A client of ours reached out a few weeks ago because an employee’s personal Facebook account had been compromised. Normal enough, this happens constantly and usually stays contained to a stolen profile, a few spam posts, an afternoon of embarrassment. Except this time it didn’t stay contained. Within a day, the same employee’s WhatsApp got hit too. That mattered a lot more, because their team used WhatsApp for real work: client updates, quick approvals, links to files, the kind of stuff you don’t think of as “sensitive” until someone else is reading it.
We got called in to help clean it up. Once things were locked back down, we sat down with the team and had a longer talk about something we don’t say often enough: for most people, home security and work security aren’t two different projects anymore. It’s the same phone, the same browser, the same three passwords typed into forty different logins. An attacker doesn’t care which bucket you’ve mentally filed an account under. They care which one is easiest to get into.
Small businesses tend to assume attackers are after bigger fish, banks, hospitals, Fortune 500 IT departments with something worth the effort. In practice, small teams get targeted precisely because they’re easier. There’s rarely a dedicated security person double-checking logins, budgets for enterprise-grade tools are thin, and personal and business tech blend together by necessity because nobody has the headcount to keep them separate. An attacker running scams like this one at scale doesn’t need a specific target. They need volume, and easy accounts convert better than hard ones.
How a Facebook Hack Became a WhatsApp Problem
We don’t share client specifics, but the pattern here is well documented and worth understanding, because it isn’t rare. Facebook and WhatsApp are both owned by Meta, but they aren’t technically linked the way people assume. A stolen Facebook password doesn’t automatically hand over WhatsApp. What actually happens is usually more human than technical.
Security researchers disclosed a scam in late 2025, nicknamed “GhostPairing,” that shows how this plays out. It starts with a message from a compromised or fake account, something like a photo tag or a link that looks like it goes to Facebook. The link leads to a fake verification page asking for a phone number, then walks the victim through “approving” what looks like a routine login. What they’re really approving is a new device pairing to their WhatsApp account, no password or text interception required. Once that pairing goes through, the attacker is reading every conversation in real time, including whatever work chatter happens to live in that same app.
The version we see most often with clients is simpler still: someone’s account gets compromised, and the attacker uses it to message the person’s own contacts asking them to forward a six-digit “verification code.” That code is the one WhatsApp just texted the real account holder to approve a new device login. Hand it over, even to someone who sounds like a friend or a coworker, and the account is gone.
One habit would have caught both scams above before they went anywhere: if a contact asks you to forward a code, click a link, or “verify” something out of nowhere, check with them through a different channel before doing anything, a phone call, a text on a separate thread, anything that isn’t a reply in the same conversation that might already be compromised. It takes thirty seconds and it’s the single easiest way to catch this while it’s still happening instead of after.
The reason this story belongs on a business cybersecurity blog and not just a personal-safety one is simple. Once WhatsApp is compromised, whatever business used it, quotes, contracts in progress, client phone numbers, internal chatter, is compromised too. Most small businesses don’t have a policy about which messaging app is “for work.” People use whatever’s already on their phone. That’s exactly the gap that got exploited here.
Turn On MFA Everywhere, Not Just at the Office
Multi-factor authentication (MFA) is the single highest-leverage thing a person can do to protect an account, and it isn’t close. Microsoft has reported that accounts with MFA enabled are more than 99.9% less likely to be compromised, even when the attacker already has the correct password. That number holds up because most account takeovers rely on a stolen or guessed password being enough on its own. MFA breaks that assumption entirely.
CISA’s guidance is blunt about it too: using more than a password, whether that’s a texted code, an authenticator app, a fingerprint, or an access card, makes an account meaningfully safer than a password alone. We push MFA hard on company logins because we manage those directly. What doesn’t get the same attention is Facebook, Instagram, personal email, the family Amazon account, or WhatsApp’s own settings. Every one of those supports it. Almost none of our clients had turned it on for anything outside of work before we asked.
The fix takes about ten minutes per account, and an authenticator app is a better choice than text-message codes where you have the option, since SMS can be intercepted or SIM-swapped. Worth doing this week for yourself, and helping a family member or new hire do the same:
- Primary email first, since it’s usually the reset path for everything else you own
- Facebook, Instagram, and any other social account tied to your real name
- WhatsApp’s own two-step verification, under Settings > Account > Two-step verification
- Banking and anything tied directly to money
- The password manager itself, covered next
Two more habits worth building alongside MFA, both take about five minutes. Call your mobile carrier and ask them to add a PIN or passcode to your account, so nobody can talk their way into a SIM swap and intercept your texted codes. And whenever a service hands you backup codes for MFA, save them somewhere other than your email inbox, a note in your password manager works well, since your inbox is often the first thing an attacker checks.
Also worth checking every so often: most major accounts let you see every device currently logged in. WhatsApp keeps this under Settings > Linked Devices, Facebook under Settings > Security and Login > Where You’re Logged In. If something’s on that list you don’t recognize, that’s exactly how GhostPairing shows up, log it out and change your password right away.
Use a Real Password Manager (We Recommend Bitwarden)
CISA’s current guidance calls for passwords at least 16 characters long, either random or built from a passphrase of several unrelated words, and unique to every single account. Nobody is doing that from memory, and CISA says as much directly: “a good password manager creates, stores and fills in passwords automatically so you only have to remember one strong password, for the password manager itself.”
