prepare your report before you file:

Inside WhatsApp, you can generally report a contact or message from the chat's menu, and block the sender. Do this after taking screenshots. If your contacts sent money because of messages from your hijacked account, encourage them to report as well; each victim's own report matters.

Other places to inform

Official resources

For the most reliable, current instructions, use WhatsApp's own Help Center for device linking, account recovery and two-step verification, and use Canadian government sites for reporting fraud. Menu names and waiting periods change between app versions, so confirm details there rather than in forum posts.

More on account safety from IT Cares: what phishing is, what to do after a fake tech support scam, and the guide to recovering 2FA access if you lose a device while tightening security.

When to stop and call a professional

Call a professional if you are locked out of WhatsApp and the steps above do not restore it, if a business number or customer data is involved, if you entered passwords or card details on the fake page, or if other accounts are behaving oddly. Do not wait for losses to grow. Early help is cheaper than late help, and a calm second pair of eyes often finds the entry you missed.

IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. In a remote session, a technician can sit with you while you review linked devices, set up a PIN and recovery email, secure your email and other accounts, and check the phone for suspicious apps. You see everything we do, and we explain each step so you can repeat it. The Expert Consultation is a single 60 minute session at 119.99 $ CAD.

To talk to someone now, call 1 (888) 711-9428 or book a remote session. Never give a stranger your WhatsApp verification code, even someone who says they are from support: we will never ask for it.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

What is the WhatsApp "vote for my friend" scam?
It is a scam in which a message, often from a hijacked contact, asks you to vote for a friend in an online contest. The link leads to a fake page that gets you to link a device to your WhatsApp using your phone number and a pairing code or QR. Malwarebytes described the pattern in a report dated August 3, 2026.
Is my WhatsApp password stolen in this scam?
No. WhatsApp does not use a password for login, and nothing is stolen. You approve a linked device yourself, so the attacker holds a legitimate session. Changing your email password does not remove it. You must log the device out from Settings, Linked devices on your phone.
How do I check which devices are linked to my WhatsApp?
Open WhatsApp on your phone, go to Settings, then Linked devices. Review every entry and log out any you do not recognise. Menu labels can differ slightly between iPhone and Android and between app versions, so read the screen and confirm in the WhatsApp Help Center.
I entered a pairing code on a fake page. What should I do first?
Open Linked devices right away and log out every unknown session. Then warn your contacts, enable two-step verification with a recovery email, and check whether you typed any other passwords or card numbers on the fake page. Do not click the link again.
Can the attacker read my old messages?
Malwarebytes reports that once a device is linked the attacker can read messages and follow conversations in real time. Whether old history is visible can depend on how linking works, which we did not verify on the WhatsApp Help Center. Assume recent chats were visible and change anything sensitive shared in them.
Does two-step verification stop the linked device scam?
Not by itself. Two-step verification protects against someone registering your number on another phone with a stolen SMS code. A linked device approved by you is a different path, so you also need to check Linked devices regularly and never enter a website's code into the linking screen.
What if I am locked out of WhatsApp completely?
Reinstall or open WhatsApp on your own phone, enter your number and request a new verification code, then follow the on-screen steps. If a two-step PIN you did not set is requested, check the WhatsApp Help Center for the current waiting period, because we could not verify its length.
How do I warn my contacts?
Send a short message from your own phone: do not click the voting link, do not enter codes or numbers, and check Linked devices. Post it once in groups you manage. A ready-to-copy template is in the warning-contacts section of this guide.
Should I pay someone to recover my WhatsApp account?
No. Meta does not charge for account recovery, and people who contact you offering paid recovery are usually running a second scam. Use the in-app options and the official Help Center, or ask a business you chose yourself for help.
Are WhatsApp Business accounts affected too?
Yes. The same device-link trick works on a business number, and the risk includes customer data and fake payment requests. Assign one owner for the number, match every linked device to a named person, remove former staff immediately and warn customers by email if the number was misused.
Can a QR code be used for the same takeover?
Yes, it can be. Malwarebytes mentions fake pages that imitate WhatsApp connection steps, and QR codes are a common way to link a device. Only scan a QR code in WhatsApp's linking screen if it is displayed by a device you personally started and are holding.
Where do I report this scam in Canada?
Report it to the Canadian Anti-Fraud Centre through antifraudcentre-centreantifraude.ca, tell your local police if money or identity information was lost, and report the message inside WhatsApp. Keep screenshots of the message and your Linked devices list.
Can IT Cares help me secure my account?
Yes. IT Cares provides remote support across Canada. A 60 minute Expert Consultation costs 119.99 $ CAD. A technician can review linked devices with you, set up two-step verification, and check your email and phone. Call 1 (888) 711-9428.

Sources and official references

Last verified: October 1, 2026

Need Help?