INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
WhatsApp Leaks User Metadata to Attackers
| 2026-04-20 14:33 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On April 20, 2026, WhatsApp was found to be leaking user metadata to attackers through a vulnerability in its design choices. The incident is attributed to Tal Be'ery, cofounder and CTO of Zengo, who demonstrated at Black Hat Asia 2026 that anyone can exploit this weakness using a custom program plugged into the WhatsApp Web protocol. This allows an attacker to silently ping a recipient's device, gather information on their online habits such as sleep or work schedule, and even perform resource exhaustion attacks draining the recipient's battery without their knowledge. The affected product is WhatsApp, with no specific number of users mentioned in the source; however, Be'ery showed that anyone can exploit this vulnerability using a jerry-rigged program designed to plug into WhatsApp.
Technical Mitigations AI-generated
• Patch WhatsApp to address the vulnerability described by Be'ery, which could allow attackers to learn device information.
• Use a custom program that detects and blocks application-layer messages sent via WhatsApp Web protocol that don't actually show up on the recipient's device.
• Implement a technique called "device fingerprinting detection" to identify when an attacker is trying to gather device information about a user.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SilenceSilence
Target & Sectors
DACH
DACH
Incident Timeline
2026/04/20
Attackers exploited WhatsApp's application-layer message feature to send silent, undetectable messages that could be used for phishing or resource exhaustion attacks.
Click on any entity below to view its context and source!
infrastructure
Windows
Related:
Microsoft's Original Windows Secure Boot Certificate Is Expiring
"With
end-to-end encryption
, if someone attacks WhatsApp's servers, they cannot read your data, and even WhatsApp cannot read your data.
infrastructure
Android
Maybe you're willing to pay more because you're an iPhone user, and you also have an iPad, and not cheaper Android-based devices.
Right around the beginning of the year, for instance, Be'ery noticed that the means by which he could fingerprint Android devices running WhatsApp no longer worked.
financial
$70 acquisition
Be’ery, cofounder and chief technology officer (CTO) of Zengo — whose
$70 million acquisition by eToro
was announced during our call — silently pried into my online habits (with my permission) using a jerry-rigged program he designed to plug into…
threat_actor
Silence
Instead it's been working around the problem with features like "Silence Unknown Callers," rate limiting, and more microscopic fixes.
victims
3.5 other users
Any WhatsApp user can message any of its other 3.5 billion users, so long as the sender knows — or guesses — the right phone number.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Related:
Microsoft's Original Windows Secure Boot Certificate Is Expiring
"With
end-to-end encryption
, if someone attacks WhatsApp's servers, they cannot read your data, and even WhatsApp cannot read your data.
Metrics
infrastructure
Android
Affected Product
Maybe you're willing to pay more because you're an iPhone user, and you also have an iPad, and not cheaper Android-based devices.
Right around the beginning of the year, for instance, Be'ery noticed that the means by which he could fingerprint Android devices running WhatsApp no longer worked.
Metrics
financial
70,000,000
Acquisition
Be’ery, cofounder and chief technology officer (CTO) of Zengo — whose
$70 million acquisition by eToro
was announced during our call — silently pried into my online habits (with my permission) using a jerry-rigged program he designed to plug into…
Metrics
victims
3,500,000,000
Other Users
Any WhatsApp user can message any of its other 3.5 billion users, so long as the sender knows — or guesses — the right phone number.
Intelligence Sources
Dark Reading
2026-04-20
WhatsApp Leaks User Metadata to Attackers
Dark Reading
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:46
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Microsoft
entity
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
7 METRICS
tactic
Cyber Operation Type
Phishing
tactic
financial
Acquisition
70,000,000
acquisition
timeline
Temporal Reference
2024
date
target region
Target Country
Austria
country
threat actor
APT Group
Silence
actor
general metric
Hat Asia
2,026
hat asia
victims
Other Users
3,500,000,000
other users
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.