Categories: Tech and Auto

Big WhatsApp Scam Warning: ‘GhostPairing’ Lets Hackers Take Over Your Account Without OTP – How To Stay Safe

A new scam has been introduced in market through which attackers are hijacking Whatsapp without any OTP. Follow these steps to stay safe.

Add NewsX As A Trusted Source
Add as a preferred
source on Google
Published by Syed Ziyauddin
Published: December 20, 2025 16:36:46 IST

A new scam has been rolled out in the market targeting WhatsApp users. Through this sophisticated new scam hackers exploit the app’s device-linking feature to gain full access to victims’ accounts. The cybersecurity experts have warned that the campaign, called GhostPairing. This allows attackers to hijack accounts without stealing passwords, SIM cards, or OTPs. 

The GhostParing relies entirely on social engineering, tricking users into approving a malicious device themselves. This method is tough to detect and spread quickly through trusted contacts and raises serious questions about how device pairing features are designed and understood. 

How hackers work 

As per experts and reports, the scam begins with a seemingly innocent message from a trusted contact, such as “Hey, I just find your photo!” The message contains a link that displays a Facebook-style preview inside WhatsApp. 

Clicking the link leads users to a fake webpage resembling a Facebook photo viewer, which prompts users to ‘verify’ before seeing the content. In reality, this step triggers WhatsApp’s official device-pairing process. Users are asked to enter their phone number, after which WhatsApp generates a numeric pairing code. The fake page then instructs users to enter this code in WhatsApp, presenting the process as a routine security check. 

 After entering the code, victims unknowingly approve the attacker’s device. This grants the hackers full WhatsApp Web access, enabling them to read messages, download media, send messages as the victim, and receive new messages in real time, all while the phone continues to function normally, making the breach difficult to notice. 
 

How to stay safe 

To protect against GhostPairing, users are advised to follow these steps 

  • Regularly check settings > Linked Devices in WhatApp and remove any unfamiliar sessions. 

  • Enable two-step verification for added security. 

  • Verify unexpected messages carefully, even if they appear to come from known contacts.  

Cybersecurity experts warn that vigilance is essential, as attacks like GhostPairing exploit human trust rather than technical vulnerabilities. 

Published by Syed Ziyauddin
Published: December 20, 2025 16:36:46 IST

Recent Posts

West Bengal Budget: As Polls Near, Mamata Govt Announces ₹500 Monthly Increase In Lakshmi Bhandar- What We Know About The ‘Women-Friendly’ Scheme

Bengal hikes Lakshmi Bhandar aid by ₹500 ahead of polls; women to get ₹1,500–₹1,700 monthly…

February 5, 2026

Cloudeva.ai Rolls Out Public Preview Of New Cloud Decision Intelligence Platform, Check Its Features And Why Does Its Matter

Cloudeva.ai officially launches as a multi-cloud intelligence platform that helps enterprises turn cloud activity into…

February 5, 2026

School Headlines (February 6, 2026): PM Modi To Interact With Students At Pariksha Pe Charcha, When, Where And How To Watch

PM Modi will interact with students, teachers, and parents during the ninth edition of the…

February 5, 2026