We recommend Bitwarden to clients and run it internally ourselves. It’s open source, so its code has been independently audited rather than taken on faith. It has a genuinely usable free tier for individuals, and its family and business plans let you share specific logins, a shared streaming account, a shared vendor portal, without ever showing anyone the actual password. That last part matters more than people expect. The number one reason password reuse happens at small businesses is that sharing a password out loud or over text feels easier than setting up anything formal. A shared vault removes the excuse.
Worth knowing too: current NIST guidance has actually backed away from forcing people to change passwords every 90 days on a fixed schedule, since it mostly just trains people to make small, predictable, weaker tweaks to the same password. A long, unique, randomly generated password that stays put is better than a mediocre one you’re forced to fiddle with every quarter. That’s the whole case for a manager doing the generating.
If your team already uses Bitwarden at work, the easy next step is getting everyone set up with it personally too, on the same phone and in the same browser, but with a separate free personal account and vault, not the work one. Keeping them apart means a personal password never sits in the same place as a client login, and if you ever offboard someone, revoking the work vault doesn’t touch anything of theirs. It’s less friction than reusing “Fall2024!” everywhere, and once the app is already installed for work, setting up a personal vault next to it is a five-minute favor to yourself.
Audit the Browser Extensions and Apps You’ve Forgotten About
This is the one people skip, and it shouldn’t be. In February 2026, researchers caught three separate Chrome extension campaigns actively stealing data from business users. One, disguised as a Meta Business Suite productivity tool, was quietly transmitting two-factor codes and exported contact lists to an outside server. A cluster of 32 extensions marketed as AI assistants was harvesting Gmail message content and sending it off-platform. A separate campaign tied to social media customization tools hit roughly half a million accounts before it was caught.
None of these looked suspicious at install time. They had believable names, reasonable-looking permission requests, and worked well enough that people kept using them for months. That’s the real danger: a browser extension or phone app doesn’t need to look malicious. It just needs to ask for a bit more access than it actually needs, and nobody notices.
Worth doing on a recurring basis, at home and at work: open your browser’s extensions page and actually look at what’s installed. If you don’t remember installing it, or haven’t used it in the last month, remove it. Do the same pass on your phone, particularly for anything that asked for contacts, microphone, or accessibility permissions it had no obvious reason to need. If you’re handling anything sensitive, business banking, client data, admin logins, a separate browser profile with zero extensions installed, used only for that, is a cheap and effective habit.
Physical Security Still Counts
All of the above assumes the attack arrives over the internet. Plenty don’t. CISA’s own device security guidance is simple and easy to ignore anyway: lock your screen every time you step away, even for a minute, and set auto-lock to kick in on its own after fifteen minutes. Don’t leave a laptop or phone unattended in a car, a coffee shop, or a hotel room, that’s where most physical device theft actually happens. And pay attention to who can see your screen in public. Shoulder surfing doesn’t take any technical skill at all, just someone glancing over at the right moment.
Full-disk encryption is worth turning on too, and it’s built in and free on nearly everything now, BitLocker on Windows, FileVault on a Mac. If a laptop does get stolen, an encrypted drive means the thief has a paperweight instead of a folder full of client files. And at home, this extends to the router. Change the default admin password on it (a shocking number never get changed from “admin/admin”), keep its firmware updated, and if you’ve got smart devices, cameras, thermostats, whatever, put them on a separate guest network from the laptop you use for work. A compromised smart plug shouldn’t be able to see traffic from a work VPN.
Where Home and Work Actually Meet
The uncomfortable truth here is that “keep work stuff secure” and “keep home stuff secure” aren’t actually two different projects for most people. It’s one phone, one laptop, one set of habits. The employee in this story didn’t do anything careless by most people’s standards. They used the same messaging app for work that everyone on their team already used, and they got targeted through a personal account nobody had thought to lock down. That’s not a rare mistake. It’s close to the default.
None of this is a one-time fix either. New employees join without knowing any of it, family members get new phones and fall back on old habits, and attackers update their playbook constantly, GhostPairing itself is only a few months old as of this writing. The businesses that hold up best treat this like an ongoing habit, a quick refresher every few months, rather than a single training session everyone forgets by summer.
The good news is none of the fixes above are expensive or complicated, and if you want help walking your team, or your own family, through setting any of this up, that’s exactly the kind of thing we’re happy to sit down and do. It doesn’t have to start with a breach.
Quick list, worth saving:
- Turn on MFA for email, socials, WhatsApp, and banking, an authenticator app over text where you can
- Get everyone on a password manager, a personal vault and a separate work vault, both with long, unique, generated passwords
- Add a PIN with your mobile carrier and save MFA backup codes somewhere other than email
- Check “linked devices” on Facebook and WhatsApp now and then, log out anything you don’t recognize
- Verify odd requests, especially “forward me this code,” through a different channel before acting
- Audit browser extensions and phone app permissions twice a year, remove what you don’t use
- Lock your screen every time you step away, and turn on full-disk encryption
- Put smart home devices on a separate network from anything you do work on
Sources:
- ESET, “WhatsApp hacked? How to detect, recover, and lock it down”
- CISA, “Require Strong Passwords”
- CISA, “Protect the Physical Security of Your Digital Devices”
- The Hacker News, “Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History”
- Bitwarden, Business Password Manager overview

Comments are closed