In recent weeks, thousands of users in Armenia have faced mass hacks of accounts on WhatsApp and other messengers. Little has been officially said about the scale of the incident, but according to media expert Samvel Martirosyan, the problem is far more serious than it may seem at first glance — and it affects not only WhatsApp, but all popular messaging apps.

“I am not allowed to disclose details right now,” Martirosyan emphasized, “but I can say one thing: thousands of people were affected, and this is a systemic vulnerability that we all need to understand and address together.”

Why messengers are vulnerable

Most users believe that if they never share their password, their account is safe. But with messengers, this assumption is not entirely true.

“When you register with Gmail, Facebook, or Instagram, you have a password,” the expert explains. “And if two-factor authentication is enabled, you get an additional layer of protection. Messengers work differently.”

WhatsApp, Telegram, Viber, and similar services use a phone number as the key to the account by default. When installing the app on a new device, the user enters their number and receives an SMS with a one-time code (OTP — one-time password). Enter the code, and access is granted. This is where the main problem lies.

Phishing and SMS interception: how accounts are taken over

The most common scenario is phishing. The user receives a call or message asking them to “dictate the code” that supposedly arrived for voting, confirmation, or participation in a promotion.

“People do not realize that this code is the key to their account. You enter it somewhere or give it to someone, and your WhatsApp or Telegram is already on someone else’s phone,” the expert notes.

There is also a more dangerous scenario, where the user does not enter anything at all. This involves vulnerabilities in the SMS infrastructure itself. “SMS is a very old technology, and its weak points are known worldwide, but they still have not been fully eliminated. Messages can be intercepted in transit.”

Moreover, as Martirosyan points out, SMS messages containing codes from Facebook, Google, or messengers are often sent not by mobile operators themselves, but by third-party companies — contractors working with major platforms. “If such a company is hacked, it becomes a catastrophe: all those SMS messages can end up in the wrong hands,” he warns.

The expert recalls that in July 2020, many people in Armenia received fake SMS messages allegedly sent on behalf of the Ministry of Defense. It later emerged that an intermediary service provider had been hacked by the Azerbaijani side.

“That is why it is important to understand: there are many ways to steal your account,” Martirosyan says.

What to do: one simple but critically important step

According to the expert, a solution exists and is available to everyone. You need to enable two-factor protection inside the messenger itself.

“The idea is that an SMS code alone is no longer enough. You additionally set a password or PIN code,” he explains.

In WhatsApp, this is a six-digit numeric PIN; in Telegram, it is a full password similar to the one used for email. Even if an attacker intercepts the SMS with the code, they still will not be able to access the account without this password.

Martirosyan urges people to treat this not as an individual issue, but as a collective task.

“If we all enable two-factor protection, messenger accounts will simply stop being stolen. That will be good news for us and bad news for those who make money from hacks,” he says.

In the coming days, the expert promised to publish a series of short video tutorials — separately for each messenger and for different devices, both Android and iPhone — to make the setup process as simple as possible.