Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days on the annual plan.Learn More
MERENA
Advisory Alert

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Researchers say suspected Russian groups are targeting specific people in government, research, defense, and policy organizations by misusing trusted sign-in and account-linking features from Google and WhatsApp. The goal is to trick people into approving access to their accounts without realizing it.


Who is at risk

People working in government, universities, think tanks, aerospace, and defense organizations in Europe and the U.S. are at the highest risk, especially if they are publicly visible or handle sensitive information.

What to watch for

Watch for unexpected sign-in approvals, requests to connect your account to another app or service, or unusual WhatsApp messages asking you to verify, link, or approve access.

What to do

Immediately review connected apps and active sign-ins for your Google and WhatsApp accounts, remove anything you do not recognize, and change your password if you see suspicious activity.