Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

A sophisticated attack campaign has been uncovered, with suspected Russian hackers exploiting a combination of Google’s OAuth authentication system and WhatsApp’s linking feature to gain unauthorized access to multiple high-profile targets. This brazen hacking operation not only highlights the vulnerabilities in our increasingly interconnected online lives but also underscores the importance of robust security measures.

At its core, this attack leverages the trust placed in popular services like Google and WhatsApp. Here’s how it works: attackers use Google OAuth, a widely used authentication system that allows users to grant access to various third-party apps without revealing their password, to gain entry into a target’s account. By combining this with WhatsApp’s linking feature, which enables seamless messaging between the two platforms, hackers can then move laterally within the target’s digital footprint, using OAuth tokens to sidestep traditional security controls.

The scope of this attack is significant, affecting multiple high-profile targets across various sectors. The exact number and identities of those impacted remain classified due to ongoing investigations, but it’s clear that these targeted campaigns pose a real threat to sensitive information and systems. As the attackers move seamlessly between platforms, exploiting interconnected services like OAuth and linking features, security experts warn against underestimating the stealthy nature of these operations.

Security researchers have been sounding alarm bells about the dangers of cross-domain privilege escalation for some time now. Essentially, this technique involves abusing trusted relationships between services to bypass standard security controls. By mapping these breach routes at key choke points, hackers can evade detection and cause significant damage before being noticed. In this case, the attackers’ expertise in navigating complex digital landscapes is evident.

The implications of such attacks are far-reaching, emphasizing the need for a more comprehensive understanding of online risk management. It’s no longer sufficient to focus solely on individual system vulnerabilities; we must also consider the broader ecosystem and how interconnected services can be exploited. As this campaign demonstrates, a single weak point in the digital armor can have devastating consequences.

For individuals and organizations seeking to protect themselves against such attacks, it’s essential to adopt a multi-layered approach to security. This includes implementing robust authentication protocols, keeping software up-to-date, and regularly monitoring for suspicious activity within their systems. Additionally, being aware of the services you use and how they interact with one another can help identify potential vulnerabilities before they’re exploited.


Source: The Hacker News — 2026-08-20