WhatsApp users should be vigilant against a growing scam that leverages the platform’s six-digit verification code. Security experts warn that sharing this code with anyone, even trusted contacts, could lead to complete account compromise.
The messaging service employs the six-digit code to verify users during login or account recovery. This code, automatically generated and delivered via SMS or automated call, is considered a critical piece of confidential information. According to reports from September 14, 2025, attackers are actively attempting to trick individuals into revealing this code.
Scammers often pose as acquaintances or family members, claiming they accidentally entered the user’s number during a login attempt. If a victim provides the code, the attacker gains full control of the account, including access to all messages and the ability to contact the user’s network. This tactic highlights the increasing sophistication of social engineering attacks targeting popular communication platforms.
To protect against this type of fraud, WhatsApp advises users to never share their six-digit verification code with anyone, regardless of their claimed identity. Users should also be cautious of suspicious messages or communications from unknown numbers. Enabling two-factor authentication within WhatsApp provides an additional layer of security.
WhatsApp is also developing further security measures, including the ability to protect individual conversations with a unique secret code. While still in the testing phase, this feature, as reported on December 8, 2024, could offer enhanced privacy for both personal and professional communications. The addition of this feature demonstrates WhatsApp’s commitment to bolstering user security in the face of evolving threats.
Beyond the six-digit code, users should also be aware of potential risks associated with MMI codes, which can be exploited to unknowingly enable call forwarding and potentially lead to account takeover. Checking for active call forwarding is a proactive step in maintaining account security.