What is Social Media Impersonation / WhatsApp Takeover Scam?
Scammers will hack into a victim’s social media accounts or messaging apps such as Whatsapp and use their identity to ask contacts to buy iTunes or other gift cards for them.
In other cases, scammers will reach out to the victim’s contacts to ask for personal and bank details, and One-Time passwords (OTPs) of their online accounts (such as Lazada, Shopee, Qoo10) on the pretext of helping them sign up and/or claim prizes for fake lucky draws, contests purportedly conducted by popular e-commerce sites such as Lazada, Shopee or Qoo10. Once the scammers get hold of these information, they will then proceed to make unauthorised transactions on those accounts.
Social Media Impersonation Scam
In this variation, scammers would either impersonate the victim or hack into their social media account and ask their contacts for their personal details such as mobile number, bank account details, and One-Time Passwords (OTPs) on the pretext of helping them sign up and/or claim prizes for fake contests or promotions allegedly by popular e-commerce sites such Lazada, Shopee, Qoo10, etc.
Whatsapp Takeover Scam
Scammers will use a variety of ways to get victims to share their 6-digit OTP with them. Here are some of the common methods used:
Method 1
A victim will receive a Whatsapp message from a friend or loved one whose account has been compromised. The scammer will use a variety of reasons to trick the victim into sharing their 6-digit Whatsapp verification code, personal or bank details with them. Reasons may range from the need for the information to help them sign up for fake contests or promotions to them sending the OTP to the victim by mistake. Once the victim shares the 6-digit Whatsapp OTP with the scammer, they will lose access to their Whatsapp account.
Method 2
A victim receives a Whatsapp message from a person who claims to be a Whatsapp support staff. The person asks for the victim’s 6-digit OTP for verification. After providing the pin, the victim loses access to their Whatsapp account. We wish to highlight that Whatsapp or their staff will never ask for a user’s 6-digit OTP.
Method 3
The scammer will deliberately fail the verification code process when attempting to install Whatsapp app using a victim’s number on their phone. This then triggers the 6-digit OTP to be sent to the user’s voicemail.
The scammer will then seize the opportunity to access the victim’s voicemail account remotely by using the voicemail’s default PIN provided by telecos to retrieve the victim’s Whatsapp OTP. Once the scammer retrieve the OTP, he will proceed to takeover the victim’s Whatapp account and enabling the 2-step verification to prevent the victim from regaining control over the account.
In all scenarios, scammers will proceed to reach out to more victims through the compromised accounts.
- WHAT YOU SHOULD LOOK OUT FOR...
- WHAT YOU SHOULD DO...
- You have trouble logging into your account
- Unauthorised transactions on your online or bank accounts
- Your phone data bill is larger than usual
- Never agree to an unexpected request from a friend without calling them first to verify if they want you to buy the gift card
- Under no circumstances should you share your One-Time passwords (OTPs) of any accounts with anyone, including your loved ones and friends
- Be extra careful with dealings over mobile message platforms like Facebook Messenger, WhatsApp, Skype or Line
- Verify with official sources such as the company's website or social media accounts to check if the promotion or lucky draw is real
- Enable the Two-Step verification feature for all online accounts. This will add an extra layer of security to your account in case your password is stolen
- If your account has been compromised, inform your contacts immediately of the hack and ask them not to accede to requests for personal information, especially OTPs. You should also make an immediate report to the operator of the messaging app or platform to regain control of your account.
- Change your voicemail account's default pin to prevent scammers from gaining access to your account. If you have no use of your voicemail account, contact your teleco to deactivate it
Recent Related Stories
A PHONE CALL PREVENTED ME FROM GETTING SCAMMED
This scam uses the name of IDA, covid-19 as an excuse that...
Read MoreA PHONE CALL PREVENTED ME FROM GETTING SCAMMED
This scam uses the name of IDA, covid-19 as an excuse that...
Read MoreMY INSTAGRAM ACCOUNT WAS TAKEN OVER BY SCAMMER
Instagram acct was locked by the scammer and msgs was sent to...
Read More