How not to get WhatsApp Hacked: Change Your default Voicemail password now!

Pradeek Mohandas
2 min readOct 6, 2018

This method can be used to hack any online account of yours. Loophole was first reported in year 2017 by an Israeli web developer named Ran Bar-Zik. On first week of Oct 2018 Israeli government has reportedly sent out a nation-wide security alert, warning about Whatsapp accounts being hijacked by attackers using this method. The new attack method hijacks WhatsApp accounts using the service providers’ voicemail feature.

It’s pretty simple method, no high fi hack skills required.

Prerequisite : Victim have voicemail activated and didn’t change default password (0000 or 1234 ) .

Step 0 : Make sure victim is not using phone.

Step 1 : Download and install WhatsApp on phone.

Step 2 : Put in victim’s number, enter random number as OTP.

Step 2.1 : Once failed, now go for re-sent OTP via call option.

Step 2.1 : Call goes to victim’s phone, if victim don’t answer, it goes to Voice mail.(OTP recorded in voice mail)

Step 3 : Access victim voice mail via default password and get OTP.

Most mobile telco providers allow remote access to any customer’s voicemail account. For carrier specific details google on how to access voice mail from another phone.

(https://www.quora.com/How-do-you-use-voicemail-in-India-with-Vodafone ,https://www.att.com/esupport/article.html#!/wireless/KM1009121?gsi=gMzYXV4)

Step 4 : Hacked.

Conclusion

If you don’t use voice mail service, deactivate it. If you do use it, keep a proper pin code(PIN can still be brute forced if your telecom don’t provide enough security against brute force).

Reference

  1. https://www.martinvigo.com/voicemailcracker/
  2. https://www.kaspersky.co.in/blog/hacking-online-accounts-via-voice-mail/13944/
  3. https://www.indiatoday.in/technology/news/story/new-whatsapp-hijacking-method-is-using-voicemail-system-to-hack-accounts-1356746-2018-10-05
  4. https://www.theguardian.com/technology/2018/aug/10/hackers-accessing-paypal-via-voicemail-security-expert-says-its-possible
  5. https://www.komando.com/happening-now/481345/hackers-can-use-voicemail-to-break-into-your-online-accounts

--

--