Skip to content
Secureweb Prespa dark mode logo
Secureweb

Secure Your Website Now

  • Home
  • Contact
  • Blogs
  • Free Scan
    • Free Security Test
    • Free Website Scanner
  • en
    • ar
    • fr
    • en
  • Start Now

WhatsApp Hack Morocco: Why Hijacked Accounts Are Messaging Friends for Money

WhatsApp hack Morocco alert: hijacked accounts are asking contacts for money. How it works, and the one setting that shows if you are affected.

blogs News
Post read time 6 min read

On Monday 1 and Tuesday 2 September 2026, a wave of hijacked WhatsApp accounts began messaging Moroccan contacts asking for money. If you use WhatsApp in Morocco, there is a good chance you have already seen one of these messages, or will soon. This WhatsApp hack in Morocco spreads through ordinary chats rather than spam numbers, which is exactly why it works.

The script is consistent, written in Darija: a “transfer problem” or “daily limit reached“, asking the contact to send 4,800 dirhams (some reports say 2,850), with a promise to repay “tomorrow morning”. The money is not even meant for the friend: it goes to a third party’s bank details in the message.

Nobody broke WhatsApp’s encryption or breached its servers. The attacker simply borrowed a real account with permission obtained under false pretences, which is why the message really does come from your friend, and why it works so well.

WhatsApp hack Morocco: a phone chat screen showing a hijacked contact asking for an urgent money transfer

WhatsApp hack Morocco: why it actually works

Several account owners caught up in this wave report that the money-request messages sent from their account never appear in their own chat history. That detail matters: it is not the signature of malware on a phone. It is the signature of a second, separate session logged into the same account from somewhere else.

Moroccan outlets thevoice.ma and akhbarona both covered the wave, quoting security expert Tayeb El Hazaz, who explained that no breach of WhatsApp’s servers is needed and advised checking the app’s Linked Devices list immediately.

To be precise about what is confirmed: as of 2 September 2026 there has been no official statement from the DGSN, CNDP or DGSSI about this specific wave. What we know comes from user reports and Moroccan press coverage, not a confirmed authority statement, and this article treats it accordingly.

How the pairing-code trick works

The mechanism is a technique researchers call GhostPairing, documented by Gen Digital researchers Luis Corrons and Martin Chlumecký on 15 December 2025, first seen in Czechia. It resurfaced in August 2026 as a “vote for my friend” contest lure, covered by Malwarebytes and Infosecurity Magazine. The chain:

  1. A link arrives from an already-hijacked contact: a supposed photo of you, or a vote for someone’s child, dog or dance school.
  2. The link opens a lookalike page imitating a Facebook photo viewer or voting site. Domains seen include photobox[.]life, postsphoto[.]life, yourphoto[.]life and fotoface[.]top; some hide behind the genuine wa.me domain.
  3. The page asks for your phone number, “to view the photo” or “confirm your vote”.
  4. The attacker’s server feeds that number into WhatsApp’s own legitimate “link a device” feature.
  5. WhatsApp generates a real 8-digit pairing code, meant only for the account owner.
  6. The fake page shows you that code and tells you to type it into WhatsApp “to confirm”.
  7. You do it, and the attacker’s browser becomes a trusted linked device on your account.

From there the attacker reads your synced chats, receives new messages in real time, and messages your contacts as you, since WhatsApp allows up to four linked devices. No password is stolen, no SIM swap happens, no software flaw is exploited, and encryption is not broken. As Gen Digital puts it, “everything happens inside the boundaries of the feature set that WhatsApp intended.”

There is no reset email or failed-login alert, so this WhatsApp hack in Morocco can sit undetected for days. It also spreads through real friendships rather than random spam, which is exactly why it feels trustworthy.

The older trick: stealing the 6-digit code

An older method still circulates: an attacker starts registering WhatsApp on your number, you get WhatsApp’s genuine 6-digit SMS code, and an already-hijacked “friend” asks you to forward the code sent to you “by mistake”. Hand it over, and they register your account on their device and lock you out. Unlike the pairing-code method, this one is noticeable immediately, since you lose access. A two-step verification PIN blocks it outright.

What this WhatsApp hack is not

Despite a theory circulating in Moroccan media, there is no evidence a recent WhatsApp update introduced the vulnerability behind this wave, because no vulnerability is being exploited.

The one genuine recent flaw, CVE-2025-55177 (an authorization gap in linked-device sync on WhatsApp for iOS and macOS, chained with Apple’s CVE-2025-43300), was a patched zero-click bug used in narrow, targeted attacks on journalists and human rights defenders, not a mass money campaign. It was fixed in WhatsApp for iOS 2.25.21.73 and Mac 2.25.21.78. WhatsApp’s encryption was never defeated here.

Diagram of the pairing-code chain behind the WhatsApp hack Morocco is seeing, step by step

Morocco is not the only target

This did not begin in Morocco. GhostPairing’s infrastructure is language-agnostic and the campaign started in Czechia in late 2025; the “vote for my friend” wave in August 2026 was international. Lebanon reported its own WhatsApp account-theft wave that same month.

