Cyber Security · 2 May 2026

UK Cybersecurity Scam Alert: WhatsApp Hijacking 2024

By Markelly AI · 2 May 2026

A dangerous new cybersecurity threat is sweeping across the United Kingdom, targeting WhatsApp users through sophisticated account hijacking schemes. Criminals are using a combination of social engineering tactics and SMS phishing to gain unauthorized access to personal WhatsApp accounts, potentially leading to identity theft, financial fraud, and the compromise of sensitive personal information belonging to entire contact lists. This scam has already affected thousands of UK residents and experts warn that without proper awareness and protective measures, it could escalate into one of the most damaging cyber threats of 2024, potentially resulting in millions of pounds in losses and irreparable damage to personal and professional relationships.

How the WhatsApp Hijacking Scam Works

The scam begins when fraudsters send text messages to mobile phone numbers claiming to be from WhatsApp or a trusted service provider. These messages typically state that the recipient needs to verify their account or that suspicious activity has been detected. The message includes a six-digit verification code and urgently requests the user to share this code to maintain account security. However, this code is actually a legitimate WhatsApp verification code that the criminals have triggered by attempting to register the victim WhatsApp account on a different device. Once the victim shares this code, the scammers immediately gain control of the WhatsApp account, locking out the legitimate owner.

The Devastating Impact on Victims

Once criminals gain access to a WhatsApp account, they quickly change security settings and begin impersonating the account owner. They contact everyone in the victim contact list, often claiming to be in an emergency situation and desperately needing money. Because the messages come from a trusted contact verified account, many people fall victim to these follow-up scams and transfer money believing they are helping a friend or family member in need. The National Cyber Security Centre has reported that average losses per victim can range from hundreds to thousands of pounds, with some cases involving even larger sums when business accounts are compromised.

Warning Signs to Watch For

UK cybersecurity experts advise the public to be vigilant for several red flags that indicate a potential WhatsApp hijacking attempt. First, be extremely suspicious of any unsolicited text message containing a verification code, especially if you did not initiate any account recovery or device change. Second, WhatsApp will never call or text you asking for your verification code. Third, if your WhatsApp suddenly stops working or you receive a message saying your account is being registered on a new device without your knowledge, act immediately to secure your account. Additionally, be wary of any urgent requests for money from contacts, even if they seem legitimate, and always verify through a phone call or alternative communication method before sending funds.

How to Protect Yourself

Protecting yourself from this scam requires multiple layers of security. Enable two-step verification in WhatsApp settings, which adds an extra PIN code that criminals cannot bypass even if they obtain your SMS verification code. Never share verification codes with anyone under any circumstances, regardless of how convincing the request may seem. Regularly review your WhatsApp security settings and ensure your account email address is current and secure. Educate family members and friends about this scam, particularly elderly relatives who may be more vulnerable to such tactics. If you believe your account has been compromised, immediately contact WhatsApp support, inform your mobile provider, and warn all your contacts that your account may be sending fraudulent messages.

Reporting and Recovery

If you become a victim of this scam, swift action is essential. Report the incident to Action Fraud, the UK national reporting centre for fraud and cybercrime, and contact your bank immediately if you have shared financial information or made payments. Document all communications related to the scam and preserve evidence. The National Cyber Security Centre also encourages victims to report suspicious messages through their Suspicious Email Reporting Service. While recovering a hijacked WhatsApp account can be challenging, acting quickly significantly increases the chances of successful recovery and minimizes potential damage to your contacts and finances.