Hackers quietly link a victim’s account to a device they control, turning a trusted tool into a hidden doorway. Once the link is made, attackers can read messages, view photos and videos, listen to voice notes, and access other private data.

What makes this threat more dangerous is its simple and sneaky design. Experts say the attack can begin with just one message. The message often appears to come from someone the victim knows, which lowers suspicion and builds false trust.

The message includes a link that claims to show a photo. Instead, it redirects the user to a fake Facebook login page. 

Any details entered there are quietly captured and used to gain access to the victim’s WhatsApp account. From that point on, hackers can also message the victim’s contacts, spreading the scam further like a chain reaction.

Cybersecurity specialists stress that this method does not crack WhatsApp’s encryption. Instead, it walks around the front door by tricking users into giving access themselves.

Experts advise users to stay alert and act with caution. Unknown or unusual links should never be opened, even if they appear to come from a familiar number. Any unexpected login alerts or device-linking requests should be rejected immediately.

In a digital world where scams grow smarter by the day, researchers remind users of a simple rule, pause, check, and think before you click. A few seconds of caution can save months of trouble.