Latest News
‘Zero-click’ WhatsApp attack hits iPhones in Sri Lanka, CERT warns

A sophisticated “zero-click” cyberattack capable of hijacking WhatsApp accounts without any action by the victim has reportedly reached Sri Lanka, with several individuals, including members of the media and business community, lodging complaints with the Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT).
The attack is particularly concerning for iPhone users running vulnerable versions of iOS, as it reportedly enables cybercriminals to take control of WhatsApp accounts without requiring victims to click on a malicious link, scan a QR code or knowingly provide their credentials.
Sri Lanka CERT has received complaints from victims whose WhatsApp accounts were apparently compromised, with the attackers subsequently sending messages to their contacts requesting money transfers.
In some cases, the attackers were also able to take control of WhatsApp groups administered by the victims, raising fears that the compromised accounts could be used to deceive large numbers of contacts or spread further malicious content.
According to findings from a forensic investigation by an Italian cybersecurity firm, the attackers may be exploiting a combination of vulnerabilities associated with WhatsApp’s linked-device synchronisation mechanism.
What makes the attack particularly alarming is that victims reportedly found no suspicious linked devices listed in their WhatsApp account settings, making the compromise considerably more difficult to detect through the usual security checks.
The attack is believed to affect iPhones running iOS versions below 16.7.12, according to the information provided to Sri Lanka CERT.
Unlike conventional WhatsApp account-takeover scams, which generally depend on victims being tricked into sharing verification codes or scanning fraudulent QR codes, the latest attack reportedly requires no user interaction at all.
Sri Lanka CERT has urged users to take immediate steps to protect their devices and accounts, including updating their iPhones to the latest supported version of iOS and installing the latest version of WhatsApp.
Users have also been advised to activate WhatsApp’s two-step verification and Chat Lock features and to remain particularly cautious about unexpected requests for money, even when such requests appear to come from trusted friends, colleagues or family members.
Sri Lanka CERT further advises users to independently verify unusual financial requests through another trusted communication channel before transferring any money.
Cybersecurity experts have warned that the reported incident highlights the growing sophistication of financially motivated cybercriminals, who are increasingly turning to “zero-click” exploitation techniques that can compromise devices and accounts without victims knowingly doing anything wrong.
The reported attacks also underscore the risks faced by users who continue to operate mobile devices and applications with outdated security patches.
iPhone users in Sri Lanka who have not updated their devices should therefore check their iOS version immediately and install all available security updates.
RELATED NEWS
View all

Latest News
New Chinese ambassador arrives in Sri Lanka, pledges stronger ties
Aug 11, 2026

Latest News
Six planets to light up Lankan skies before dawn
Aug 11, 2026

Latest News
Rajitha indicted over Rs.20m Kirinda harbour deal
Aug 11, 2026

Latest News
US$3.04m fuel tank project cleared for Muthurajawela
Aug 11, 2026



