When the scammer gets into your WhatsApp

When the scammer gets into your WhatsApp

Antonio* realized something was wrong with his phone when he tried to access WhatsApp and found he could no longer do so.

At first, he suspected an app glitch, a device issue, or one of those fleeting outages that usually resolve after a restart; however, a far more dangerous situation was unfolding behind this apparent hiccup: someone else had managed to take control of his account and was communicating with his contacts using his name, his photo, and a digital identity that wasn’t his.

While he tried to regain access, his friends and acquaintances began receiving messages from his usual number. The name and profile picture were his, and the tone of the conversation raised no initial suspicions.

The imposter posing as Antonio claimed to need money and proposed an arrangement that might seem common among acquaintances: an immediate transfer followed by a later cash repayment.

Some trusted him and proceeded to transfer funds—sums of 30,000, 40,000, and more—believing they were dealing with a friend, when in reality they were responding to someone who had hijacked his account.

The Ministry of the Interior in Sancti Spíritus province identifies this method as one of the primary ways technology-based scams are carried out. Lieutenant Colonel Sonlit Fernández Montiel, head of Information and Analysis for the Technical Investigation Directorate (DTI) in the region, summarizes it this way: “The most common method currently being used—that is, the modus operandi involving technology—is the hacking of WhatsApp accounts.”

In criminal jargon, this practice is known as *tarjeteo*; essentially, it involves hijacking an account to subsequently use it for fraudulent purposes.

The goal is not merely to gain access to an application. Once inside, the perpetrator finds something far more valuable: a list of people who already have reason to trust the person appearing on the screen.

THE CLICK THAT OPENS THE DOOR

The process may begin with a seemingly routine commercial transaction. A person sees a post on a social media group for an item they need, expresses interest, and contacts the alleged seller. Then, a link appears—purportedly allowing the user to check prices, view product details, or complete a step in the purchasing process.

The link, however, may conceal malicious software. Fernández Montiel explained that “when you access the link, it contains a malicious program that hacks your app; once the scammer manages to take over the account, they start asking for money in your name.”

According to the expert, cases have also been detected where victims hand over personal information or data regarding their phone’s location—details that can facilitate unauthorized access to the account.

The logic behind the scam is simple, which is precisely what makes it dangerous: the criminal identifies someone on social media interested in a product, leverages that interest to initiate contact, and steers them toward a process that appears to be part of the transaction but actually ends up handing over control of their WhatsApp account.

At that point, trust ceases to protect the user and instead becomes the criminal’s primary asset.

A SUPPOSED MSME AND $3,000

The scenario shifts in the case of 65-year-old Ana**, who found a supposed MSME on Facebook specializing in the installation of solar energy kits or packages—complete with panels, batteries, and an inverter.

The proposal addressed a genuine need, which is precisely why it seemed convincing. After making contact via social media, the woman received a call assuring her that the equipment was already en route to her home and that only the payment remained to be made. The amount requested was around 3,000 US dollars, to be sent via Zelle.

The woman was on the verge of completing the transaction but decided to wait.

The promised time passed, and no one showed up.

The equipment never arrived, nor did the personnel for the alleged installation, nor was there any sign confirming that the call actually corresponded to a legitimate business transaction.

The failure to deliver on the promises prompted her to verify the details before paying, thereby avoiding the loss of a substantial sum of money.

This case illustrates a common characteristic of such scams: the victim does not necessarily receive an absurd proposal. On the contrary, the deception often succeeds because it is built around something the victim needs, desires, or considers plausible.

OTHER MODUS OPERANDI

Owen Hernández Rodríguez, head of the provincial DTI unit, emphasized that Sancti Spíritus, Trinidad, Cabaiguán, and Yaguajay are among the most affected areas, though he noted that this type of crime has reached every municipality.

He added that WhatsApp hacking is not the only method used. Social media can also serve as a storefront for non-existent sales, he said. A perpetrator posts an ad for a motorcycle, a house, a piece of clothing, or another attractive item, waits for someone to show interest, and requests an advance payment before any in-person meeting takes place.

The pretext may vary, but the pattern remains the same: a portion of the money must be handed over upfront to secure a transaction that never actually materializes.

The DTI classifies these activities as traditional scams, noting that in social media transactions, “the alleged scammer always asks for an advance payment,” Hernández Rodríguez insisted.

A similar scenario can occur with offers involving foreign currency. Facebook groups are used to propose a deal that appears mutually beneficial: one person transfers Cuban pesos…

…and expects to receive the agreed-upon currency later. The first part of the transaction is completed; the second is not.

