How to protect your business WhatsApp: two-step verification, the six-digit code rule, staff access, and what to do if the number is hijacked or impersonated

A hijacked business WhatsApp is a scam machine aimed at your own customers, and a common one: attackers trick someone into revealing the six-digit registration code, take the number, and message your contacts asking for money. Most of the defence is one setting and one rule. Here is the checklist, and the recovery steps if it goes wrong.

By Ritchie, ReplyKit · Published 5 September 2026 · 7 min read

Quick answer

Turn on two-step verification with a PIN and a recovery email; never share the six-digit SMS code with anyone, including someone claiming to be WhatsApp, a courier or a colleague; review linked devices monthly and log out any you do not recognise; give staff access through linked devices rather than the phone; keep the phone locked and its SIM PIN on; and tell customers how to verify it is really you. If the account is hijacked, re-register the number on your phone immediately, which logs the attacker out, and warn contacts.

The checklistImpersonation aimed at your customersIf the account is hijackedIf you use an AI agentFAQ

The checklist

  1. Two-step verification. Settings, Account, Two-step verification. Set a PIN and add a recovery email. This is the single most effective control; an attacker with your SMS code still cannot register without the PIN.
  2. The six-digit code rule. WhatsApp sends a code only when someone is registering your number. Nobody legitimate will ever ask you for it. A message saying "I accidentally sent my code to you, please forward it" is the attack itself. Train every staff member on this one sentence.
  3. Linked devices. Settings, Linked devices. Review monthly; log out anything you do not recognise. Staff should use linked devices, not the phone. Details in linked devices explained.
  4. Phone and SIM. Screen lock, a SIM PIN so a stolen SIM cannot receive the registration code, and a carrier account password against SIM-swap.
  5. Staff access. Limit who can hold the phone. When someone leaves, log out their linked devices the same day.
  6. Backups. Keep an export of important chats; see backing up WhatsApp Business chats.

WhatsApp's own guidance is on its security page.

Impersonation aimed at your customers

Attackers also create new numbers with your business name and logo and message your customers with fake payment details. Malaysia's MyCERT has published advisories on exactly this pattern. Defences: publish your official number everywhere (website, Google listing, receipts), tell customers you only ever send payment details from that number, never change bank details by chat, and put a line in your greeting and your AI agent's instructions that says so. Meta's verified badge, described in the verified badge guide, helps customers tell the real account from a copy.

If the account is hijacked

  1. Re-register the number on your own phone immediately: install WhatsApp, enter the number, receive the code. This logs the attacker out. If two-step is on and they changed the PIN, WhatsApp's recovery process applies; contact WhatsApp support from the app.
  2. Post on Status, social media and your website that the number was compromised and to ignore requests for money.
  3. Message key customers and suppliers from another channel.
  4. Turn on two-step verification, review linked devices, and change the recovery email.
  5. Report to the police and, in Malaysia, to MyCERT or the National Scam Response Centre; in Singapore, ScamShield and the police.

If you use an AI agent

An agent is a linked device, so everything above applies. Add to its instructions: never share bank details other than the ones in the knowledge base, never confirm a change of payment details, and hand over anything that asks for account, password or code information. ReplyKit staff never ask for your WhatsApp code either; the connection is a Meta sign-in you do yourself.

Frequently asked questions

How do scammers take over a business WhatsApp?

Usually by tricking someone into sharing the six-digit registration code, or by SIM swap. Two-step verification blocks the first; a SIM PIN and carrier password help against the second.

What is the one setting that matters most?

Two-step verification with a PIN and recovery email.

Someone says they sent their code to my number by mistake. What do I do?

Do not forward it. That message is the scam.

What do I do if my business WhatsApp is hijacked?

Re-register the number on your phone to log the attacker out, warn contacts publicly, turn on two-step, review linked devices, and report it.

How can customers tell it is really my business?

Publish one official number everywhere, say you never change bank details by chat, and consider Meta's verified badge.

Pair safely, answer safely

An agent that never shares codes or changes bank details. 7-day free trial.

Start free
Written by Ritchie, ReplyKitPart of the small team in Malaysia that builds and runs ReplyKit. Writes about WhatsApp automation, AI customer service and small business lead response.

How we know this. Because ReplyKit customers run their business on one WhatsApp number, we spend a lot of time on account hygiene with them; the checklist below is what we recommend before connecting a number. Product figures in this article (limits, prices, per-reply costs) are taken from ReplyKit as it runs today and are re-checked when we update the page. Where we cite outside research, the source is linked below. We sell ReplyKit, so read our product claims with that in mind; we say where a different tool or no tool is the better choice. About ReplyKit.

Sources and further reading

  1. WhatsApp, Security
  2. MyCERT advisory, Scammers using compromised WhatsApp accounts for impersonation
  3. WhatsApp Terms of Service

ReplyKit is an independent product and is not affiliated with or endorsed by Meta or WhatsApp. This article is general security guidance. Follow WhatsApp's current instructions and report crimes to the police and your national cyber security agency.