WhatsApp users across Spain and Italy are confronting a sophisticated cyberattack that exploits view-once media features and Apple software vulnerabilities to bypass security controls and extort money, according to reports from the Catalan media outlet El Caso. The malicious activity spans two distinct tactics: zero-click account takeovers that send fraudulent payment requests to contacts without user interaction, and extortion attempts using ephemeral intimate photos.
Account Takeovers via Software Vulnerabilities
Together, these exploits allow attackers to extract session data and run a parallel WhatsApp client tied to the victim’s account. Forensic analysis conducted by the Italian firm Forenser following cases in May identified continuous resynchronization events where two terminals contested the same account, while the compromised users remained unaware because sent messages failed to appear in their own chat histories.
Extortion Involving View-Once Media
A parallel scam detailed by El Caso uses WhatsApp’s view-once photo and video feature to trap unsuspecting recipients. Attackers using international phone prefixes from countries such as Senegal or Burma send ephemeral media marked with the “1” icon to numbers not stored in their contacts. Once the recipient opens the file—which often displays intimate or sexual content that immediately disappears—the sender initiates a conversation, falsely claims they reached the wrong person, and then accuses the victim of illegally viewing private documents. The fraudsters demand immediate money transfers under threat of police complaints or legal action for invasion of privacy.

Official Guidance and Legal Realities
Spanish law enforcement authorities have stepped in to clarify the legal standing of these encounters. The Policía Nacional confirmed that viewing an unsolicited digital message does not constitute a criminal offense, rendering the threats used by the extortionists entirely baseless. Police advise the public to refuse ephemeral files sent by unknown numbers, immediately cease communication upon receiving intimidation, capture screenshots of the messages and sender numbers as evidence, and block the profiles through the app settings.
How attackers use WhatsApp view-once photo scams
How do attackers initiate the view-once photo scam on WhatsApp?
Attackers send a temporary media file marked with the view-once icon from an unknown foreign or domestic telephone prefix to a target who does not have the sender in their contacts, as detailed in reports from El Caso.
Do victims of the zero-click iPhone exploit see outgoing fraudulent messages on their own phones?
No. reported that compromised users see no record of the messages sent in their name, discovering the breach only when contacts call to report receiving urgent requests for money.
What specific software flaws enable the WhatsApp session hijacking?
noted that the attack combines an Apple image-processing memory corruption vulnerability tracked as CVE-2025-43300 with a WhatsApp synchronization authorization flaw designated as CVE-2025-55177.
Worth a look