Alert in Extremadura over the hijacking of WhatsApp accounts

  • Increase in WhatsApp kidnapping scams in Extremadura, with cases in several towns such as Zafra.
  • The fraud begins with a six-digit verification code that arrives unsolicited.
  • Cybercriminals impersonate the victim to ask for urgent money from contacts, especially via Bizum or bank transfer.
  • The Police and the Civil Guard recommend not sharing codes, activating two-step verification, and reporting immediately.

WhatsApp hijacking in Extremadura

La The National Police and the Civil Guard have raised the alarm in Extremadura. Faced with the rise of a scam popularly known as the "WhatsApp hijacking," several cases have been reported in the community in recent weeks, particularly in municipalities like Zafra, where several residents have lost money after their messaging accounts were taken over by criminals.

This fraud, which affects users throughout Spain but is showing a worrying upswing in the Extremadura regionIt relies on a simple deception: stealing access to the victim's WhatsApp account to impersonate them and ask for money from friends and family; in addition, there are other methods such as WhatsApp account theft via video call.

This is how WhatsApp hijacking works in Extremadura

According to the Extremadura Police Headquarters, the fraud usually begins when the user receives a message on their mobile phone. automated WhatsApp message with a six-digit verification code which you did not request. That message is part of the process the app uses when someone tries to register an account with a specific phone number.

Shortly afterwards, a message appears on the screen from a supposed acquaintance - usually a friend or family member - explaining that he has victim's number entered in error while trying to set up his own account. In a friendly and seemingly innocent tone, he asks that the code received "by mistake" be resent to him so that he can finish the registration.

The moment the user, trusting, shares that six-digit number, Cybercriminals now have the key to activate the WhatsApp account on another deviceThe legitimate owner is automatically banned from their profile and loses access to their conversations, groups, and contacts.

From that moment on, the account is literally "hijacked": the criminals take complete control of it, can read recent chats and They start writing to their most frequent contacts impersonating the victim. The attack relies on this false appearance of normality, taking advantage of profile pictures, real name, and chat history.

WhatsApp kidnapping scam

Identity theft and urgent request for money

Once they have taken control of the account, the scammers put the second part of the plan into action: identity theft and soliciting moneyTo do this, they select trusted contacts—family members, close friends, or even co-workers—and write them messages that appear completely normal.

In those chats, they argue that they are in a emergency situation or financial hardshipA medical problem, a robbery, a frozen bank account, or an urgent payment they can't make right then. The key is to create pressure: they use urgent language, demand speed, and try to prevent the potential victim from having time to verify the story through other means.

The National Police emphasize that The requests usually include Bizum or instant transfers as a payment method, taking advantage of the convenience of these tools and how common it has become to send money via mobile phone. In some cases detected in Extremadura, large amounts have been requested, which can reach or exceed 400 or 500 euros, taking advantage of the fact that the person believes they are helping someone close to them.

In Zafra, for example, the following have been recorded Several complaints from neighbors who have seen how friends and family members were deceived through messages that appeared to be from them. The victims explain that the criminals imitated their writing style and used personal data extracted from old conversations to lend more credibility to the story.

This combination of trust, apparent closeness, and urgent messages makes WhatsApp hijacking a particularly effective scam, because It is not based on sophisticated computer techniquesbut in manipulating the emotions and goodwill of contacts.

Warnings from the National Police and Civil Guard

In response to the increase in cases, the Extremadura Police Headquarters has issued videos and messages on social media to alert the public. In these messages, the agents emphasize that receiving a WhatsApp verification code without having requested it should raise serious concerns, as it could be the first step in this type of fraud.

The message from the security forces is very clear: never share Never share WhatsApp codes with anyone, not even if the message appears to be from a trusted contact. Authorities remind the public that these codes are strictly personal and that WhatsApp will never ask for them via chat, email, call, or SMS.

The Civil Guard, for its part, has received a dozen complaints related to similar cases in the Zafra areaand is investigating the possible connection between them. Authorities stress that these types of incidents should not be minimized, as they are often linked to organized networks operating in different provinces and, in some cases, internationally.

Furthermore, both the National Police and the Civil Guard recommend that citizens, if they receive a message from a contact asking for money or urgent help, Always verify the situation through another channel.A phone call, a voice note, or even a message to another known number of yours. Any small doubt is reason enough to stop before sending money.

Police warn of WhatsApp hijacking

Tips to protect your WhatsApp account

Cybersecurity experts insist that the best defense against account hijacking involves Strengthen WhatsApp's security settings and adopt some common-sense guidelines in the daily use of the application.

First, they recommend activating the two step verification From the app settings. This feature allows you to set an additional PIN that will be required when someone tries to register the account on a new device. This way, even if an attacker obtains the six-digit code, they won't be able to complete the process without this second factor.

It's also crucial to be wary of any message requesting codes received via SMS or WhatsApp. No legitimate service will ask for such codes. forward this data If someone tries to contact you through a chat, it's very likely a scam. If you're unsure, the best course of action is not to reply and to verify the information directly with the person involved through another means.

Police forces also advise frequently check linked devices Go to your account settings in WhatsApp to check for active sessions on unknown phones or computers. If you find anything suspicious, log out immediately.

Finally, it's advisable to adopt a proactive approach to the information shared in chats. The more personal data, habits, or routines you share in the app, The more material criminals have to construct believable stories if they manage to access an account.

What to do if you have already been the victim of a WhatsApp hijacking

If, despite everything, someone loses access to their account, authorities recommend acting quickly. The first step is Try to regain control of your profile through the official WhatsApp procedure, requesting the verification code again and, if necessary, restoring the account on the legitimate device.

In parallel, it is fundamental Notify all contacts as soon as possible Share this information so others are aware of what has happened and don't respond to any fraudulent messages sent from the compromised account. A simple warning in groups and frequent conversations can prevent others from falling into the trap.

If recovery through the app doesn't work, you can contact the WhatsApp support service by email, detailing the situation and attaching as much information as possible. In more complex cases, it is advisable to contact the company's data protection officer and, if a satisfactory response is not received, file a complaint with the Spanish Data Protection Agency.

Whatever the outcome, the security forces insist on the importance of always report the facts Report this information to the National Police or the Civil Guard, providing screenshots, messages, transfer receipts, and any other document that may serve as evidence. These reports are key to identifying patterns, locating those responsible, and curbing the expansion of these networks.

Organizations such as the National Cybersecurity Institute (INCIBE) also offer, help and advice services through their cybersecurity helpline, available every day during extended hours. There, they can provide step-by-step guidance on how to proceed and what additional measures to take.

This whole surge in so-called "WhatsApp hijacking" in Extremadura highlights the extent to which our daily lives now depend on messaging applications and how a simple oversight can become a serious problem for both the account holder and their surroundings. The combination of prudence, proper security setup, and a quick response to any suspicion It has become the best tool to stop a scam that, although simple in its approach, can have significant economic and personal consequences.

WhatsApp account theft via video call
Related article:
WhatsApp account theft via video call: how they work and how to protect yourself