WHATSAPP · LINKED DEVICES · PIN
WhatsApp hacked: what to do? Emergency assessment guide
WhatsApp may be used to exchange business information or coordinate quick decisions. A taken-over account or unauthorised linked device may impersonate a manager, request a transfer or deceive partners. A familiar conversation must never replace company approval procedures.
Here is how to perform a WhatsApp account assessment and respond according to your access. Re-registration on a new phone does not automatically reveal past conversations: distinguish account takeover, device linking and compromise of the phone itself.
1. Warning signs of a WhatsApp intrusion
An unfamiliar linked device
A Web, Desktop or other device session appears without your approval. An activity notification may alert you, but its absence does not prove the account is safe: review the list inside WhatsApp.
Unusual messages
Contacts or partners report requests for money or messages you did not send. An unusual read state needs corroboration: blue ticks are read receipts and do not alone prove surveillance.
An unsolicited registration code
A code received without your request may reflect a registration attempt, but also a mistyped number. Do not share it, even with a familiar contact, and do not approve unexpected device-linking requests.
Your number is no longer registered on this phone
If you have not changed phones or re-registered the account, this message calls for immediate action. Also check your mobile line: unexplained loss of service may require contacting your carrier.
2. Assess the account without exposing access
Never share your password, a 2FA code or a backup code with a third-party assessment tool. Perform checks in official interfaces opened directly.
Review linked devices
On iPhone, open Settings then Linked devices. On Android, use the three-dot menu then Linked devices. Compare each entry with your usage, select an unfamiliar device and log it out. Labels may vary by version.
Review PIN and recovery
In account settings, review two-step verification and the associated email. Make sure you control and secure that mailbox. Your personal PIN is separate from the registration code received by SMS or call.
Review conversations and the phone
Look for unfamiliar messages, documents or recipients without opening suspicious attachments. Storage usage is not a complete exfiltration log. No unfamiliar linked device does not rule out spyware on the phone: ask support to examine it if anomalies persist.
3. Regain control according to your situation
Still signed in: remove unfamiliar devices
Log out unfamiliar devices from the official app, then review the list again. This does not erase messages or files already copied by someone else. Alert affected contacts and IT if the account is used for work.
Lost access: re-register the number
On a trusted phone, open WhatsApp, choose to log back in and enter your number in international format. Enter the six-digit SMS or call code only in the app. Official help states that re-registration logs out devices using the account; review linked devices afterwards.
Unknown PIN: follow the offered recovery flow
A requested PIN does not prove an attacker created it: it may also have been forgotten. Use the recovery option offered if you control the associated email. Otherwise, WhatsApp help states a seven-day wait before retrying; follow the delay displayed in the app. This is a service rule, not a legal requirement. After validation of the SMS code, help states that the other user is logged out even if the PIN is still requested.
Strengthen two-step verification
In Settings > Account > Two-step verification, enable a personal PIN and check the recovery email. Share neither the PIN nor registration codes. This reduces risk without preventing every attack, including a device link approved by mistake or a compromised endpoint.
4. Lost mobile access and payment requests: alert others
If you can no longer receive codes and suspect SIM takeover, contact your carrier through a trusted channel to regain control of the number. Alert IT and contacts another way. For a fraudulent payment request, promptly alert accounting and the relevant bank.
Never share codes and review linked devices
Security does not depend on SMS alone: protect the phone, mobile line, recovery email and device-linking requests. Do not scan a login QR code or enter a linking code at a stranger’s request. Checking a suspicious WhatsApp account complements an independent callback before sensitive operations.
Deploy SecurCheck Business to support your teams every day