CYBER WELFARE

Protect your Digital Privacy

Messaging account takeover: how someone ends up writing in your place

A message arrives from your number, with your photo and your name. The person who receives it has no reason to doubt it: they know you, and they think they are replying to you.

That is what messaging account takeover means: someone gains control, full or partial, of one of your chat, email or social media accounts, and uses it to write to your contacts as if they were you. The techniques vary, but they all aim at the same target: the trust other people place in your name.

This post describes the most common ones, one by one. It is the threat-side companion to the recommendation on checking messages sent in your name: when a contact tells you about a message you do not recognise, it is worth looking into.

One useful clarification: this post explains how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

It is Sunday afternoon. You get a message from a friend in your gym group: “Sorry, I sent you a six-digit code by mistake, could you send it back to me? I need it straight away.”

The code really has arrived on your phone. It looks like a tiny favour, so you forward it.

A few minutes later your chat app signs you out, and the same message starts going out from your number to your entire address book. Your friend, it turns out, had received the same request an hour earlier, “from” someone else she knew.

Nobody forced anything. Every step happened through a kind gesture, made in good faith.

Why an account that writes in your name is worth so much

All the techniques that follow share one thing: they do not need to convince strangers, they only need to borrow a voice your contacts already recognise.

A message from an unknown number is read with suspicion; the same message from the number of a relative or a friend is read with trust, and often in a hurry. That is why a compromised account becomes a channel for requests for money, infected links and fresh attempts to take over other accounts.

An infected link is a link that leads to a fake page or downloads malware, meaning software built to spy on you, steal data or take control of the device.

1. The fake “I sent you a code by mistake”

In plain terms. Someone asks you to forward a code that has just arrived on your phone, with a plausible excuse. That code is what activates your account on another device.

How it works. Many chat apps, when they are installed on a new phone, send a verification code to the number linked to the account: a short string of digits, valid for a few minutes, that proves you are the owner. Whoever wants the account starts the registration with your number and then asks you for the code, pretending it was a mistake or part of a competition, often from the already compromised account of someone you know.

Why it works. The code looks like worthless information, and the request comes from a familiar face.

Possible impact. Loss of your chat account, “urgent” messages and requests for money sent to your contacts, access to your groups.

What should make you suspicious. A code you did not request, followed by someone asking you for it; the app signing you out without warning.

How to protect yourself. A verification code is never shared with anyone, not even with people you know. Where it exists, turn on your chat app’s two-step verification PIN: a second code you choose yourself, which is needed to register the account on a new phone.

2. Cloning through a linked device

In plain terms. Your account stays on your phone, but someone gets a copy of it on another device, and from there reads and writes in silence.

How it works. Many messaging apps let you use your account from a computer as well, linking it through a QR code, a square pattern of dots that the camera reads to pair the new device. If someone manages to get you to scan their QR code, presented as an invitation or a check, or has your unlocked phone in their hands for a few moments, their device stays linked to your account.

Why it works. There is no visible theft: your phone works just as before, and the copy can stay active for a long time.

Possible impact. Your conversations read by someone else, messages sent to your contacts and then deleted, access to photos and documents.

What should make you suspicious. Messages marked as read that you do not remember opening, replies you did not write, linked devices you do not recognise.

How to protect yourself. Only scan a QR code for linking when you are the one starting the process, on your own computer. Check the list of linked devices on messaging apps from time to time and remove any you do not recognise.

3. SIM swapping

In plain terms. Someone persuades your mobile network operator to move your number onto a SIM card they control. From that moment on, calls and text messages meant for you go to them.

How it works. Replacing a SIM is a legitimate service, designed for people who lose or break their phone. The attacker poses as you, using personal details gathered beforehand, and once they have the number they receive the verification codes for your chat apps, your email and, sometimes, your bank.

Why it works. Your phone number is the recovery key for a great many accounts.

Possible impact. Several accounts lost at once, unauthorised financial transactions.

What should make you suspicious. Your phone suddenly loses signal; confirmations arrive for password changes you did not request.

How to protect yourself. Limit the personal details you make public, ask your operator whether protections exist against SIM changes, and prefer an authenticator app or a passkey to text messages. A passkey is a way of signing in with your device and a fingerprint, face or PIN. If your signal disappears for no reason, contact your operator from another phone.

4. Credential phishing

In plain terms. A convincing message takes you to a page imitating a real service, where you type your password and codes and hand them over to whoever built the page.

How it works. Phishing arrives by email, text message or chat. It can imitate the service itself, a fake technical support team, or a known contact sending you a link “to vote”. The fake page asks for your credentials, meaning your username and password, and often for the verification code that has just arrived as well.

Why it works. It plays on urgency or curiosity, and with the password and the code in hand the attacker gets in straight away.

Possible impact. Access to your email, social media or chat account; from there, more phishing messages sent to your address book.

What should make you suspicious. Unjustified urgency, web addresses almost identical to the official ones, a link from a contact with wording that does not sound like them.

How to protect yourself. Only sign in to a service from the app or the address you normally use, never from links you have received. Turn on multi-factor authentication, an extra check on top of the password, preferring methods that cannot be copied onto a fake page: the guide to protecting accounts with a second factor explains how.

