Applications, which people use for communication, protect the content of the messages by encryption, but still they are not able to prevent an application user from handing over credentials to an attacker. The most commonly the hackers do not get into your account due to breaching technical security, but because of social engineering, such as a convincing message, a phone call, a technical support scam.
WHAT TO PAY ATTENTION TO
- PIN or verification code requests
- Unexpected logout or a request to register
- Unknown linked device
- Invitation by a link or a QR code
- Unusual account behaviour
- Unknown member of the group
RECOMMENDED SETTINGS AND GOOD HABBITS
- Turn on registration lock or two-steps verification.
- Restrict visibility of the phone number.
- Use disappearing messages where it is suitable.
- Ignore unsolicited invitation and suspicious contacts.
- Verify identity in another way.
- Delete inactive accounts.
WHAT TO DO IF I HAVE A SUSPICION THAT MY ACCOUNT WAS HACKED?
- Do not share any sensitive information.
- Disconnect unknown devices.
- Enhance security – change security PIN, password, or turn on registration lock or a two-steps verification.
- Let relevant people know about it – notify your contacts, that the messages sent from your account are not necessarily from you.
- New secure communication – communicate with administrator outside compromised application for next procedure.
- It is better to consider a new registration, in serious cases even consider use of a new telephone number.
RECOMENDATION FOR GROUP ADMINISTRATORS
- Individual approach to an individual – if it is necessary, delete compromised member of the group and contact him in a different way.
- Create a new group – if there is a suspicion, that an attacker could monitor the communication of several members, stop using original group, ask members to check linked devices and create a new group. Invite only verified users into the new group. Delete the original group after moving the members.
REMEMBER
There is no support, colleague or a supervisor who needs your PIN, verification code or access though unsolicited QR code. Even if you have the slightest doubts, think, do not react hastily, do not confirm anything and verify the request through different channels.
More detailed information and exact procedures can be found here: