A simple message, a stolen code, and suddenly your trusted contacts become targets; inside Lebanon’s growing WhatsApp hacking networks and the tricks criminals use to steal accounts, money and personal data.
The complete journey of hackers into your accounts
The complete journey of hackers into your accounts
You may be among those whose WhatsApp accounts were hacked over the past year. Or at least, you may have received a message from one of your contacts asking you to send money through money transfer companies, only to discover later that their WhatsApp number had been hacked. If you were lucky enough not to have your account hacked, or not to have responded by sending money to hackers who had taken over the accounts of people in your contact list, thousands of people in Lebanon have fallen victim either to account hacks or to sending money to organized hacking networks that begin by stealing WhatsApp accounts and do not stop until they steal users’ money.
In this context, information and communications technology consultant Amer Tabbash reveals to Nidaa Al Watan that MPs and ministers from different areas across Lebanon have not been spared by organized hacking networks. Social figures working in social assistance have also been victims of WhatsApp account hacks, particularly because their contacts are accustomed to sending them money. Those contacts became a “perfect” target for hackers.
As for the latest hacking operations, they begin with a message sent through Messenger before taking control of WhatsApp. How do these “organized” cybercrimes happen? How have their techniques evolved with the development of social media platforms? Where do users’ weaknesses appear? How can we protect our accounts? And what does the Head of the Public Relations Division at the Internal Security Forces, Brigadier Joseph Moussallem, say about the awareness campaign launched by the Internal Security Forces?
Whose responsibility is it?
Azza, a citizen who works in social assistance, needs to request money from her contacts through WhatsApp as part of her work. What caused her the greatest embarrassment after her account was stolen was that some of her contacts fell victim to the trap of being asked to send money through money transfer companies, because the nature of her work made it easier for the hacker to convince them.
Sources at the Ministry of Telecommunications explain to Nidaa Al Watan that the ministry does not take any action related to blocking any application unless based on a judicial decision. As for hacking users’ accounts, this does not fall within its authority, as these applications are not subject to the ministry’s control, and their servers are located outside Lebanon.
Security forces, particularly the Cybercrime Bureau and the Information Branch, are responsible for dismantling hacking networks and arresting those involved. However, the first proactive responsibility falls on the user, meaning the Lebanese citizen, whom security and technology experts compare to a homeowner who is expected to protect their house from thieves knocking on the door and immediately letting them in.
So how does a hacker knock on the user’s door? And how do they steal from them online?
Hacking and theft techniques
Information and communications technology consultant Amer Tabbash points out that the age of theft operations through social media applications is the same as the age of these applications themselves. As social media platforms developed, the techniques used to steal through them evolved as well.
Previously, theft occurred through stealing mobile phone recharge cards, which served as electronic wallets, as some users requested limited amounts of money from others through them. The process then evolved into blackmail involving personal photos accessed by hackers, who demanded money in exchange for not publishing them.
With Lebanese people increasingly adopting electronic payment operations in recent years, and with these services existing as applications on their phones, which accelerated money transfers with the click of a button, the situation moved into a new form of organized two-stage theft that begins with WhatsApp and ends with money transfer company applications.
In this context, Tabbash attributes the ease of hacking WhatsApp, then luring the contacts of the user whose account was stolen and deceiving them into sending money to hackers through money transfer companies, and sometimes through other money transfer methods or bank Visa cards, to the fact that not all users are fully familiar with how WhatsApp and money transfer applications work.
Protection options are not secondary
This brings us back to the first proactive responsibility, which lies with the user.
In the first stage, users are deceived because they trust links sent by hackers or respond to their requests to share the OTP code linked to their phone. However, taking control of a WhatsApp account becomes much easier when the user has not activated all available security features on the application, such as fingerprint protection and two-factor authentication, which are available in the app’s security settings.
A WhatsApp account with weak security can be stolen either through this vulnerability or by sending a link containing malicious software. Once the number is taken over, the hacker gains access to the user’s large network of contacts and begins targeting them as well in order to compromise as many accounts as possible.
The theft occurs through several methods, the most common being:
Sending an invitation to join a group under the name “WhatsApp Join Group,” while the link is malicious. Many users fail to notice that the URL does not contain the WhatsApp logo or official indication in the web address.
The hacker may send images and ask the user to download them onto their phone, for example by sending the phrase: “Download this picture” along with the image.
Sometimes, the hacker may send a malicious application that takes control of WhatsApp and possibly other information stored on the phone.
Another method, which cybersecurity experts and security officials strongly warn against, is a request to send an OTP code received on the phone of the targeted user through a regular SMS message. Once such a request is made, any user should immediately understand that they are being targeted for hacking. The code is linked to the user’s own WhatsApp number, not the hacker’s number requesting that the OTP code be shared.
Tabbash warns: “This code belongs exclusively to the user as long as it was sent to their number. There is no way in the world to send a message to someone’s SIM card using another person’s number.”
Therefore, once the account owner shares the code with the hacker, the latter takes control of the user’s WhatsApp account and locks the user out of the application through the logout feature.
As soon as the hacker enters the WhatsApp account, they begin changing account settings, such as the email address. However, they cannot change the fingerprint protection or two-step verification feature. If these protections are not activated, the hacker can simply take full control of the WhatsApp account.
Scamming contacts
$1,200 in Just 3 Hours!
At this stage, after taking control of the largest possible number of WhatsApp accounts and reaching a dead end with protected accounts that have fingerprint protection or two-step verification activated, the hacker moves to the stage of financially scamming the contacts of stolen WhatsApp accounts.
The operation is profitable. Tabbash gives an example: “In just three hours, during which a hacked WhatsApp account was recovered, the hacking network had stolen $1,200 from its contacts.” So how are contacts lured into the trap?
