Let's talk: editor@tmv.in
Indian cyber agency flags WhatsApp ‘GhostPairing’ account Hijack

Indian cyber agency flags WhatsApp ‘GhostPairing’ account Hijack

Yellarthi Chennabasava
December 21, 2025

India’s national cybersecurity agency, CERT-In , has issued a warning about a high-severity vulnerability in WhatsApp’s device-linking feature that allows attackers to gain near-complete control of user accounts. The flaw, dubbed GhostPairing , enables cyber criminals to hijack accounts without requiring passwords or SIM swaps.

According to CERT-In’s advisory, the attack begins when victims receive a message, often appearing to come from a trusted contact, with text such as “Hi, check this photo” and a link showing a Facebook-style preview. Clicking the link directs users to a fake Facebook or content viewer page , which prompts them to “verify” by entering their phone number.

By exploiting WhatsApp’s “link device via phone number” feature, attackers generate a pairing code that looks legitimate. Once the victim enters their number, the attacker’s device is secretly added as a trusted linked device , giving them the same level of access as WhatsApp Web.

CERT-In warned that attackers can then read existing and real-time messages , view photos, videos, and voice notes , and send messages impersonating the victim to contacts and group chats. The linked device can remain hidden, making the attack difficult for victims to detect .

The agency classified the threat as high severity , highlighting that it bypasses traditional safeguards like passwords and SIM verification, relies on social engineering, and can compromise privacy and communications at scale.

CERT-In recommended that users remain vigilant, avoid clicking suspicious links even from known contacts, and never enter phone numbers on external sites claiming to be WhatsApp or Facebook.

Experts say that preventing such attacks in the future would require stronger authentication for device linking , such as two-factor verification or in-app/bio-metric confirmation, and alerts when new devices are added . WhatsApp could also enhance its anti-phishing measures to block fake login pages, while security agencies could run awareness campaigns to educate users about phishing tactics.

Additionally, regular security audits and real-time activity monitoring could help users quickly detect and revoke unauthorized device access. CERT-In’s advisory underscores the importance of combining technical safeguards, proactive monitoring, and user awareness to counter sophisticated cyber threats like GhostPairing.

A response from WhatsApp to the advisory is awaited.