Hong Kong police recorded 2,020 cases of instant messaging account hijacking during the first seven months of this year, a 154 per cent increase from the same period in 2025, as scammers used phishing links, stolen verification codes and increasingly sophisticated deepfake technology to defraud victims.

The cases resulted in total losses of about HK$150 million, according to police. WhatsApp was involved in 99 per cent of the reported incidents, making it by far the most frequently targeted messaging platform.

Some victims lost millions of dollars after criminals gained access to accounts belonging to people they trusted and then used those accounts to issue convincing requests for money.

In one of the largest cases cited by police, a financial manager working for an investment company transferred HK$12.2 million after receiving instructions through his supervisor's compromised WhatsApp account.

The manager believed he was communicating with his superior. The messages appeared to come from a familiar account and followed the kind of communication he would normally expect at work. By the time he realised the account had been taken over, the money had already been transferred.

Another victim, a businessman, lost more than HK$10 million after scammers used a deepfake voice message designed to imitate his father.

The case illustrates how criminals are moving beyond conventional text based scams. Rather than relying solely on written messages, fraudsters can now combine stolen accounts with artificial intelligence tools to make communications appear and sound more authentic.

Fake WhatsApp warnings used to steal verification codes

Police said many of the reported hijackings began with phishing messages designed to look as though they had been sent by WhatsApp's official service centre.

The messages typically create a sense of urgency. Victims may be told that their accounts are about to be suspended or that they need to complete an immediate security check. A link in the message directs them to a fraudulent website.

The fake pages are designed to resemble legitimate services. Victims who enter their mobile phone numbers and WhatsApp verification codes unknowingly provide scammers with the information needed to take control of their accounts.

Once access has been obtained, criminals can use the compromised account to contact family members, friends, colleagues and business associates. Because the messages come from an account the recipient already knows, the request may not immediately raise suspicion.

The scammers can then attempt to obtain money, additional personal information or further verification codes from the victim's contacts.

Police also warned about the use of search engine poisoning, a technique in which criminals manipulate search results so fraudulent websites appear prominently when people look for legitimate services online.

A user searching for help with a WhatsApp account could therefore encounter a fake support page before finding the genuine service. Entering personal details or security codes on such pages can hand the information directly to scammers.

1_2_29.jpeg

Criminals study victims' conversations

Superintendent Rachel Hui Yee wai of the Cyber Security and Technology Crime Bureau said criminals do more than simply gain access to an account.

After hijacking an account, scammers can examine previous conversations to understand how the account owner communicates with other people. They can study names, relationships, writing habits and the subjects discussed in earlier messages.

That information allows them to make their subsequent messages appear more believable.

A scammer impersonating a company executive, for example, may already know the names of employees, clients or business partners from the victim's chat history. A criminal targeting a family member can similarly use previous conversations to understand the relationships between relatives and the way they normally communicate.

Hui said scammers were also using deepfake technology to create realistic voice messages.

The technology adds another layer of deception because victims who are accustomed to verifying a request by listening to someone's voice may no longer be able to rely on that method alone.

The businessman who lost more than HK$10 million after receiving a deepfake voice message imitating his father is an example of the financial damage that can result when a familiar voice is used to establish trust.

The rise in such cases comes as criminals increasingly combine established phishing methods with tools capable of producing highly convincing impersonations.

WhatsApp accounts remain the main target

The fact that WhatsApp accounted for 99 per cent of the 2,020 reported hijacking cases shows the extent to which criminals are focusing on the platform.

The service is widely used for personal conversations, family groups and business communications, giving criminals a large pool of potential targets once an account has been compromised.

A stolen account can also provide access to a victim's network rather than just the victim themselves. Messages sent from a genuine account can reach dozens of contacts, while group chats can expose the scam to many more people.

That makes account hijacking particularly useful to fraudsters. Instead of approaching strangers from an unfamiliar number, they can exploit an existing relationship.

For victims, the danger often lies in the assumption that a message from a known contact is automatically trustworthy.

Police have urged users to treat unexpected requests for money, verification codes or urgent action with caution, even when they appear to come from someone they know.

whatsapp-hacking-surge-fuels-fraud-blackmail-cases-1775452145-9216.jpg

Meta urges users to avoid unknown links

Philip Chua, APAC Director of Public Policy, Products at Meta, said WhatsApp had strengthened its security measures to help protect users from account takeovers.

Those measures include two factor authentication and systems designed to detect suspicious activity.

But Chua also urged users to remain cautious, particularly when they receive unexpected links or requests for sensitive information.

Security tools can reduce the risk of account hijacking, but they cannot prevent every successful phishing attempt if users voluntarily enter their phone numbers or verification codes on fraudulent websites.

Users should therefore avoid clicking links in unsolicited messages claiming to come from WhatsApp or another service provider. They should also verify unusual requests through a separate communication channel rather than relying solely on the compromised account or message thread.

For businesses, the financial manager's HK$12.2 million loss shows why payment instructions sent through messaging applications should receive additional verification, particularly when they involve large sums.

A phone call to a known number, confirmation through an established company system or a second approval process can expose an impersonation before funds leave an account.

The scale of the losses reported by Hong Kong police also shows that account hijacking is no longer limited to small personal scams. A single compromised account can be used to manipulate a workplace transaction worth millions of dollars or persuade a victim to hand over substantial family funds.

With 2,020 cases already recorded in the first seven months of the year and losses reaching HK$150 million, police are urging users to treat verification codes, unfamiliar links and urgent financial requests as potential fraud signals rather than routine messages.