Some risks of using WhatsApp and other closed messaging applications
- Being compromised via the app, in the following different ways:
- Financial fraud: receiving a message from someone on a number you don’t recognise claiming to be a family member or friend, informing you they have changed their phone number. Having convinced you that this is authentic, they then request money to solve ‘a problem which needs payment’, never to be heard of again. This is known as the ‘Friend in Need’ or ‘Mum and Dad’ scam.
- Data theft: receiving a text message purporting to come from WhatsApp, containing a login code, which is a two-factor authentication (2FA) code proving you are in possession of the phone number. You then receive a WhatsApp message purporting to be from a family member or friend along the lines of “I accidentally sent you my WhatsApp login code but have now deleted it, could you send it back to me please?” They can then log into your account as you, exclude you from accessing it and create havoc impersonating you. They can also use the same scam to hack everyone in your contact list.
- Identity/data theft: receiving a message allegedly originating from a retailer or other organisation, which is an advertisement for an attractive offer, giveaway or other incentive. The message includes a link that takes you to a set of questions, encouraging you to supply personal data. You are then also encouraged to share the link with your contacts for a chance to take advantage of the same offer.
- Your data being shared with other organisations. For example, in 2020 WhatsApp, which is owned by Facebook’s parent company Meta, updated its terms to allow data sharing between the two, in certain countries but not the UK.
- Messages and calls being intercepted if encryption is not used.
- Some closed messaging apps, including WhatsApp, collect metadata information about you, such as who you message (gained from your contacts list), when and for how long, as well as your device, phone number and IP address.
Safe use of WhatsApp and other messaging apps
- If you get a message requesting money, check it isn’t a scam by calling the person it claims to come from on the original number you know to be correct.
- Never reveal security codes for any accounts to anybody, however genuine the message seems.
- If you receive a message asking for your WhatsApp or other messaging app verification code, ignore and delete it. If you find out that your account has been compromised, try to log in and remove the illicit user. Warn the contact whom the message claimed to come from, that they have been hacked.
- WhatsApp features end-to-end encryption – which means your private messages and calls are scrambled – by default to maintain your privacy. However, with some other closed messaging apps you need to manually select encryption.
- If you are concerned about your usage metadata being collected, set up a VPN (virtual private network) on your device to prevent this.
- We recommend you specify the optional two-factor authentication feature, requiring a PIN to verify your phone number on any device. Find out how here.
- Note that messages are not stored on WhatsApp servers after being delivered to the recipient. If undelivered, messages are automatically deleted from the server after 30 days.