5. Malware on your phone

In plain terms. A malicious app installed on your phone reads your messages, codes and notifications, and can send messages in your place.

How it works. Malware often arrives with an app downloaded from outside the official stores, or through a link asking you to “update” something. It then asks for wide-ranging permissions, such as access to text messages, to notifications or to accessibility services: features designed to help people use the screen, which can read and tap on the user’s behalf.

Why it works. Everything happens from your real phone, so no “new device” check is ever triggered.

Possible impact. Automatic messages to your address book with a link that spreads the same malware, theft of banking codes.

What should make you suspicious. A battery that drains for no reason, apps you do not remember installing, contacts receiving links from you. For more on this: spotting the signs of malware on your phone.

How to protect yourself. Install apps only from the official stores, keep the phone’s operating system up to date, and refuse permissions that have no reason to exist.

6. Hidden forwarding rules in your email

In plain terms. Whoever got into your mailbox sets up a rule that copies or diverts your messages to another address, and leaves it running.

How it works. A forwarding rule is an automatic instruction in your mailbox, such as “forward these messages to another address” or “move them to the bin”. The attacker creates it after getting in through phishing or a reused password: that way they keep receiving your email even after you change your password, and they hide the replies from contacts asking “is this really you?”.

Why it works. The rule stays active even once the original access has been closed, and it sits in a menu that hardly anyone opens.

Possible impact. Conversations watched by someone else, emails in your name with altered bank account details, security alerts made to disappear.

What should make you suspicious. Replies you never receive, emails that end up in the bin on their own, rules you did not create.

How to protect yourself. After any suspicion, as well as changing your password, check your forwarding rules, your filters and the list of active sessions, meaning the devices the account shows as signed in at that moment, and close them. Turn on account login alerts.

7. Messages that spread from one contact to the next

In plain terms. Every compromised account is used to compromise others: the message you received from a friend is sent, from your account, to your friends.

How it works. The fake code, the phishing link or the infected app go out from a compromised account to its address book and groups, and whoever falls for it becomes the sender of the next round.

Why it works. Every step comes from a trusted person, and groups multiply the number of recipients.

Possible impact. Embarrassment, money lost by friends and relatives, work or family groups drawn in.

What should make you suspicious. The same odd message “from” different people, contacts asking whether it was really you.

How to protect yourself. Warn your contacts as soon as you notice a message that is not yours, through a different channel, and do not act on unusual requests without checking by voice first.

Summary table

AttackMain riskWhat should make you suspiciousEffective defences
Fake code sent by mistakeChat account registered on another phoneA code you did not request, followed at once by a request for itNever share codes, two-step verification PIN
Linked deviceA silent copy of your accountMessages read or sent that you do not recogniseChecking linked devices, scanning QR codes only when you start the process
SIM swappingYour phone number moved to someone elseSignal suddenly lostOperator protections, a second factor not based on text messages
Credential phishingPassword and codes handed to a fake pageUrgency, addresses that look similar but are not the sameSigning in from the usual app or address, MFA
Malware on your phoneMessages and codes read from your own deviceBattery drain, unknown apps, texts sent without youOfficial stores, updates, fewer permissions
Hidden forwarding rulesEmail watched even after a password changeMissing replies, rules you did not createChecking rules, filters and active sessions
Spreading between contactsThe chain grows longer in your nameThe same message from different sendersWarning contacts, checking through another channel

What they have in common

Seven different techniques, three defences that cut across almost all of them:

  1. Your codes stay yours — a verification code, a PIN or a QR code for linking is never shared, not even with people you know.
  2. A second check on your accounts — a two-step verification PIN, MFA (multi-factor authentication) and login alerts keep working even when something has already slipped through.
  3. Verification through a different channel — a phone call or a question asked in person takes apart most of the unusual requests that arrive by chat.

The digital resilience self-assessment helps you see which of these defences you already have in place. For the first clues, there is the guide to the signs of messages you did not send.

Protection checklist

  • ☐ No verification code is shared, with anyone, for any reason
  • ☐ The two-step verification PIN is on for every chat app that offers it
  • ☐ MFA is on for email, social media and any account linked to your phone number
  • ☐ The list of linked devices is checked from time to time
  • ☐ QR codes for linking are scanned only when you start the process yourself
  • ☐ Apps are installed only from the official stores, with limited permissions
  • ☐ Email forwarding rules and filters are checked after any suspicion
  • ☐ Unusual requests from contacts are verified through another channel

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that a messaging account is taken over above all to exploit the trust of your contacts
SkillsRecognising the mechanism of each technique from the signals it leaves
Secure BehaviourNot sharing codes, and checking through another channel before responding to an unusual request

Reference level: FL3 — Autonomous, with elements of FL2 — Beginner in the section on the fake code sent by mistake.

Conclusion

The techniques described here are not aimed at you in particular. They exploit everyday gestures, such as forwarding a code or scanning a QR code, and the trust between people who know each other.

That is why the most effective defence is not to suspect everyone, but to keep your codes to yourself and to check when a request does not sound like the person it claims to come from. Protecting your voice is also a way of protecting the people you care about.

The picture is completed by how to tell if your account was hacked and by the choice of limiting social login.

Something to think about. If a friend asked you by chat tomorrow for a code “sent by mistake”, what detail would tell you it was not really them writing?

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.