- Sri Lanka CERT has warned iPhone users about WhatsApp account takeovers requiring no action from the victim, following reports from people in the media and business communities.
- Victims describe messages sent from their account asking contacts for money, with nothing showing under Linked Devices, and in some cases loss of control of groups they administered.
- The attack affects iPhones running iOS below 16.7.12. Apple and WhatsApp fixed the underlying flaws around a year ago.
- This is not a new or unpatched vulnerability. Updating your iPhone removes the conditions the attack depends on, rather than partially mitigating it.
- Some local coverage has described attackers reaching the camera, microphone and all personal data. The published forensic analysis describes something narrower: hijacking of the WhatsApp session, with access to recent chats only.
- If you cannot update, or you think you are already affected, the sequence below still helps.
Sri Lanka CERT has issued a public warning about a WhatsApp account takeover technique affecting iPhone users, after complaints from several people including members of the media and the business community. Reported by Daily Mirror and other local outlets on 11 August, the warning describes accounts being taken over with no link clicked, no QR code scanned and no code shared. The advice is to update iOS and WhatsApp immediately, enable two-step verification and Chat Lock, and verify unusual money requests through another channel.
That advice is sound and worth acting on today. The framing around it needs some care, because the difference between “a new attack nobody can stop” and “old flaws on phones that were never updated” changes what you should actually do.
What victims are seeing
The pattern is consistent and unusually confusing for the person experiencing it. Your account sends messages you did not write, typically to recent contacts, asking for money transfers. You open WhatsApp, check Linked Devices, and it shows nothing. No unfamiliar sessions, no web logins, no trace of anything. Local reporting adds that in some cases attackers also took over WhatsApp groups the victim administered.
That absence of any linked device is what makes this so disorienting, and it is also the detail that identifies the technique.
What the forensic work actually found
The Sri Lankan warning refers to analysis by an Italian security firm. That firm is Forenser, and its investigation was published in May 2026 after a cluster of cases in Italy showed exactly the same signature.
Their analysis, reported by Security Affairs, found every affected device was an iPhone running some version of iOS 16, across models from the iPhone 8 through the iPhone 14. Device logs showed a continuous sequence of session resynchronisation events, which the researchers read as two clients competing to hold the same WhatsApp account open at once. That is why nothing appears under Linked Devices: the attacker’s client is not registered as one in the normal sense.
The mechanism, which the firm partly reproduced in a laboratory, involves extracting the cryptographic material used to establish a WhatsApp session from the compromised phone, then using it to stand up a separate client attached to the victim’s account. The researchers point to two previously disclosed vulnerabilities as the likely route: an Apple image processing flaw and a WhatsApp linked-device synchronisation flaw affecting iOS below 16.7.12.
One detail from that analysis matters for anyone assessing their own exposure. Attackers could reach recent conversations but appeared unable to see older or archived chats. This is an account takeover, not total control of the phone.
Three things worth getting right

It is not new. The forensic analysis was published around three months ago, and the underlying flaws were fixed roughly a year before that. What is new is that Sri Lankan victims have come forward, which is genuinely newsworthy and is why the warning exists. But “newly identified attack” invites the conclusion that there is nothing you can do yet, and that is the opposite of the situation.
Zero-click does not mean unstoppable. The term describes how the attack reaches you: no tap, no scan, no code. It does not mean the attack works against a patched phone. Every compromised device examined was running software that was already out of date. Updating is not a partial defence here, it is the defence.
It is an account takeover, not spyware. Some local coverage has described attackers gaining access to the device’s data, microphone and camera, and has recommended watching for battery drain and unusual data usage. Those are reasonable indicators for a spyware infection, but they do not match what was actually documented, and we have seen no published evidence supporting the broader claim. Overstating the impact makes the story frightening rather than actionable, and it points people at the wrong checks.
What to do

Updating your iPhone is the step that matters, and there is a wrinkle worth knowing about. Not every iPhone can move to the newest version of iOS. The older devices in the affected range cannot go beyond the iOS 16 line at all, which means “update to the latest iOS” means different things depending on what you own. Open Settings, then General, then Software Update, and install whatever your device offers. If your iPhone’s newest available version is on the iOS 16 branch, the number to look for is 16.7.12 or later.
If your phone has stopped receiving updates altogether, no setting will close this, and replacing the device is the only real answer. That is an expensive sentence to write in a market where second-hand iPhones are common, and it is still the honest one.
If you think you have already been affected, updating WhatsApp or reinstalling it and re-authenticating appears to evict an attacker session. Turning on two-step verification prevents your number being registered elsewhere. Chat Lock puts conversations behind a PIN or Face ID, and locked chats appeared to remain out of reach in the cases examined.
Do not reply in the same chat to check whether it is really them. If their account is compromised, whoever is inside it may read your reply before they do, and can answer convincingly. Call the person instead, on a number you already have. This applies to any unexpected request for money or account details, not only this campaign.
Why it matters
For individuals, this is the clearest possible argument for a habit most people put off. The attack did not defeat a current iPhone. It found phones that had not been updated in a year or more, which is an extremely common state for a device that still works fine. If you have been dismissing the update prompt, this is what that decision eventually costs.
It also matters who was targeted. Journalists and businesspeople were among those reporting incidents, and a compromised WhatsApp account belonging to either is worth more than the money any single transfer request might raise. For a journalist it exposes sources and unpublished work. For a business owner it is a trusted channel for instructing payments. If you are in either group, the steps above are not general hygiene, they are specific to your risk.
For organisations in Sri Lanka, the uncomfortable question is how much business runs through WhatsApp. Payment instructions, approvals and client conversations move through it constantly here, on personal devices nobody manages and nobody patches. That is a real dependency, and this incident is a reasonable prompt to decide whether financial instructions should ever be actioned from a chat message without a second channel confirming them.
For practitioners, the observable signature is worth knowing. The published analysis identifies repeated session resynchronisation events in device logs as the artefact that distinguished this from ordinary account theft, and the absence of any entry under Linked Devices as the symptom that makes users think nothing is wrong. If you are asked to assess a suspected case, those are the two things to look for. Reporting to Sri Lanka CERT can be done through its official incident reporting channels, and their hotline is 101.
- Open Settings, General, Software Update on your iPhone and install what is offered. If your device tops out on the iOS 16 branch, confirm you are on 16.7.12 or later.
- Update WhatsApp from the App Store. If you suspect you are affected, reinstall it and re-authenticate.
- Turn on two-step verification in WhatsApp under Settings, Account.
- Use Chat Lock on your most sensitive conversations.
- Check Linked Devices and remove anything you do not recognise, while knowing that an empty list does not prove you are unaffected.
- Never confirm a money request in the same chat it arrived in. Call instead.
- Ask the older iPhone users in your family whether their phone has updated recently, since they are the most likely to be exposed and the least likely to have noticed.
- If you are compromised, tell your contacts through another channel quickly, because the request goes to people who trust you.
Last verified: 12 August 2026. The Sri Lanka CERT warning is reported here from local news coverage published on 11 August. Technical detail comes from forensic analysis published in May 2026, which the researchers described as ongoing. Attribution of the compromise to specific vulnerabilities is the researchers’ assessment rather than a confirmed finding.