Assume that a hacker has collected seven WhatsApp accounts. They send “Hi” to each one. The contact replies, and a conversation begins, which the hacker tries to shorten in order not to reveal themselves, whether through their writing style, the way they communicate, or even details about the relationship between the stolen-account user and the contact.
The hacker then requests money, saying something like:
“I’m at a phone shop and I urgently need $100... Send it to me through a money transfer company. I had an accident, but once I leave the hospital I’ll pay you back...”
Assuming that each of the seven compromised WhatsApp accounts has 100 contacts, the hacker now has 700 potential conversations with 700 potential victims, and this is where the money begins flowing in.
The speed of electronic transfers, especially since WhatsApp and money transfer applications are installed on the phones of most users in Lebanon, makes the theft process easier and faster.
Around 90 to 95 percent of transfers cannot be stopped by money transfer companies because they are sent instantly. The hacker then moves the money from one account to another, transfers it abroad, or collects it in cash. By the time investigations are completed, recovering the money becomes almost impossible in most cases, especially because the numbers receiving the transfers are anonymous numbers purchased on the black market.
Security forces continue to uncover hacking networks one after another, but proactive protection requires us to rely on ourselves first, says Tabbash, “by using the highest levels of protection available on WhatsApp and being aware not to fall victim to sharing our phone codes or transferring money.”
When an OTP code arrives on your phone, it is 100% yours alone. Sharing it with anyone else means handing over “your neck.” Therefore, the security measures available on our phones must be used to the fullest and become a habit.
As for money transfers, users must remain alert and call the person before sending any amount to confirm that their WhatsApp account has not been hacked, limiting the theft operation with the least possible damage.
From Facebook… to WhatsApp
Meta launched what is known as the Account Center, which links users’ Facebook, Messenger, Instagram and WhatsApp accounts in order to make managing these accounts easier.
However, recently, WhatsApp theft has begun through links sent via Messenger. Tabbash explains: “Once a hacker is able to steal a Facebook and Messenger account, the accounts connected within the Account Center, including WhatsApp, also become vulnerable to theft, as the hacker exploits the weakness in the linking process between these accounts to take control of them.”
For this reason, Tabbash urges users to remain aware of all applications on their phones, not only WhatsApp.
As for how far the theft can go, it depends on the type of WhatsApp backup used, whether it is stored on Google Drive, where the risk is limited, or locally on the phone, where the risk is much greater. In the latter case, the hacker may be able to access all files uploaded to the backup: photos, documents, voice messages and more.
The most dangerous aspect of gaining access to rich data and personal materials is the transition to electronic blackmail, where hackers demand thousands of dollars in exchange for returning materials, photos or videos.
MPs, ministers and social figures… victims!
Account theft has reached MPs, ministers, lawyers and social figures from different Lebanese regions. Tabbash reveals that the work of someone whose account has been hacked in the field of social assistance and fundraising, which became widespread after the economic crisis to collect money for patients’ operations and medication, makes their contacts easy targets for hackers.
For this reason, Tabbash emphasizes the importance of awareness. Everyone is concerned with this issue, and the victim is our cybersecurity.
Internal Security Forces awareness campaign
The Public Relations Division of the Internal Security Forces launched an awareness campaign through its social media pages about cybercrimes.
Under the title “To All WhatsApp Users: Be Careful,” an ISF video explains in detail how WhatsApp accounts are hacked and warns against sending money to contacts before confirming that their accounts have not been compromised, even if this requires making a regular phone call and hearing the voice of the WhatsApp account owner to verify that the request is genuine.
In this context, the Head of the Public Relations Division at the Internal Security Forces, Brigadier Joseph Moussallem, tells Nidaa Al Watan that a significant number of Lebanese people have fallen victim to WhatsApp account theft because they rushed to open a malicious invitation link or responded to a hacker’s request for their OTP number. This code, he stresses, “is something nobody in the world asks for, and it belongs only to the owner of the number.”
Hackers exploit the relationship between the user whose account has been hacked and the person whose money they are trying to steal. When the potential victim has a trusted relationship with the first victim, such as a childhood friend, employer, friend or relative, they are more likely to respond to the hacker’s requests because they do not question a money request coming from that person.
Moussallem therefore stresses the need to be responsible when using our phones and to “count to ten before responding to this type of request, whether it involves joining links or sending money.”
The victim is our privacy and personal information, or information related to our businesses. All of our information on WhatsApp may be vulnerable to hacking.
Fraud through Artificial Intelligence
Returning to WhatsApp, Moussallem warns of fraudulent techniques such as sending an actual voice message from the hacked user through the forwarding feature. The message may simply say: “How are you, my friend,” or something similar, after which hackers write the text requesting money.
For this reason, Moussallem urges users to pay attention to phrases, accents and every possible indication, and to call the person on their regular phone number to confirm that they are actually the one requesting money, especially in the age of artificial intelligence, where AI-generated voice messages can be created.
As for theft that begins through Facebook, he points out that it is not necessarily the Facebook account itself that is stolen. Instead, hackers may impersonate a person by creating a fake account and then contacting their friends on Facebook or Instagram.
Moussallem concludes by comparing the phone applications that contain our private information to “our home,” asking: “Do we immediately open the door to everyone who knocks?”
He encourages citizens to follow awareness campaigns, especially since theft is no longer limited to WhatsApp. Financial fraud has also expanded to platforms claiming to offer stock market trading.
The first step toward protection is awareness
More than a year has passed since the pattern of WhatsApp account theft and hacking targeting Lebanese users began.
Spreading knowledge and awareness remains necessary to protect citizens from further hacking operations and financial theft, because the first step toward protection is awareness and using the security technologies that phone applications have provided for this purpose.