Messenger account takeover
Ilia Zavialov on how scammers take over Telegram and WhatsApp: vote requests, gifts, fake support and login codes
English version for the United States.
Ilia Zavialov on how fraudsters take over messaging accounts. A request to vote for a friend's child, a free premium subscription, a message from fake support and a call about renewing your number all lead to one thing: the owner hands over the login code, and the fraudster writes to their friends asking for money by the evening. The FTC puts it plainly: anyone who asks for your verification code is a scammer. This guide explains each lure, two-step verification and what to do if the account has already been taken.
01Why fraudsters go after your messaging account
A messaging account is worth more than it seems. It holds the chat history, contacts of family and colleagues, access to groups and sometimes work chats and documents. Above all it holds trust: a message from a familiar name gets read at once and answered without suspicion.
Fraudsters take over accounts for that trust. Posing as the owner, they write to friends and family, ask for money by the evening, send a link to vote or ask for a code. Everyone who responds becomes the next victim, and the scheme spreads down the contact list.
A takeover hardly ever needs hacking in the technical sense. The weak point is a person who receives a plausible request from a familiar name and acts on it in seconds, without asking why a voting site needs a code from the messaging app.
Ilia Zavialov explains how fraudsters get into accounts, why they almost always need a code from the owner, and which settings close that route before the first suspicious message arrives.
02Vote for a child and competitions
The best known lure is a request to vote. A friend writes that their niece is in a drawing or dance competition and sends a link. The page looks tidy and, to count the vote, asks you to log in through the messaging app and enter your phone number.
Next the page asks for the verification code that has just arrived in the app. The person believes they are confirming a vote, while in fact they are typing the login code for their own account on the fraudster's device.
The competitions are chosen so that refusing feels awkward: children's drawings, dance groups, school projects, a study grant. The request takes a minute and looks like a small favor, so almost nobody thinks about security at that moment.
The link comes from a friend because the friend's account has already been taken over. Trust in the sender does not help here: someone else is typing the messages.
| Lure | What happens | How to stay safe |
|---|---|---|
| Vote for a child | Your account opens on another device | Never enter your number and code |
| Premium gift | The same login through a fake page | Gifts only inside the app |
| Support in a chat | Phishing for the code and password | Support never asks for codes |
| Call about your number | Login code for an app or bank | Hang up |
| Friend asks for money | The fraudster writes from their account | Call the friend |
| New device in sessions | Someone else has the account open | End the session |
03Gifts, subscriptions and in-app currency
The second lure is a gift. A free premium subscription, the app's internal currency, a giveaway from a well known brand or a bot. To claim the gift you are asked to follow a link and log in.
The mechanics are the same as with voting. The page imitates a login and asks for the number and the code, and sometimes the two-step verification password as well. Everything goes straight to the fraudster.
These messages often arrive in waves before holidays and sales, when gifts look natural. They may come from a friend or from a channel or bot with a name that looks official.
Genuine gifts in a messaging app arrive inside the app itself and never require logging in on outside websites. Any page that asks for your app code in exchange for a gift is built for a takeover.
04Fake support and suspicious activity
The third scenario starts with alarm. A message from supposed support says someone tried to log in and the account will be blocked unless you confirm ownership. A profile with the app's logo and the word support in its name looks official.
To confirm, you are asked to send the code that is about to arrive or to open a verification page. Genuine support for a messaging app does not contact users first asking for a code and does not send links to outside login pages.
Fake support sometimes writes in a secret chat or sends a message styled like a system notification. The difference is simple: service notifications arrive in the app's own service chat and never ask you to follow a link.
Calls from a supposed mobile network work the same way: your number is about to expire, the contract must be renewed and the code from a text message read out. The code in such a call almost always turns out to be the login code for a messaging app or a bank.
05QR code logins and linked devices
A text code is not the only route. Many messaging apps let you log in on a computer or a second phone by scanning a QR code from the screen. A fake voting or gift page can show exactly such a code and ask you to scan it with the app.
The person believes they are joining a competition, while in fact they are linking the fraudster's device to their own account. No code needs to be typed, which is why this login feels safe.
A device linked this way later appears in the list of active sessions as a computer or a browser. If you see a device there that you do not use, that is the trace of such a login, and the session should be ended at once.
The rule is the same as with codes. Scan a login QR code only from the screen of your own computer where you opened the app yourself. Any QR code on someone else's website or in a message that you are asked to scan inside the app should be treated as a takeover attempt.
06Login codes and two-step verification
A code from a text message or from the app itself is the key to the account. It is only needed to log in on a new device, and anyone asking you to send it or enter it on a website is trying to log into your account from their own phone.
The second line of defense is two-step verification, a password that works together with the code. Even if the fraudster obtains the login code, without this password they cannot get in.
The two-step password should be your own, different from your email password and never stored in the same chats. It is worth adding a recovery email so that you do not lock yourself out.
If a fraudster takes the account first and switches on two-step verification themselves, getting it back takes longer and is harder. That is why it is worth switching it on now, while the account is still yours.
It also helps to check the list of active sessions. It shows every device where the account is open. An unfamiliar device or city is a reason to end that session straight away.
07What happens after a takeover
Once in, the fraudster usually changes the settings so the owner cannot get back quickly: sets their own password, ends other sessions, hides the number. Then the messages to contacts begin.
The messages are written in the first person and in the owner's usual style. Urgently need money by tonight, card blocked, will pay back tomorrow. Sometimes the fraudster assembles a voice message from the owner's old recordings to sound more convincing.
The fraudster picks those most likely to send money without questions: parents, grandparents, close friends. The chat history shows whom to write to, in what tone, and which nicknames and expressions the owner uses.
