The Invisible WhatsApp Trap: How a Simple Courier Call Can Empty Your Bank Account
By Prof. Dr. Bimal Kumar Mishra
Cybercriminals are no longer relying on sophisticated malware or expensive hacking tools. Instead, they are exploiting one of the most powerful vulnerabilities in cybersecurity—the human mind. A new fraud technique, rapidly spreading across India, demonstrates how social engineering combined with standard telecommunication features can compromise a victim’s WhatsApp account within minutes and lead to significant financial losses.
The attack typically begins with what appears to be an innocent telephone call. The caller introduces himself as an executive from a reputed courier company and politely informs the victim that the delivery agent is unable to contact them. To resolve the issue, the caller claims to have sent a “verification number” through SMS and requests the victim to simply copy and dial it.
Most unsuspecting users comply without realizing that the SMS does not contain an ordinary number. Instead, it carries a GSM command in the following form:
“21XXXXXXXXXX#”
where the mobile number belongs to the cybercriminal.
The victim unknowingly executes a Mobile Man-Machine Interface (MMI) command rather than making a normal phone call. This command activates Unconditional Call Forwarding, causing every incoming voice call to be diverted to the attacker’s telephone number.
Technically, the command follows the GSM supplementary service protocol. The symbol “” initiates the command sequence, “21” represents the GSM supplementary service code for unconditional call forwarding, the second “” separates the command from the destination number, and “#” terminates the instruction. Once transmitted, the request reaches the telecom operator’s switching network, where the subscriber’s call-routing profile is updated.
From that moment onward, incoming voice calls no longer reach the victim’s handset. Instead, the Mobile Switching Centre (MSC) automatically redirects them to the attacker’s designated number.
This seemingly harmless redirection becomes the gateway to WhatsApp hijacking.
The attackers immediately attempt to register the victim’s WhatsApp account on another device. WhatsApp sends a One-Time Password (OTP) through a voice call when SMS verification is unavailable or when the attacker selects voice verification. Since all incoming calls are now forwarded, the verification call reaches the cybercriminal instead of the legitimate owner.
Within minutes, the attacker gains complete access to the victim’s WhatsApp account.
The fraud does not stop there.
The cybercriminal rapidly exploits WhatsApp’s Broadcast List feature, which allows a single message to be simultaneously delivered to as many as 256 contacts without creating a group. Since the messages originate from the genuine WhatsApp account of the victim, friends, relatives, colleagues, and business associates are far more likely to trust them.
The fraudulent message usually reads:
«”I urgently need some financial help. My UPI is not working. Please transfer the amount to this new UPI ID. I will return the money within two hours.”»
Because the request appears to come from someone they personally know, many recipients transfer money immediately without independently verifying the request.
This combination of telecommunications manipulation, identity theft, and social engineering makes the attack exceptionally dangerous.
Fortunately, protecting oneself is neither expensive nor complicated.
First and foremost, never dial any code received through SMS merely because someone instructs you to do so over the phone. Courier companies, banks, government departments, or customer-care executives never require customers to execute GSM service codes to receive deliveries or verify identities.
Users should periodically verify whether call forwarding has been activated on their phones. Dialing “*#21#” displays the current unconditional call-forwarding status and, where supported, the destination number receiving forwarded calls.
If call forwarding has been enabled accidentally or fraudulently, it can usually be removed by dialing “##21#”. In many networks, “##002#” cancels all active call-forwarding services and restores normal routing to the subscriber’s SIM card.
Equally important is enabling Two-Step Verification within WhatsApp. This feature introduces a user-defined six-digit PIN that acts as a second authentication factor. Even if a cybercriminal successfully intercepts the OTP through call forwarding, the WhatsApp registration cannot be completed without this confidential PIN. This additional security layer significantly reduces the likelihood of account takeover.
Families should also adopt a simple but highly effective precaution. Any request for money received through WhatsApp—even from a close friend or family member—should always be verified by making a direct telephone call or using another trusted communication channel before transferring funds. A few seconds of verification can prevent substantial financial loss.
The larger lesson extends beyond WhatsApp. As digital communication becomes increasingly integrated into everyday life, cybercriminals continue to exploit legitimate technologies rather than merely attacking software vulnerabilities. Awareness, critical thinking, and basic cyber hygiene remain our strongest defence.
Technology alone cannot eliminate cybercrime. An informed citizen is the most effective firewall.
(The author is a mathematician and cybersecurity researcher working in the areas of artificial intelligence, cyber-epidemiology, and digital security awareness.)