BREAKING: 3.5 Billion WhatsApp Numbers Exposed in Massive Security Oversight

The CyberSec Guru

3.5 Billion WhatsApp Numbers Exposed

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide, Writeup Access: Get complete in-depth writeup with scripts access within 12 hours of machine drop.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

In a digital privacy crisis that has sent shockwaves through the cybersecurity world, a critical flaw in WhatsApp’s infrastructure has reportedly exposed the phone numbers and account details of nearly 3.5 billion users—almost half of the global population.

Researchers from the University of Vienna and SBA Research have uncovered a “systemic flaw” in the messaging giant’s contact discovery system, allowing them to harvest a staggering amount of user data without triggering security alarms.

The “Rate Limit” Loophole

The vulnerability wasn’t a sophisticated hack, but a glaring oversight in WhatsApp’s design. According to the report released yesterday, the platform failed to enforce “rate limits”—the digital speed bumps that usually stop bots from making too many requests at once.

Exploiting this, researchers were able to automate a process that checked billions of phone numbers to see if they were registered on WhatsApp. The system happily returned the data, allowing the team to map users on a global scale.

“Phone numbers were not designed to be used as secret identifiers for accounts, but that’s how they’re used in practice,” the researchers noted in their explosive findings.

What Was Leaked?

While message contents remain encrypted, the metadata exposed is a goldmine for scammers and phishing operations. The scraped data includes:

  • Active Phone Numbers: Confirmation that a number is real and active.
  • Profile Pictures: roughly 57% of the exposed accounts had profile images set to “Public.”
  • “About” Text: Personal bios and status updates for 29% of users.
  • Device Data: Timestamps that can reveal usage patterns.

Crucially, the researchers managed to identify millions of accounts in countries where WhatsApp is officially banned, identifying 2.3 million users in China and 60 million in Iran, potentially putting those citizens at risk.

RankCountry# AccountsGlobal ShareAndroid (%)iOS (%)Picture (%)About Text (%)Business (%)Companions (%)
1India749,075,24621.67%95562.229.59.86.2
2Indonesia235,245,0776.81%92849.127.510.79.3
3Brazil206,949,2245.99%811961.141.510.315.5
4United States137,859,2843.99%336744.032.82.46.1
5Russia132,855,0223.84%762461.733.53.69.4
6Mexico128,324,1663.71%821846.123.34.111.7
7Pakistan98,277,6652.84%95558.520.021.75.4
8Germany74,565,4252.16%584251.035.42.213.4
9Türkiye72,131,9032.09%732748.033.43.012.0
10Egypt69,317,8062.01%901053.225.111.36.1
11–245Others1,552,021,57144.90%772356.927.99.39.0
Global(245 countries)3,456,622,389100.00%811956.729.39.08.8

Meta’s Response

Meta, WhatsApp’s parent company, has stated that the issue was patched in October 2025 following a disclosure by the researchers. A spokesperson downplayed the severity, characterizing the leaked data as “basic publicly available information.”

However, cybersecurity experts warn that this “basic” data is exactly what bad actors need to execute sophisticated Smishing (SMS Phishing) attacks and identity theft.

How to Protect Yourself Now

While the flaw has been patched, the data may already be in the wild. Experts recommend immediately tightening your privacy settings:

  1. Open WhatsApp Settings.
  2. Navigate to Privacy.
  3. Change Profile Photo, About, and Status visibility to “My Contacts” or “Nobody.”
  4. Enable Two-Step Verification to prevent account hijacking.

Stay tuned as this story develops.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading