Skip to content

WhatsApp Flaw Enables Massive Scraping of 3.5 Billion User Accounts

Esecurityplanet Ken Underhill November 20, 2025

A WhatsApp flaw allowed researchers to scrape 3.5 billion accounts, showing how simple app features can create serious security risks.

A newly uncovered WhatsApp security flaw may have exposed data from every one of the platform’s 3.5 billion users — making it what researchers are calling the largest data leak of its kind.

The vulnerability , which allowed attackers to enumerate user accounts at extraordinary scale, required no advanced hacking techniques and exploited a long-standing gap in WhatsApp’s discovery feature.

“On the surface, WhatsApp’s API appeared to expose only limited information — a phone number, a timestamp, and a public key. While none of these elements seem individually sensitive, that assumption is flawed,” said Omer Tal, Director of Innovation and Research in the CTO Office at Seemplicity.

Tal further explained “Even seemingly benign data can hold significant value for malicious actors. In this case, a timestamp can reveal whether a phone number is active, and patterns in the public key may allow attackers to infer additional details, such as account age or even the operating system in use.”

He also emphasized the scale of the exposure, noting, “It’s also important to recognize the scale of this incident. Collecting small pieces of data from a few devices is one thing; scraping information tied to 3.5 billion phone numbers, nearly one-third of the global population, is something else entirely.”

Tal concluded by stressing Meta’s responsibility in the incident: “The core issue is Meta’s responsibility. As a company that holds vast amounts of data on billions of people worldwide, even the smallest data elements must be safeguarded with extreme care. Meta has an obligation to ensure that vulnerabilities like this cannot be exploited, and that the trust users place in their platforms is protected.”

The flaw highlights how even basic app features — such as checking whether a phone number is registered — can be weaponized when rate limits and anti-automation controls are insufficient.

The researchers demonstrated that attackers could confirm account ownership, view profile photos, and extract profile text from billions of users, creating opportunities for phishing, harassment, surveillance, and large-scale social engineering.

The researchers tested WhatsApp’s discovery mechanism using WhatsApp Web.

According to the researchers, WhatsApp imposed no meaningful blocking as they submitted 7,000 phone numbers per second, allowing them to verify 3.5 billion accounts.

The data the researchers collected included:

This scaled-up enumeration — essentially a “reverse phonebook” — dramatically increases privacy risks compared to typical, one-off lookups.

The root of the vulnerability lies in unrestricted enumeration, a known security weakness in which an attacker can submit unlimited queries to verify user accounts.

WhatsApp’s lack of strict rate limiting allowed researchers to brute-force billions of numbers without triggering any defensive mechanisms.

While WhatsApp encrypts messages end-to-end, its account discovery feature — designed for convenience — exposes far more data than many users understood.

Profile text sometimes included political views, sexual orientation, drug-related content, links to social media accounts, or professional email addresses.

Researchers also identified millions of active accounts tied to numbers from countries where WhatsApp is banned, such as China and North Korea — information that could put individuals at real personal risk.

While WhatsApp has taken steps to address the data scraping vulnerability, organizations and developers must adopt stronger safeguards to protect against similar abuses in the future.

Strengthening resilience against these types of attacks requires layered controls that combine strong authentication, smarter detection, and proactive privacy controls.

Meta stated that the exposed information was already public based on user privacy settings and emphasized that “user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption.”

Meta also confirmed that the Austrian research team deleted the data after the study.

According to WhatsApp VP of Engineering Nitin Gupta, the company had been working on new anti-scraping systems, and the researchers’ findings “were instrumental in stress-testing” those defenses.

The researchers confirmed that after Meta deployed fixes in October, the enumeration technique was fully blocked.

This incident underscores a growing challenge in modern app security: platforms designed for frictionless onboarding often create hidden attack surfaces.

Even when only “public” data is exposed, mass enumeration increases harm potential, especially for vulnerable populations like journalists in countries with oppressive regimes.

This risk reinforces why organizations must shift toward a zero-trust approach, where every request is treated as untrusted by default and every data access pathway is intentionally verified and restricted.

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

A fake CAPTCHA click led to a 42-day Akira ransomware breach that went largely undetected despite extensive security tooling.

A new ShadowRay 2.0 campaign is abusing a Ray vulnerability to seize control of AI infrastructure worldwide.

A glob CLI flaw lets attackers run commands via malicious filenames, putting CI/CD pipelines at risk.

The Cloudflare outage showed how one failure can disrupt the internet and highlighted the need for stronger cyber resilience.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (2)

Malware (1)

Platforms (1)

Ransomware Groups (1)

Tools (1)