According to the Guardia Civil, nearly 50 cyberattack complaints involving zero-click WhatsApp exploits have been filed across the Spanish province of Huelva since late August, targeting iOS mobile devices. The stealthy campaign allows attackers to siphon chat histories and impersonate victims without requiring any user interaction.
Zero-Click WhatsApp Attacks Target iOS Users in Huelva
Investigators from the Guardia Civil report that the security breaches rely on a zero-click methodology. According to local law enforcement notes, the attack executes invisibly on the victim’s device without requiring the user to click a malicious link, scan a QR code, or hand over a verification token. Once inside, the attacker gains illegitimate access to all private conversations.
How the WhatsApp Impersonation and Financial Fraud Works
Following the unauthorized intrusion, operators maintain simultaneous access to the victim’s messaging threads while the real owner remains unaware. Attackers frequently send urgent requests for money transfers or demand app verification codes to cascade the account takeovers further across the region. Because the messages originate from a legitimate, trusted phone number, contacts routinely fall victim to the social engineering trap.

Vulnerable Devices and Official Security Guidance
Forensic analysis by the Guardia Civil indicates that the exploited security gaps specifically impact iPhone models running outdated operating systems, specifically iOS 16.7.12 and earlier versions. To counter the threat, the Spanish security agency urges users to immediately verify their software settings and update both the iOS operating system and WhatsApp to the latest available releases. Security teams also advise activating two-step verification, regularly inspecting the linked devices menu to terminate unrecognized sessions, and ignoring any money transfers requested solely through messaging apps until verified via an independent phone call.