The WhatsApp messenger remains one of the main targets for cybercriminals: even amidst mass blocks of millions of accounts by Meta, perpetrators continue to use the platform to steal personal data and funds. According to RBK-Ukraine, citing Lifehacker experts, 2026 has seen a stable set of seven most common fraud schemes that, in one form or another, affect millions of users worldwide. Understanding the mechanics of each is the first and most important step towards protection, as most attacks are based not on hacking, but on social engineering and the victim's trust.
Hijacking the confirmation code: the entry point to someone else's account
The basic and most frequent scheme remains the interception of the one-time SMS code. The perpetrator enters the victim's phone number on their own device, after which the user receives a message with the WhatsApp confirmation code. Immediately after this, the scammer, masquerading as an acquaintance or "support service," asks the user to forward this code. Transferring the code leads to the complete transfer of the session to the attacker's device and the irreversible loss of access to the account. It is through this vector that all subsequent financial scams described below are opened.
Financial scams: from "emergency situations" to long-term "romance"
After capturing an account, criminals send messages to all contacts demanding urgent money transfers due to an alleged "accident" or "health problem," counting on the victim's panic and haste. In parallel, a longer-term model operates — "romance" scams, where perpetrators gain trust over months through correspondence, then coax funds under the pretext of helping relatives or "profitable investments." Both schemes exploit emotions: fear in the first case and attachment in the second.
Technical masking: fake apps and impersonation of services
A separate layer of threats is related to technical tricks. Users are sent links to download allegedly exclusive versions of the app — "WhatsApp Gold" or "Premium" — clicking on which installs spyware on the device. Another option is impersonating banks, delivery services, tech support, or government agencies: scammers use official logos to demand one-time passwords or remote access to the smartphone. In July 2026, specialized publications recorded an increase in the activity of such "cyber-squatters," hijacking sessions via calls to support.
Gaming vacancies and fake charity
Two other popular vectors are offers for "easy remote earnings" (e.g., liking items) and fundraising for fictional charitable foundations. In the first case, to "confirm the account" or receive subsequent tasks, the victim is asked to contribute their own funds; in the second, they parasitize on empathy, collecting money to help victims of disasters or the seriously ill. Experts note that such schemes are particularly dangerous for vulnerable groups, including minors, who most often fail to recognize manipulative techniques.
Why Ukrainians are in the high-risk zone
For the audience in Ukraine, the listed schemes have acquired special acuteness: scammers deliberately play on the feelings of people who have lost relatives during the war or are waiting for news about missing relatives. Emotional tension makes the victim more susceptible to messages about "urgent help" and "emergency situations," increasing the conversion of attacks specifically in this region. Therefore, digital hygiene here is not an abstraction, but an element of personal security.
Working protection methods: settings you need to do today
To minimize risks, experts recommend a number of specific actions. First, enable two-step verification (Settings → Account → Two-step verification) — this will block access even if the SMS code is stolen. Second, never disclose one-time passwords to anyone. Third, upon receiving messages about financial help from acquaintances, call immediately via a verified number, rather than replying in the chat. Additionally, turn off link previews (Settings → Privacy → Advanced), limit the display of photos and status to the contact list only, and regularly check the list of active sessions in the "Linked Devices" section.