Summary Fake QR codes and call-forwarding scams are among the methods used to compromise WhatsApp accounts.
WhatsApp has introduced new security features designed to strengthen account protection, including improved two-step verification and support for multiple passkeys. While the upgrades are expected to make account takeovers more difficult, users still need to remain cautious because stronger authentication cannot stop scams that trick people into giving attackers access.
WhatsApp has experienced several security threats over the years. In the past, attackers exploited vulnerabilities that could allow spyware to be installed without requiring users to take any action. More recently, however, criminals have increasingly turned to phishing and social-engineering scams that manipulate users into handing over access themselves.
Fake QR codes and call-forwarding scams are among the methods used to compromise WhatsApp accounts. The platform’s new security measures are intended to reduce the risk of such attacks, but users still have an important role to play.
One of the biggest risks is unauthorized access through linked devices. Even a strong password may not help if a user is tricked into linking an attacker’s browser or device to their WhatsApp account. Users should therefore regularly open Settings > Linked Devices and review all computers, browsers and phones connected to their account. Any unfamiliar device should be removed immediately.
WhatsApp also recommends reviewing its privacy and security settings. Users can enable features designed to limit unwanted message floods from unknown accounts and protect their IP address during calls.
Another useful update is coming to Android users. WhatsApp will provide more information about calls from numbers that are not saved in a user’s contacts. The app may show whether the caller is from another country and whether the two users belong to any of the same WhatsApp groups. This additional context could help users decide whether a call is legitimate before answering.
Despite the new protections, basic security precautions remain essential. Users should never scan a WhatsApp QR code or enter a device-linking code simply because a website, message or person claiming to be support instructed them to do so.
The new features provide another layer of protection, but the safest approach is to combine WhatsApp’s security tools with regular checks of linked devices and caution around unexpected messages, calls and account-verification requests.