The underlying idea, a trusted contact asking for urgent money, is old and global. In Australia, the “Hi Mum” scam cost victims over AU$7 million in its first year, with 1,150+ victims and AU$2.6 million lost in the first seven months of 2022 alone, per the ACCC.

In the UK, Action Fraud logged 1,235 reports and over £1.5 million in losses between February and June 2022; Lloyds Banking Group reported a 2,000% year-on-year surge, averaging £1,950 per victim. Newer variants add AI-cloned voice notes, so “it sounded just like them” is no longer proof.

What is specifically Moroccan here is the packaging: Darija phrasing, dirham amounts, local transfer and cash-pickup rails, and a large pool of leaked Moroccan phone numbers and personal data already circulating, which eases targeting. Hespress reported in April 2026 on exactly this kind of leaked data fuelling online fraud in Morocco, a pattern SecureWeb also covered in its reporting on a separate Morocco data leak.

The number every Moroccan WhatsApp user should know

Here is the most useful fact in the whole story, from a WhatsApp census by researchers at the University of Vienna and SBA Research (arXiv 2511.20252, to be presented at NDSS 2026). Morocco ranks 23rd worldwide with 32,954,817 active WhatsApp accounts, about 87.8 per 100 inhabitants: 89% Android, 11% iOS, and 54.4% with a public profile photo, itself useful raw material for attackers building lures.

The figure that turns advice into a hard rule: only 5.6% of Moroccan WhatsApp accounts use a linked device at all. Put differently, roughly 94 out of every 100 Moroccan users should see a completely empty list under Settings, then Linked Devices. For almost everyone in Morocco, anything in that list is suspicious by default.

The same study found Meta fixed an underlying rate-limiting weakness after disclosure, and that roughly half the phone numbers from the 2021 Facebook leak are still active on WhatsApp today.

Infographic showing Moroccan WhatsApp users how to check linked devices to avoid the WhatsApp hack Morocco is seeing

What to do right now

  1. Open Settings, then Linked Devices, today. Log out of anything unfamiliar. Remember the 5.6% rule: for most Moroccan users, that list should be empty.
  2. Turn on two-step verification (Settings, Account, Two-step verification): a 6-digit PIN plus a recovery email.
  3. Never share a code. WhatsApp’s 6-digit SMS code and 8-digit pairing code are for you alone; nobody legitimate, including WhatsApp, will ever ask for either.
  4. Never enter your phone number on a page reached from a WhatsApp link. See our guide on how a single link can compromise you.
  5. Verify money requests by voice, calling a number you already had, never one in the message. Ask something only they could answer; AI voice cloning defeats voice recognition alone.
  6. Treat “send it to this other account” as a stop signal by itself. Real friends do not route repayment through a stranger’s bank details.
  7. If your account is taken over, reinstall WhatsApp and re-register with the SMS code; this logs the attacker out. Then warn your contacts, since your account has been messaging them.
  8. If you already sent money, contact your bank immediately: speed matters. Beware of follow-up calls claiming to be your bank, a tactic we covered in our piece on Bank Al-Maghrib phishing.
  9. Report it via the DGSN’s cybercrime portal, e-Blagh, live since June 2024, which accepts 24/7 reports, including anonymously, from Morocco or abroad.
  10. Warn the least tech-confident people in your family first. This fraud converts trust into money, and older relatives are consistently hit hardest.
Red flags checklist for spotting a WhatsApp hack Morocco money-request message on a phone

None of this needs special skill: one settings screen, one phone call. The attackers are not breaking anything; they are borrowing your account with permission obtained under false pretences, and taking that permission back is enough to stop it. For more on recognising manipulative messages, see our guide to spotting phishing attempts, and on account security more broadly, how to build a strong password habit. For reporting rights in Morocco, see our overview of Moroccan cybersecurity law.


Stay Updated With Cyber News

Follow Secureweb

  • WhatsApp
  • Facebook
  • YouTube
  • Instagram

Posts navigation

< Morocco Data Leak: What the Jabaroot Claim Means
Morocco SMS Scam: The Fake Traffic Fine Text and How to Spot It >

Related Posts

Invoice Fraud in Morocco: E-Invoicing Scams in 2026
blogs Guides
Invoice Fraud in Morocco: E-Invoicing Scams in 2026
Morocco SMS Scam: The Fake Traffic Fine Text and How to Spot It
blogs News
Morocco SMS Scam: The Fake Traffic Fine Text and How to Spot It
Morocco Data Leak: What the Jabaroot Claim Means
blogs Threat Intelligence
Morocco Data Leak: What the Jabaroot Claim Means

secureweb

Hackers knock. We don’t answer. Join SecureWeb and keep your door shut.

Need Help?

Contact

Reviews

Get Started

Cybersecurity Consulting

Learn More

Services

Pricing

Free Cybersecurity Tools

Learn Cyber security

Get in Touch

contact@secureweb.ma

Stay Informed:

© Copyright 2026 secureweb. All rights reserved

Free Security Assessment




    Secureweb Premium Plan

    Say goodbye to hackers




      Premium Scanner




        Secureweb Basic Plan

        Ideal for small websites