Risk:High — Messaging account hijackers abuse phishing and device pairing to impersonate trusted contacts, making fraudulent transfer requests appear genuine.
Install the app:Open the app and verify suspicious content in one scan.
Hacked WhatsApp or Signal Account: What to Do
Messaging account takeovers are active globally in 2026, especially against WhatsApp and Signal users. Attackers increasingly abuse phishing, social engineering, linked-device approvals, unauthorized pairing and stolen sessions—not just passwords or SIM swaps.
6 signs an account may be hacked
- An unexpected device-linking request appears. Myth: pairing is routine maintenance; reality: a message such as “Link this device to keep using your account” can lead to a flow that authorizes the attacker’s device. Quick check: open the official app directly and inspect linked devices or active sessions.
- A known contact suddenly requests a transfer. Myth: a familiar profile proves who is writing; reality: a hijacked session can preserve the person’s name, photo and conversation history. Quick check: call the person through a separate, previously known channel before sending anything.
- Your account still works normally. Myth: you would be logged out immediately; reality: unauthorized linked sessions may coexist with your phone. Quick check: look for devices, browsers or recent activity you do not recognize.
- Someone asks for a code, QR scan or approval. Myth: only passwords unlock accounts; reality: pairing flows can grant access without revealing one. Quick check: reject any approval for a device you are not physically setting up.
- Messages appear that you did not send. An attacker may impersonate you to request money or target more contacts. Quick check: review recent chats, archived conversations and sent media for unfamiliar activity.
- The sender insists the bank will protect the transfer. Myth: banks automatically identify account impersonation; reality: a payment you authorize after trusting a hijacked chat may look legitimate. Quick check: stop and verify both the request and recipient independently.
If any sign matches
- Do not transfer money or share codes.
- Remove unrecognized linked devices and sessions.
- Start recovery only through the app’s official settings or website.
- Warn contacts through another trusted channel.
- Contact the payment provider immediately if money was sent.
Most common warning signals
- Unexpected linked-device approval
- Unknown active session
- Unrequested QR scan
- Verification code request
- Messages you did not send
- Sudden transfer request
What to do now
- Stop all transfers and code sharing.
- Remove every unrecognized linked device or session.
- Use the service’s official account-recovery process.
- Enable two-step verification and secure recovery email.
- Warn contacts through a separate trusted channel.
- Contact the payment provider if money was sent.
Sources
Further reading
- Account and Payment Recovery After Tax Refund Phishing
- Account and Payment Recovery Scam Defense Guide
- Top Scam Warning Signs in a Fake Prize Message
FAQ
Can WhatsApp or Signal be taken over without my password?
Yes. Attackers may trick you into approving a linked device, scanning a pairing code or surrendering an active session, so password theft or a SIM swap is not always required.
Should I send money if my contact confirms in the same chat?
No. The attacker may control that conversation. Verify the request by calling a previously known number or using another trusted channel before transferring anything.
What if my messaging app still works on my phone?
That does not rule out compromise. Review linked devices and active sessions immediately, remove anything unfamiliar, and check for messages or media you did not send.
What should I do if I already approved an unknown device?
Remove the device or session immediately, use the platform’s official recovery controls, enable two-step verification, and alert contacts that messages from your account may be fraudulent.