Visualização normal

Antes de ontemMalwarebytes
  • ✇Malwarebytes
  • WhatsApp account takeover scam asks you to “vote for my friend”
    A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely. It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click. We spotted the scam showing up in o
     

WhatsApp account takeover scam asks you to “vote for my friend”

4 de Agosto de 2026, 03:22

A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely.

It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click.

scam examples

We spotted the scam showing up in our anonymized Scam Guard submissions. WhatsApp is popular with cybercriminals, and the third most common channel where we see scams delivered, behind websites and email.

At first glance, nothing seems out of the ordinary. But the link doesn’t lead to a real voting page. Instead, it redirects to a page that appears to be related to WhatsApp, often involving the legitimate wa.me domain, where the real attack begins.

This scam works because it combines trust and curiosity. If the message comes from someone you know, you’re far less likely to question it and far more likely to follow through to do them a small favor.

In some versions of the scam, the link redirects you into a flow that abuses WhatsApp’s legitimate “Linked devices” feature.

Depending on your device, you may see what looks like a WhatsApp page prompting you to continue, verify, or connect. In some cases, the victim is guided through steps that resemble setting up WhatsApp Web or linking a new device.

The goal is to trick you into authorizing a new linked session that gives the attacker access to your WhatsApp account.

A typical flow looks like this:

  • You tap the “vote” link.
  • A page opens that appears to be related to WhatsApp.
  • You’re prompted to complete a connection or verification step.
  • That action links your WhatsApp account to a device controlled by the attacker.

Some versions of this scam take a less direct route. Instead of sending victims to a fake voting page, the message or the landing page instructs victims to open WhatsApp, go to “Connected Devices,” and enter a code supplied by the scammer.

These scammers aren’t trying to steal your password. Instead, they’re tricking you into giving them access to your account yourself.

How WhatsApp’s Linked devices feature works

WhatsApp allows you to use your account on multiple devices, including a web browser or desktop app, through its Linked devices feature.

Normally, this works by:

  • Opening WhatsApp on your phone.
  • Scanning a QR code displayed on another device.
  • Approving the connection.

Once linked, that secondary device can:

  • Read your messages.
  • Send messages as you.
  • Access your ongoing conversations in near real time.

But if you follow those steps, you could be giving an attacker access to your messages, contacts, and ongoing conversations.

This is a legitimate and widely used feature, especially for WhatsApp Web. But in this scam, attackers abuse it to gain the same level of access without your informed consent.

Once a scammer links their device to your WhatsApp account, they can continue accessing your conversations until that device is removed.

From there, they can:

  • Send messages pretending to be you, including forwarding the same scam to your contacts.
  • Ask friends or family for money or sensitive information.
  • Read your chats and harvest personal information.

Because this doesn’t involve a traditional login, there are no obvious signs like password reset emails or failed login alerts. The attacker’s device simply appears as another linked session on your account.

Unless you check your linked devices, the compromise can go unnoticed for quite some time.

How to stay safe

Scams like this rely on quick reactions and misplaced trust. A few simple precautions can make a big difference:

  • Be cautious with unexpected “vote” or “support” requests, even if they come from someone you know.
  • Don’t click unexpected links, especially if you’re immediately asked to verify, connect, or link your WhatsApp account.
  • Never follow instructions to link devices or scan QR codes unless you initiated the action yourself.
  • Regularly review your linked devices in WhatsApp (Settings > Linked devices) and log out of any you don’t recognize.
Linked devices on WhatsApp. Log out of any you don't recognize.

If you suspect your account has already been compromised, immediately log out of all linked devices and warn your contacts so they don’t fall for follow-up scams.

Indicators of Compromise (IOCs)

These domains are typically short-lived and quickly replaced. However, they may help you recognize similar scams if you encounter them:

ngdance[.]fun/vote
fokindenfo1[.]lol/home/voteeeg3
stardancer[.]fun/home/voteCZ03
thebestscollato[.]top/home/scolatica
vatiter[.]click/home/voteerok
megadencer[.]top/home/eng10


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

  • ✇Malwarebytes
  • Stolen iPhones could soon be worth a lot less to thieves
    The UK’s Metropolitan Police has reached an agreement with Apple designed to make stolen iPhones harder to resell and less attractive to thieves. The approach combines stronger technical protections with direct data sharing between Apple and law enforcement. In 2023, about 1.4 million mobile phones were stolen in the US alone. London is reportedly one of the worst cities for phone theft, with around 200 devices stolen every day.  As part of this effort, Apple has strengthened its Stolen De
     

Stolen iPhones could soon be worth a lot less to thieves

12 de Junho de 2026, 11:03

The UK’s Metropolitan Police has reached an agreement with Apple designed to make stolen iPhones harder to resell and less attractive to thieves. The approach combines stronger technical protections with direct data sharing between Apple and law enforcement.

In 2023, about 1.4 million mobile phones were stolen in the US alone. London is reportedly one of the worst cities for phone theft, with around 200 devices stolen every day. 

As part of this effort, Apple has strengthened its Stolen Device Protection feature in iOS 26.4, making it harder for thieves to change security settings, factory‑reset a stolen iPhone, or set it up as new.

Previously, thieves with your passcode (or who snatched your iPhone while it was still unlocked) could factory reset it, wiping your account and making the device look new for resale. Stolen Device Protection blocks this, requiring biometric authentication, not just a passcode, to make critical changes.

The Met has started sharing identifiers for reported stolen devices with Apple. In return, Apple can provide data on whether those devices later attempt to reconnect to a network or attempt to be reactivated.

Police say this gives them a better picture of what happens to stolen devices: Are they being switched back on locally? Shipped abroad? Broken down for parts?

Met Police Commissioner Sir Mark Rowley said Apple believes it has “cracked” the engineering problem. Phone thefts in London have since fallen 18% year-on-year, with Westminster (the capital’s worst-affected borough) down 45.8%.

Given the early signs of success, the Met is pressing for broader changes.

The Commissioner has written to the Home Secretary asking for laws that would require all phone manufacturers and mobile operators to share information about stolen devices and implement measures that make stolen handsets unusable. 

As part of that effort, the Met has explicitly said that Samsung and Google are also improving device security to address phone theft, suggesting this will become an industry‑wide expectation rather than an Apple‑only initiative.

Possible pitfalls

From a privacy perspective, it’s important to keep an eye on what data is shared, and who can see it.

Reports so far suggest that Apple and the Met are exchanging device identifiers and high‑level information about whether a stolen phone has attempted to reconnect or be reactivated. In theory, that sounds narrow and purpose‑bound: device X was reported stolen, later tried to come online in country Y, at time Z. There is no public indication that content, contacts, or location histories are being handed over wholesale.

There’s also a risk of someone reporting your phone as stolen. If a device is incorrectly marked as stolen, the protections designed to stop thieves could lock an innocent user out, turning a valuable asset into a brick. Without transparent appeal mechanisms, this is a notable concern.

The measures could also create challenges for recycling initiatives, legitimate repair shops, and refurbishers. They may face additional hurdles when diagnosing, restoring, or reselling devices if anti-theft protections become more restrictive.

Stay safe

Make sure your phone is protected with a strong passcode and biometric security, such as Face ID or a fingerprint.

Enable Apple’s Find My feature, or the Android equivalent, and make sure it is linked to a strong account password.

Keep lock screen notifications to a minimum so thieves cannot quickly access your sensitive information if they get hold of your device.

When buying a used phone, use a reputable seller and make sure the device has been reset by its owner. Complete the initial setup process with the seller present to confirm the phone isn’t locked to someone else’s account or reported stolen.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

❌
❌