Econet Wireless Zimbabwe has called on its subscribers to tighten the security settings on their WhatsApp accounts, warning that hackers and social-engineering fraudsters are increasingly targeting mobile users across the country.
The mobile network operator said account hijackings have become one of the fastest-growing forms of mobile fraud, with criminals using hijacked profiles to borrow money from contacts, spread malicious links and gain access to linked banking and mobile-money services.
Why WhatsApp is the frontline of mobile fraud
For millions of Zimbabweans, WhatsApp has stopped being just a chat app. It is the marketplace where traders in Mbare and Glen View take orders, the channel families use to send money requests, and often the only reliable way small businesses in Harare communicate with clients.
That dependence is precisely what makes the platform attractive to criminals. Once an account is taken over, the attacker inherits the victim’s contact list, chat history and the trust that comes with a familiar name and profile picture.
The steps Econet wants customers to take
The operator has been pushing security guidance through SMS and its social media platforms. Its core message is that customers should secure their accounts before an attack happens, rather than trying to recover them afterwards.
- Switch on passkeys and two-step verification, including a six-digit PIN and a recovery email address.
- Never share verification codes or security PINs with anyone, no matter who they claim to represent.
- Check which devices are linked to the account and remove any that are unfamiliar.
- Keep WhatsApp updated so the latest security patches are installed.
- Review call-forwarding settings and disable any forwarding that was not set up deliberately.
- Avoid dialling unverified USSD codes, particularly those beginning with * or **.
- Do not scan QR codes or pairing codes from unknown sources, including third-party websites and public displays.
- Log out of WhatsApp Web sessions that are no longer in use.
- Treat messages that create a sense of urgency with suspicion, especially if they ask for confidential information.
- Do not click links simply because they appear to come from a known contact.
- Verify any request for money, account details or verification codes by phoning the person directly before acting.
How the scams usually unfold
Most hijackings do not rely on sophisticated hacking. They rely on conversation. A typical approach involves a fraudster posing as a friend or relative who claims to have sent a code to the wrong number and asks the victim to forward it. The code is in fact the key that lets the attacker register the victim’s number on a new device.
Other variants use cloned profile pictures, fake customer-care agents offering to “fix” an account, or messages warning that a number will be deactivated unless details are confirmed. Criminals also exploit phones left unattended and QR codes displayed in public places, which can silently link a victim’s account to a stranger’s computer.
What to do if your account is taken over
Victims should act quickly to limit the damage. Re-register the number using the verification code sent by SMS, which normally forces the intruder off the account. Contacts should be alerted immediately so they do not fall for money requests sent from the compromised profile.
It also helps to review mobile-money and banking apps linked to the number, change any passwords that may have been exposed in chats, and report the incident to the service provider so the number can be monitored for further suspicious activity.
Small businesses are the most exposed
Traders, haulage operators, landlords and informal businesses that run their operations through WhatsApp carry the highest risk. Many hand their phones to employees or relatives to manage orders, and some share PINs with assistants for convenience — a practice security advisers say should stop.
Businesses are being encouraged to keep customer conversations on a dedicated device, avoid saving banking credentials in chat threads and treat any unsolicited request to re-register or verify a number as a red flag.
The warning comes as mobile fraud continues to evolve faster than many users update their settings. For Econet, the message is straightforward: the tools to block most hijackings already sit inside the app, but they only work if customers switch them on.





