WhatsApp and Microsoft users are increasingly being targeted through fake login requests and authentication-based cyberattacks. In such attacks, cybercriminals send a login alert or authentication request to a user’s phone or computer that may appear legitimate at first glance. If the user hurriedly approves the request, the attacker could gain unauthorized access to the account.
In these attacks, criminals do not necessarily need to steal the password directly. Instead, they attempt to manipulate the user into completing the authentication process themselves. This makes user awareness particularly important even when strong passwords and multi-factor authentication (MFA) are enabled.
How Does the Fake Login Request Scam Work?
The attack typically begins with an attempted login to an account. The user may then receive an authentication prompt or login alert that appears to have been generated by the legitimate service.
If the user assumes that the request is connected to a login they initiated and approves it without checking, the attacker may get an opportunity to access the account.
In some cases, criminals may also use verification codes, device codes or other authentication mechanisms to confuse users and persuade them to complete the process.
Microsoft accounts can be particularly valuable targets because they may provide access to email, cloud storage, documents and other connected services. Recent cybersecurity analysis has also highlighted the misuse of authentication features and legitimate login processes by attackers.
WhatsApp Accounts Also at Risk
WhatsApp accounts can also be targeted through social engineering techniques. Attackers may try to convince users that an account verification or device-linking process is underway and persuade them to approve a request that they did not initiate.
The biggest vulnerability in such cases is often not a technical weakness but the user’s trust and haste. Criminals may create a sense of urgency by claiming that an account is about to be blocked or that immediate verification is required.
Once a user follows the attacker’s instructions, the security of the account can be compromised.
Why a Strong Password May Not Be Enough
Renowned cyber crime expert and former IPS officer Prof. Triveni Singh said authentication-based scams often attempt to bypass security by manipulating the user rather than directly breaking the security system.
He advised users not to approve an unfamiliar login prompt, verification request or device approval simply because it appears official or familiar. Users should independently verify the activity before taking any action.
If a person has not initiated a login, the request should be rejected. The user should then open the official application or website independently and check the account’s recent activity and security settings.
How to Stay Safe From a Wrong Click
Users should never approve an unfamiliar login request without first verifying its source. If they have not initiated the login, the request should be rejected.
Users should also:
- Never share OTPs, verification codes, passwords or authentication codes with anyone.
- Avoid approving authentication requests made at another person’s instruction.
- Enable two-factor authentication or multi-factor authentication wherever available.
- Use passkeys and other modern authentication features where supported.
- Check account activity directly through the official application or website.
- Avoid clicking login or security links received through unexpected messages.
If an unfamiliar sign-in appears on a Microsoft account, users should independently access Microsoft’s official security page and review recent activity. Similarly, any unexpected WhatsApp device-linking or verification request should be treated with caution.
Cybercriminals Are Constantly Changing Their Tactics
Cyberattacks are no longer limited to fake websites and fraudulent login pages. Criminals are increasingly attempting to misuse legitimate authentication systems, device codes, OAuth permissions and account-linking features. Such tactics can make attacks harder to identify because the underlying security process may appear genuine.
This makes user awareness a critical layer of account protection. A login alert should never be approved merely because it looks legitimate.
Before approving any authentication request, users should ask one simple question: “Did I initiate this login?”
If the answer is no, the safest response is to reject the request, independently check the account and investigate any unusual activity.