At 11:40 on a Tuesday night, a six-digit code arrives by SMS. You did not ask for it. Ninety seconds later a message comes from a number you know — a cousin, a colleague, someone in your building committee — saying they sent a code to your number by mistake and could you please forward it. You do. By midnight your WhatsApp is open on a phone in another city, your contact list is being read, and messages asking for money are going out to two hundred people in your name.
This is the most common account compromise in Bangladesh today, and it does not involve malware, a password, or any technical skill on the attacker's part. It involves one text message and thirty seconds of politeness.
Why WhatsApp specifically
For most Bangladeshi executives, WhatsApp is not a chat app. It is where the board coordinates before a meeting, where a family office instructs its accountant, where a contractor sends the revised quotation, and where a minister's staff circulates the day's schedule. Email is what you use for the paper trail. WhatsApp is where the decisions actually get made.
That makes the account itself more valuable than anything on the phone. An attacker who takes over your number does not need to break encryption or read your old messages — the interesting part is the future, not the past. They inherit your standing. When a message arrives from your number, in your name, inside a group your colleagues already trust, the ordinary checks people would apply to a stranger simply do not run.
The practical consequence: treat your WhatsApp registration the way you treat your bank signature card. Anyone who can register your number can sign as you.
The three ways the code leaves your hands
WhatsApp ties your account to your phone number. To move that account to a new device, the attacker needs the six-digit registration code that WhatsApp sends to your number. They have three reliable ways of getting it.
The forwarded code. The classic. The attacker enters your number on their phone, WhatsApp texts you the code, and they message you — usually from an account they have already stolen, so the name and photo are familiar — asking you to pass on a code that arrived "by mistake". People who would never give a stranger anything will hand a code to a colleague without a second thought. That is the entire attack.
The phishing page. Singapore's police issued an advisory in November 2025 on a variant that skips the conversation entirely. Victims receive an SMS claiming their WhatsApp account has a problem — unverified for too long, due for suspension — with a link to a page that looks exactly like WhatsApp. They enter their number, receive the genuine code, and type it into the fake page. The attacker collects both and registers the account. In that campaign, the hijacked accounts were used to send loan requests to the victim's contacts.
The pairing code. The newest and the least understood. WhatsApp's linked-devices feature lets you run your account on a desktop or a second device, and it offers an eight-digit pairing code as an alternative to scanning a QR image. Security researchers have documented attacks that abuse this — the victim is talked into entering a pairing code, and the attacker's device is silently added to the account. Nothing is stolen and nothing is reset, so nothing looks wrong. Your phone keeps working normally. The attacker simply reads along, in real time, indefinitely.
The rule that covers all three: no code that arrives on your phone is ever meant for anyone else. WhatsApp does not request login codes in chat, support staff do not ask for them, and there is no legitimate scenario in which a friend needs a code that was sent to your number. If someone asks, the account asking you has already been taken.
The PIN almost nobody enables
WhatsApp has a setting that makes the forwarded-code attack fail outright, and most people reading this have not switched it on.
Two-step verification adds a six-digit PIN of your own choosing that must be entered whenever your number is registered on a new device. The attacker can obtain the SMS code by any of the methods above and it will not be enough — without your PIN, the registration stops. It is the single highest-value thirty seconds you will spend on your phone this year.
Open WhatsApp, go to Settings, then Account, then Two-step verification, and tap Turn on. Choose a six-digit PIN that is not your phone unlock code, not your date of birth and not the last six digits of your number. WhatsApp will then ask for an email address. Add one, and make sure it is an address you can actually get into — it is used only to send you a reset link if you forget the PIN, and an account with two-step verification and no recovery email is one forgotten number away from being locked out of your own life.
Do this on every phone in the family and every phone in the office that carries a number people trust. The chairman's PIN protects the chairman. It does nothing for the executive assistant whose account is the one the attacker actually wants.
The door beside the door
Two-step verification protects registration. It does not protect linked devices, and this is where most people's mental model breaks. A PIN stops someone moving your account to their phone; it does not necessarily stop a device that has already been paired from continuing to read everything.