WHEN FEAR REPLACES BUSINESS

There is another type of scheme that does not use an attractive product to persuade the victim, but rather plays on fears regarding a family member.

Investigators have detected calls in which the scammer poses as a prison official and informs a relative of an incarcerated person that a fight, a disciplinary infraction, or some form of damage has occurred within the facility. The story might involve a broken television, fan, or other piece of equipment that urgently needs repair.

Then comes the solution: making a transfer to a specific card to prevent the alleged incident from causing further consequences for the inmate.

This method exploits a different psychological dynamic than the fake sales schemes. It does not need to spark interest or promise a financial gain; instead, it aims to instill fear and create a sense of urgency requiring immediate action.

According to available information, this practice was observed primarily late last year and early this year. In some cases, the phone numbers and cards used by the perpetrators are not registered in their names, making it difficult to immediately identify who is behind the operation.

TECH-SAVVY YOUTH

The profile of the perpetrators also requires looking at the phenomenon from a different perspective.

The DTI notes that many of those under investigation are young people with no criminal record who possess knowledge of computing, social media, and digital telephony. They are not necessarily career criminals, but rather individuals capable of using technological tools for illicit purposes.

When asked if this constituted a criminal network, the head of the DTI in Sancti Spíritus made an important distinction: “They are individual scammers.”

This clarification helps explain that the repeated use of the same method does not necessarily mean a single criminal structure is behind every incident. Different perpetrators may resort to similar tactics and exploit similar vulnerabilities.

A PHONE DOESN’T ALWAYS REVEAL THE CALLER’S IDENTITY

…and expects to receive the agreed-upon currency later. The first part of the transaction is completed; the second is not.

WHEN FEAR REPLACES BUSINESS

There is another type of scheme that does not use an attractive product to persuade the victim, but rather plays on fears regarding a family member.

Investigators have detected calls in which the scammer poses as a prison official and informs a relative of an incarcerated person that a fight, a disciplinary infraction, or some form of damage has occurred within the facility. The story might involve a broken television, fan, or other piece of equipment that urgently needs repair.

Then comes the solution: making a transfer to a specific card to prevent the alleged incident from causing further consequences for the inmate.

This method exploits a different psychological dynamic than the fake sales schemes. It does not need to spark interest or promise a financial gain; instead, it aims to instill fear and create a sense of urgency requiring immediate action.

According to available information, this practice was observed primarily late last year and early this year. In some cases, the phone numbers and cards used by the perpetrators are not registered in their names, making it difficult to immediately identify who is behind the operation.

TECH-SAVVY YOUTH

The profile of the perpetrators also requires looking at the phenomenon from a different perspective.

The DTI notes that many of those under investigation are young people with no criminal record who possess knowledge of computing, social media, and digital telephony. They are not necessarily career criminals, but rather individuals capable of using technological tools for illicit purposes.

When asked if this constituted a criminal network, the head of the DTI in Sancti Spíritus made an important distinction: “They are individual scammers.”

This clarification helps explain that the repeated use of the same method does not necessarily mean a single criminal structure is behind every incident. Different perpetrators may resort to similar tactics and exploit similar vulnerabilities.

A PHONE DOESN’T ALWAYS REVEAL THE CALLER’S IDENTITY

A PHONE NUMBER DOESN’T ALWAYS REVEAL THE CALLER’S IDENTITY

Investigations do not necessarily end with identifying the registered owner of a phone number or payment card.

Experts explain that some criminals use phone lines and payment methods registered to other people—including those who have emigrated or passed away. This practice creates a gap between the identity listed in official records and the person actually using the resource to carry out the scam.

Consequently, investigators must piece together communications, financial transactions, and other evidence to determine who is truly behind the operation.

For the victim, however, the complexity of the investigation is often invisible. All they see is a phone number, a profile, or a message that appears authentic.

And often, that is enough to win their trust.

THE SECOND CALL

In a digital scam, the decisive moment may last only a few seconds: the time between receiving a request for money and verifying who is actually behind it. A voice call, a video call, or an in-person check can expose a fake identity, a non-existent product, or a fabricated emergency before it is too late.

Perpetrators of these crimes rely on us acting quickly, because when we are facing a screen, taking the time to verify information can make the difference between trusting the right person and handing over our money to someone we have never met.

Deja un comentario

Aún no hay comentarios. Sé el primero en realizar uno.

También te sugerimos

Radiostation live audio