“Add me on WhatsApp” scams: How to keep everyone safe
Paul Ducklin
09/25/2026
Share this article:
Secure transmission doesn’t make it true
Scams conducted via WhatsApp aren’t new.
Romance scams, for example, where criminals lure trusting victims into online relationships and then squeeze them for money, sometimes for months or years, often start with fake profiles on legitimate dating sites.
The scammers quickly pressure new contacts into off-site communication, typically using popular one-to-one messaging services such as WhatsApp, where their messages are end-to-end encrypted and invisible to the dating site itself, and to other members who might otherwise warn potential victims of fake profiles or known criminal “love rats.”
The more private and “opt-in” nature of WhatsApp contacts and groups represents a welcome break from the barrage of unwanted and outright dubious calls that plague the old-school mobile phone networks.
Add to this the much-vaunted and cryptographically strong end-to-end security (something you don’t get from mobile phone calls and text messages), and you can see why some users end up trusting WhatsApp connections when they shouldn’t.
This is the same sort of technology-versus-sociology problem that we’ve had with https:// websites. Secure HTTP (https) means that the connection is cryptographically protected from snooping. But it says nothing about the truthfulness of the content that the website serves up. In fact, the https layer can help cybercriminals to sneak malicious content through web firewalls, because the end-to-end encryption conceals that content from interception and threat scanning.
Keeping it super-simple
The initial problem for WhatsApp scammers, as you can imagine, is to get their victims to add them as WhatsApp connections in the first place.
Ironically, perhaps, despite the fear (and often the distraction) created by today’s dramatic cybersecurity news stories about how AI is favoring attackers, and how ever-more vulnerabilities and exploits are being found․․․
․․․it seems that WhatsApp scammers have found that going very low-tech, and keeping things as basic as possible, gives them a steady flow of new victims without arousing the sort of suspicion that a fancier attack might.
Simply put, they send an SMS (text) message from an in-country mobile number that consists of little more than words to this effect:
[sender's number]
Please add me on WhatsApp.
No greeting, no names, no explanation, to be sure, but also no facts or details that might be wrong.
At this point, you’re probably thinking, “How could something so brief and impersonal ever succeed?”
The answer, apparently, hinges on two modern commonplaces:
Official bodies such as home owners’ associations, residents’ committees, and commercial service groups, increasingly use tools such as WhatsApp for contacting members and customers. Adding them when requested on WhatsApp is considered by many people not only to be normal, but also convenient for reporting problems in the future, or arranging meetings and visits.
Tradespeople arriving for pre-arranged work such as plumbing, painting, or electrical repairs, commonly phone or send a brief text message on approach. This is considered a useful courtesy, given that their arrival often depends on traffic or previous jobs, and that you may need to head outside to let them onto the property, show them where to park, and so on.
Why it works
Recent coverage of these scams in the UK, for instance, reveals that many people are admitting that they willingly complied with the instruction, simply because the timing was right.
They were expecting a delivery or a tradesperson’s visit, without knowing the name or phone number of the person who’d be doing the job, and they were used to adding WhatsApp contacts or joining official-sounding groups after an initial contact via phone or email.
With many or most delivery and maintenance companies now scheduling their workers’ visits in windows of, say, two or four hours (and sometimes simply “any time during the day”), the scammers don’t need stolen databases or complex AI algorithms to figure out a good time to message you.
After all, if the message doesn’t mesh with your current plans, you’ll trivially ignore it as a scam.
But if the message does align with your expectations, you might accept it because it feels like an unlikely coincidence that a scammer would have sent it at exactly that moment.
But someone wins the lottery most weeks, despite the absurdly unfavorable odds involved, which is a good reminder that the prevalence of “unlikely coincidences” is merely a matter of statistics and sample sizes.
What happens next?
Obviously, once a scammer has tricked you into adding them as a WhatsApp contact, they can pitch almost any sort of dishonesty they like, using almost any type of cover story, without going through conventional email or web firewall defenses.
In the case of these unadorned “Add me on WhatsApp” lures, however, it seems that the most common endgames used by the criminals right now are:
Recruitment scams. Follow-up messages are likely to converge on discussing jobs. You may be invited to an “interview,” perhaps with attractive (but not entirely unrealistic or unbelievable) terms of employment. You may actually get “recruited,” but you’ll unknowingly be working for criminals. Whatever you do for them will ultimately make you look suspicious to the authorities, and if you ever handle money for them, you could be guilty of a criminal offense yourself. Alternatively, you might get “rejected,” which is gruelingly common in today’s unscrupulously automated recruitment processes, but only after handing over heaps of personal data. This might include scans of identity documents to establish your right to work, and a detailed personal history in the form of your resumé. The criminals could end up with enough personally identifiable information (PII) to masquerade as you, and turn you into a victim of identity theft.
Task scams. These scams are another form of recruitment, but of a very informal sort that may feel safe because they probably won’t require you to submit detailed personal data. Loosely put, you’re offered a free-time “cash job” broken into simple tasks such as clicking ad links, leaving online feedback, or posting upbeat reviews. You may actually earn a modest amount of cryptocurrency during your “trial” period, perhaps in the form of a genuine cryptocoin that you really can cash it out if wish, to “prove” to yourself it’s real. If you cut and run at this point, you might even end up ahead by a few dollars, though you’ll effectively have been paid a microscopic wage for promoting fraudulent sites and services along the way. But if the crooks gain your trust, they’ll typically keep trying to get you to “invest” in their “business” in return for an entirely bogus promise of much more work, with bigger payments, in the future.
What to do?
In one word, DON’T!
Never make the assumption that an unidentified message with coincidental timing is from someone you are expecting. The scammers may be sending hundreds of thousands or millions of untargeted messages, but hundreds or thousands of these will, entirely by chance, end up targeting potential victims.
Counsel your friends and family to reject online approaches of this sort. After all, if you think it really is the plumbers letting you know they’ll be arriving in two minutes’ time․․․ just wait two minutes. When they show up, you’ll no longer need to “add them on WhatsApp”!
Let vulnerable friends and family know they can call you if ever they are in doubt about an online connection, message, offer, or threat. Try to be there for them, and make sure they know to speak to you first, before sending or saying anything to the person at the other end.
Remember – friends don’t let friends get scammed.
Ask how SolCyber can help you do cybersecurity in the most human-friendly way. Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit you or your business!
More About Duck
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!
Paul Ducklin
09/25/2026
Share this article:
Table of contents:
The world doesn’t need another traditional MSSP or MDR or XDR.
We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
I am interested in SolCyber Foundational Coverage™
I am interested in a Free Demo
14898
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it. Privacy policy