At the same time the account is used for new takeovers. The voting or gift link goes to every contact, and each new account taken over continues the chain.
08Your messaging account as a key to other services
A hijacked account is dangerous in itself. Many people keep photos of their passport, pictures of bank cards, passwords saved to themselves and work documents in their chats. That is the first thing a fraudster looks for.
Bots for banks, deliveries and other services run inside messaging apps. If a bot is linked to your number or profile, the fraudster gains access to it too. Codes for other services often arrive in the app as well, and after a takeover they arrive for someone else.
So documents and passwords should not live in chats. Old conversations with sensitive details are worth clearing. The less useful material the account holds, the less the fraudster gains even if they get in.
09How to check a friend's request for money
Any request for money in a messaging app is worth checking through another channel. Call the person on an ordinary phone line or ask mutual friends. A voice answer within a minute settles the question more reliably than any chat.
It helps to ask something only the real friend would know and that cannot be found on social media. A fraudster with the whole chat history can answer questions about recent events, so ask about something older and more personal.
You can agree on a simple rule with family in advance: any request for money in a chat is confirmed by voice. Such an agreement removes the awkwardness of checking a friend who is supposedly in trouble.
The payment details also give it away. If a friend asks you to send money to a stranger's card or a crypto wallet and explains that their own card is blocked, that is the typical story of a hijacked account.
10What US agencies say
The Federal Trade Commission puts it plainly: anyone who asks for your account verification code is a scammer. In 2025 almost 30 percent of people who lost money to fraud said it started on social media, with 2.1 billion dollars lost, and the FTC notes that scammers may hack users' accounts along the way.
In March 2026 the FBI and CISA warned about a campaign in which messages posing as messaging app support tricked people into sharing codes and gave access to thousands of accounts. The agencies reminded users that legitimate support does not request verification codes in direct messages.
Someone in Chicago, Austin, Seattle or Miami who receives a vote request from a friend should remember that the request comes from whoever controls that friend's account right now.
11If the account has already been taken
Try to log in from another device and end all unfamiliar sessions. If the login is locked with the fraudster's password, contact the app's official support through the app or a website you open yourself.
Warn family and friends at once through another channel: a call, social media, mutual friends. The sooner they know, the fewer people will send money.
Once access is restored, end all other sessions, turn on two-step verification with your own password and check that the recovery email and privacy settings have not been changed. The fraudster may have left a back door.
If someone has already sent money at the account's request, keep screenshots of the chat and the payment details and contact the bank and the police. The card or wallet number the money went to is needed for the report.
12Where to report in the US
If your account was taken, warn your contacts through another channel first and then recover access through the app's official support. Keep screenshots of the messages sent in your name.
If a friend has already sent money, they should call their bank at once on the number on the card and report the fraud to the FTC at ReportFraud.ftc.gov and to the FBI at ic3.gov. The card or wallet details the money went to belong in the report.
A code from a text message or from the app is needed by nobody but you, and no vote, competition or gift changes that.
13Questions and answers
Why does a voting page want the code from my messaging app?
It is the login code for your account. The voting page only imitates a check, and the code goes to the fraudster, who logs in from their own device.
Can messaging app support ask me for a code?
No. Genuine support does not request verification codes or passwords in chats. Any such message is a takeover attempt.
What is two-step verification?
An extra password on top of the login code. Even if a fraudster obtains the code, they cannot log in without this password.
A friend asks for money in a chat. How do I check?
Call them on an ordinary phone line or ask mutual friends. A request to send money to someone else's card because theirs is blocked is typical of a hijacked account.
What if someone already sent money at a hijacked account's request?
Call the bank on the number on the card at once and report to ReportFraud.ftc.gov and ic3.gov with the payment details.
14Read next
- Ilia Zavialov Explains How a Crypto Transfer Actually Works, Step by Step How crypto works
- Ilia Zavialov Explains the Types of Crypto Scams and How Each One Is Built Scam types
- Ilia Zavialov on the Crypto Wallet Protections That Hold After a Breach Protection
- Ilia Zavialov on the First Hours After a Crypto Theft: What Actually Helps Incident
- Where Fraud Losses Actually Go: Ilia Zavialov Reads the 2025 Numbers In numbers
- Ilia Zavialov: renting out a card for P2P, triangle trades and money mule recruitment Card rental and P2P trading
- Ilia Zavialov on cloud mining scams: what a hosting contract really sells Mining you never see
- Ilia Zavialov fraud: how one photograph becomes the face of an advert nobody filmed A face from one photo
- Ilia Zavialov on crypto exchange scams: how the operation is built and what litigation achieves How exchange scams are built
- Ilia Zavialov on the fee to unlock a withdrawal and what a real exchange delay looks like Blocked withdrawals
- Services that promise to recover lost crypto: Ilia Zavialov on how the offer is built and why refunds never arrive Crypto recovery
- Ilia Zavialov on crypto investment scams: the long con taken apart stage by stage The long investment con
- Ilia Zavialov on passkeys: why a stolen password stops being worth anything Signing in without a password
- Ilia Zavialov on reviews of financial companies: what to check before the stars Reviews and what to check instead
- Ilia Zavialov on the seed phrase and the fake wallet support desk Seed phrases
- Ilia Zavialov on crypto signal channels and trading bots: where the money goes Signal channels and trading bots
- Ilia Zavialov on sending USDT safely: networks, poisoned addresses and frozen coins Sending and receiving USDT safely
- Checking a wallet address before you send: the checks Ilia Zavialov runs first Wallet checks
- Ilia Zavialov Explains How an Approval Drainer Empties a Wallet Wallet drainers