“Could you vote for my child?” A small favour can give away your WhatsApp account
A message from someone you know leads to a vote, then asks for a code or QR scan. Learn where to stop and how to secure your account after a mistake.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 14 September 2026
- READING TIME
- 7 min read
- TOPIC
- Human Security
The message comes from someone you know: “Could you quickly vote for my friend’s daughter? She only needs one more vote.” There is no demand for money and no threat. It looks like a tiny favour, complete with a friendly photo and a competition link. That is precisely why the story works.
The trap appears later. The voting page asks for your phone number, a code sent by text or a QR scan from inside WhatsApp. You are not confirming a vote. You may be registering your account on the scammer’s device.
The contact may be real, but the message may not be
These links are often sent from accounts that have already been taken over. The profile picture, name and conversation history are genuine because the scammer is using the owner’s identity. The same lure is then sent to that person’s contacts.
You do not need to decide whether your friend “looks trustworthy”. Judge the requested action instead. An ordinary vote should not need a code that registers your messenger on a new device, or ask you to open the Linked Devices screen. A WhatsApp registration code is for the account, not the competition.
A safe answer is: “Of course, but I’ll call you first.” A short call to the number you already had can establish whether the account owner actually sent the request.
Three moments to pause
The first is an unexpected link, even from a close contact. Opening it does not necessarily mean the account is lost, but do not enter sign-in details or follow further instructions on the page.
The second is a request for a code from a text message. Read the whole message, not just the digits. The service will normally explain what the code does and warn you not to share it.
The third is a QR code. If a site tells you to open WhatsApp, visit Linked Devices and scan something, you are granting another device access to the messenger. A competition has no reason to require that permission.
If you already entered the code or scanned the QR
Open WhatsApp directly, review Linked Devices and log out anything you do not recognise. Enable two-step verification and confirm that your number and recovery details are still yours. If you have lost access, use only WhatsApp’s official account-recovery process.
Warn your contacts through another channel that voting or payment requests may have come from a compromised account. Do not forward the live link. A redacted screenshot and a short description are enough.
If the scammer has already asked someone for a transfer, card details or another payment, that person should contact their bank immediately and report the incident through the appropriate national reporting service.
What workplaces and schools should learn from it
“Do not click links from strangers” is not enough here. The sender is a familiar person and the favour does not sound dangerous. A better rule is that registration codes and device-linking screens always concern your account, whatever story surrounds them.
The same pattern at work might use a survey, an award vote or an attendance confirmation. Staff need an easy reporting route, while support teams need a ready way to warn the organisation without embarrassing the person who clicked.
What the source confirms and what Breachroad recommends
On 10 February 2026, the Singapore Police Force described WhatsApp messages asking recipients to vote for a friend’s child. Its advisory says the fake page requested a phone number and one-time code or a QR scan that actually linked the victim’s WhatsApp account to the scammer’s device. The compromised account was then used to repeat the lure or request money from contacts. These were reports from Singapore, not evidence of a particular campaign in every country.
Breachroad’s recommendation is to judge the action rather than the apparent sender. A request can arrive from a real friend’s account, but a sign-in code is still a sign-in code. A related family scenario is covered in our “Hi Mum, I have a new number” guide. Organisations can practise these calm verification habits through cybersecurity awareness training and phishing simulations.


