Change the linked email (if one was added by the attacker)
Settings → Account → Email address
Check "Privacy" settings — make sure profile photo, status, and Last Seen visibility haven't been changed
Alert contacts — warn friends/family that the account may have been compromised and to ignore any suspicious messages they received
Step 3 — If your friend can't access their account at all
If the hacker already re-registered the number on their device:
Re-verify the phone number — open WhatsApp, enter the phone number, and request the 6-digit SMS code. This will automatically log the hacker out.
If the hacker enabled two-step verification with their own PIN, your friend needs to contact WhatsApp Support and wait 7 days for the PIN lock to expire.
Key takeaway
The fastest security action is re-verifying the phone number via SMS — this kicks out anyone else using the account on any device instantly.
This is a shared conversation. Sign in to Orris to start your own chat.