Open Settings, then Linked devices. You will see every browser, desktop and tablet currently attached to your account, each with a last-active timestamp. Look at the list properly. The office laptop you replaced in 2024, the desktop at a company you no longer work for, the browser on a machine in a hotel business centre — all of them are still reading your messages if you never logged them out. Tap anything you do not recognise or no longer use and log it out. Then put a reminder in your calendar to check the list on the first of every month. It takes fifteen seconds and it is the only way you will ever notice an intruder who is being careful.
While you are in settings, two more worth changing. Under Privacy, set your profile photo and "last seen" to My contacts rather than Everyone — an attacker preparing to impersonate you starts by collecting your photo and name. And enable the app lock so WhatsApp itself requires your fingerprint or face, which turns a stolen unlocked phone into a much smaller problem. WhatsApp is also testing a one-tap hardened setting that blocks media from unknown contacts, silences calls from unsaved numbers and disables link previews; if it has reached your version, turn it on.
What the attacker does next
Understanding the payoff explains why this keeps happening to people who are otherwise careful.
- The urgent transfer. Messages go to your contacts, in your voice, asking for a bKash or bank transfer for a plausible emergency. The amounts are small enough not to trigger suspicion and the requests go to dozens of people at once.
- The group foothold. Your account is already inside the company group, the family group and the trade association group. A stolen executive account is a credential for all of them at once.
- The invoice change. For business owners, the highest-value move is a quiet one — messaging a supplier or a client mid-negotiation to update the account number on a pending payment. This is the same fraud that is committed by email, but WhatsApp carries far more trust and almost never gets verified.
- The chain. Your account becomes the tool for the next takeover, because the request to forward a code is convincing precisely when it comes from someone real.
Publicly reported figures put cybercrime complaints in Bangladesh above 178,000 since 2020, and messaging-account takeover sits near the top of the list. Cases are now being filed under the Cyber Security Ordinance 2025 — including one in which a suspect was arrested for hijacking a university vice-chancellor's WhatsApp account to commit fraud. The people being targeted are not the careless. They are the ones whose names carry weight.
Give your finance team one standing rule and put it in writing this week: no payment instruction and no change of account details is ever executed on the strength of a WhatsApp message, regardless of who appears to have sent it. Confirm by voice call to a number already on file — not a number contained in the message.
The first hour after it happens
If your account is taken, speed matters more than anything else. The attacker's window is the period before you get the number back.
- Re-register immediately. Open WhatsApp on your phone and register your number again. You will receive a fresh SMS code. Entering it kicks the attacker's device off — an account can only live on one phone at a time. If you had two-step verification enabled, you will need your PIN.
- Check linked devices the moment you are back in. Re-registering removes the attacker's phone but you should confirm nothing else remains attached. Log out everything you do not recognise.
- Turn on two-step verification now, if it was not on before. This is what stops them simply repeating the attack an hour later.
- Warn your contacts on another channel. A message from your own account saying "I was hacked" is worth very little — post it to a group by voice note, send an SMS, call the ten people most likely to be asked for money.
- Email WhatsApp support from the address on the account with the sentence "Lost/Stolen: Please deactivate my account" and your number in full international format. This freezes the account if you cannot re-register.
- File the complaint. Report through the national cybercrime portal at
cybercrime.gov.bd, or in person to the Cyber Crime Unit of the CID at the CID Complex in Malibagh, Dhaka. Bring screenshots, the time the code arrived and the number that contacted you. If money moved, file at your local thana as well — the bank or MFS provider will usually require a General Diary number before they will act on the receiving account.
Do the first three from the phone in your hand before you do anything else. The complaint can wait twenty minutes; the account cannot.
The five minutes that prevent all of this
None of the defences here require a security background, a product to buy or a consultant to install anything. Tonight, on your own phone: switch on two-step verification with a PIN you have never used elsewhere, add a recovery email you can access, clear out linked devices, and set your profile photo to contacts only. Then send this to the three people whose accounts would cause you the most damage if they were taken — your executive assistant, your finance lead, and whoever in your family everybody trusts.
A code sent to your phone is only ever for you. The moment someone else asks for it, the conversation is already an attack.