Technology

The technology behind the most common scams on WhatsApp

Learn how each attack works and check out practical tips to protect yourself from cloning, malware, and phishing

08/26/2025

Brenda Pimentel

Over the past decade, WhatsApp has evolved from a simple messaging app into an essential tool in the lives of practically all Brazilians. According to a survey by Mobile Time, conducted in partnership with Opinion Box, the app is installed on 99% of active smartphones in Brazil. This ubiquity, connecting families, friends, and businesses via WhatsApp Business, also opens a door to digital crimes.

The app has been so widely adopted in Brazil that it is practically impossible for us not to have heard of relatives or acquaintances who have fallen victim to some scam on the platform. A report by cybersecurity firm Kaspersky revealed that, in 2023, the country was the main target of mobile device attacks in Latin America, with an alarming average of more than 700 fraud attempts per minute. And WhatsApp, due to its popularity, has established itself as the main channel for executing these scams.

In this article, we will unravel the technology and logic involved in the most common scams circulating on your WhatsApp. By understanding the mechanism behind these cybercrimes, it is possible to transform knowledge into a shield, protecting your information and your money.

The anatomy behind the top 3 WhatsApp scams 

The first step to protecting yourself is knowing how criminals operate. The most common scams can be divided into three major categories, each with its own technical logic.

1. Fake account hijacking or Account Takeover

Popularly called cloning, this is one of the scams that causes the most headaches for the victim. Known technically as Account Takeover, this scam allows the criminal to take full control of your profile, pretending to be you.

First, the scammer obtains your phone number through data leaks, public groups you participate in, or ads you published on online sales platforms. With the number in hand, the criminal installs WhatsApp on a new device and attempts to register your account. Automatically, the official WhatsApp system sends a 6-digit verification code via SMS to your cell phone (the true owner of the account). And it is at this moment that they contact you — using another account or even via a phone call — and create a convincing story so that you hand over the code you just received. Among others, the most common excuses to extract this code are related to the delivery of online purchases, ads, sweepstakes, and technical support, always involving the request for the code.

As soon as the victim provides the code, the criminal types it into the device dedicated to cloning and completes the registration. Immediately, you are disconnected from your account, and the scammer takes control, using your profile to ask friends and family for money.

To protect yourself against this scam, it is important to enable two-step verification. It is a 6-digit password (PIN) that you create yourself within the WhatsApp security settings. With it enabled, even if the criminal gets the SMS code, they will still need to type this secret PIN to access your account. It is an almost insurmountable barrier for this type of attack.

2. Phishing: data fishing in digital waters

Despite being one of the oldest threats on the internet, phishing continues to be widely used by digital criminals. The name comes from "fishing", as the goal is literally to "fish" for your most sensitive information.

You receive a message with an irresistible promise: a huge discount at a famous store, the chance to win a valuable prize, a dream job vacancy, a newly released social benefit, or tickets to a popular event. The message is designed to create a sense of urgency, such as "last items available!" or "today only!", and is always accompanied by an apparently harmless link.

By clicking on this link, the victim is directed to a front page that perfectly mimics the look of the legitimate website (colors, logos, fonts, images, etc.). To make this page even more convincing, criminals use a technique called URL Spoofing, creating addresses that look real, such as www.magazineluiza-ofertas.net instead of the official www.magazineluiza.com.br.

On the fake page, a form requests that you enter personal data such as your full name, CPF, and, most dangerously, passwords and credit card details. Upon filling it out and clicking "Confirm" or "Register", all of this information is sent directly to a server controlled by the fraudster.

The first step to avoiding this type of scam is to check if the domain link is official. You can do this by pressing and holding the link with your finger. A small window will show the actual address to which you will be taken. If the link contains different characters or unusual names, be suspicious. 

Secure sites use the https protocol, with the "s" indicating that it is secure, and display a padlock icon in the address bar. Phishing pages frequently use only http and do not usually feature the padlock icon. The golden rule here is: never click on random links. If the offer seems real, close the message, open your browser, and type the address of the official website yourself to check if the promotion exists.

3. Malware and Spyware: the invisible enemy

While phishing tricks you into handing over your data, malware (malicious software) is a program that installs itself on your cell phone to steal it silently and continuously.

Malware comes disguised as something harmless or desirable. It can be, for example, a premium or pro version of a popular app, a new sticker pack, a viral video, an important document, or a supposed security update.

The victim is induced to download and install a file from outside the Google Play Store or Apple App Store. On the Android system, these malicious files have the .apk extension. During installation, the malicious app requests absurd permissions, such as full access to your contacts, SMS, microphone, camera, location, and accessibility permissions, which allow seeing and controlling everything that happens on your screen. In a hurry, many users grant permissions without reading. Once activated, the malware can:

  • Record everything you type, including passwords for banking apps.

  • Create fake screens that overlay the login screens of banking apps to harvest your credentials.

  • Monitor your conversations and activate the microphone.

  • Hijack your files and demand a ransom in cryptocurrencies.

The defense here is to download apps exclusively from official stores (Play Store and App Store), in addition to keeping your cell phone settings configured to block installations from unknown sources. Before downloading any app, ask yourself: "Why does a flashlight app need access to my contacts?". If the permissions seem unnecessary for the app's function, do not install it.

Suspicion is the key word 

The technology behind scams may evolve day after day, but the foundation of protection remains the same: caution, suspicion, and information. You do not need to be a tech expert to be safe. You just need to understand the logic of criminals so as not to fall into their traps. In addition, it is important to keep your operating system and apps up to date, patching security flaws that could be exploited by criminals.

4 quick digital security tips:

  1. Enable two-step verification on your main apps right now. It is the strongest barrier against account hijacking.

  2. Never, under any circumstances, share the 6-digit code that WhatsApp sends by SMS. 

  3. Be suspicious of unexpected offers, prizes, and requests for money, even if they come from known contacts. When in doubt, call the person to confirm.

  4. Inspect all links before clicking and only download apps from official stores.

If you know someone who has already fallen victim to a digital scam, whether via WhatsApp or any other app/website, share this article! Every informed person is one less target for scammers and one step closer to a safer digital environment for everyone.

 

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546