Ghost Pairing: Abuse of WhatsApp's Device Linking Feature
In Ghost Pairing attacks, criminals abuse WhatsApp's official device linking feature, the BSI said. According to the agency, attackers send convincing phishing messages, often from hacked accounts belonging to the victim's contacts or purporting to come from social media platforms.
Victims are directed to fake websites and asked to enter their phone number, the agency said. The number is then passed to WhatsApp to activate the device linking function.
How the Attack Unfolds
- WhatsApp generates an eight-digit pairing code
- The attackers ask the victim to hand over this code
- Alternatively, they use QR codes designed to resemble the WhatsApp Web login
- Once a device is linked, the attackers can access messages, media and contacts
According to the BSI, the access often goes unnoticed for a long time because no notification is sent.
BSI Recommendations
- • Treat incoming messages with caution, even from known contacts
- • Do not use QR codes from unknown sources for device linking
- • Enable two-factor authentication in WhatsApp
- • Regularly review connected devices under Settings > Linked Devices
- • Consider switching to other messenger services (Signal, Threema)
Steps in Case of a Suspected Compromise
If a WhatsApp account may have been compromised, the BSI recommends the following steps:
- • Immediately remove all linked devices under Settings
- • Enable two-factor authentication or change the PIN
- • Inform contacts that messages may have been sent from the account in your name
- • File a report with the police
