WhatsApp Account Hijacking: Is a Zero-Click Attack Behind the Spread of Gambling Links?
The security of personal data is under scrutiny again after a user reported their WhatsApp account was suddenly blocked and, upon restoration, began automatically sending online gambling links to contacts. The incident, which went viral on the social media platform Threads, has fuelled speculation about the use of advanced hacking methods known as zero-click attacks.
According to the chronology shared, the victim received a notification stating, “This account cannot use WhatsApp,” on 22 July 2026. Although access was restored through the official review process that evening, the account began disseminating spam messages the following morning. The victim noted they had not clicked on any suspicious links, nor received any unfamiliar One-Time Password (OTP) SMS messages, and was using an iPhone, which is generally considered a closed security ecosystem.
The term zero-click attack refers to a hacker’s ability to exploit a security vulnerability without any interaction from the victim, such as clicking a link or downloading a file. Such vulnerabilities have been recorded in WhatsApp’s history, including a flaw identified as CVE-2025-55177 that affected older versions of the app on Apple ecosystems. However, security experts highlight that genuine zero-click exploits are typically highly targeted and expensive, usually reserved for high-level espionage rather than mass spam campaigns.
To date, no technical evidence has confirmed that the viral case was caused by a zero-click exploit. WhatsApp has also patched the 2025 vulnerability through routine application updates.
Many users assume that without receiving an OTP SMS, their account cannot be accessed by others. However, there are technical loopholes that allow hackers to gain entry without triggering a new SMS code. One common method involves social engineering to obtain the six-digit verification code. Another involves exploiting the WhatsApp Web/Desktop feature, where a device can be linked by scanning a QR code, granting persistent access without logging out the primary phone.
This case demonstrates that recovering an account after a block does not guarantee total security. Users are advised to check the ‘Linked Devices’ menu in their WhatsApp settings to log out any unrecognised sessions.
Meta, WhatsApp’s parent company, continues to intensify its crackdown on organised fraud networks. Throughout 2025 and into mid-2026, millions of fraudulent accounts and advertisements have been removed. In March 2026, a collaboration between Meta, the FBI, and the Royal Thai Police successfully disrupted a scam centre network in Southeast Asia, deactivating 150,000 related accounts. Despite these efforts, individual vigilance remains the first line of defence. Users are reminded never to share verification codes, PINs, or scan QR codes from unknown sources, even if the request appears to come from an official help centre.