Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Possible SS7 + WhatsApp metadata surveillance – need expert input

published on 2025-09-05 18:54:35 UTC by /u/RefrigeratorLanky642
Content:

Hi everyone,

I’ve been a victim of targeted cyberstalking for years and I need to share my experience to understand if what happened to me points to SS7 abuse alone, or if there had to be someone with privileged access inside Meta (WhatsApp).

Here are the facts: • I used two numbers: • One SIM only for data. • A different number for WhatsApp, but the SIM itself was not in the phone (still active with the carrier, not blocked). • I was never disconnected from my WhatsApp. • This means my account was never fully cloned using SS7 (since that would disconnect me). • Still, my stalkers somehow knew all the new contacts I talked to on WhatsApp, including people I met on Tinder. • They didn’t know those numbers beforehand. • So simple correlation at the carrier level seems impossible. • My suspicion: 1. They were using SS7 for surveillance (location, SMS interception, monitoring my SIM’s traffic patterns). 2. At the same time, they had access to WhatsApp metadata (number A ↔ number B, timestamps). • This would explain how they knew all my new contacts, without prior knowledge of their numbers. • Important detail: • I always had 2FA (PIN) enabled. • I even tested registering my number on another phone, intercepted the SMS, but without the PIN the session never completed. • Despite that, I once saw real messages appear on the second phone — which left me wondering about some kind of “silent pre-login” bug.

My questions for the community: 1. Is it technically possible to access WhatsApp metadata (who talks to who) without insider or official Meta access? 2. Could SS7 + carrier-level monitoring alone explain how they mapped all my new contacts? 3. Have there been documented cases of “silent pre-login” where WhatsApp sessions were duplicated without disconnecting the victim? 4. From a defense standpoint, am I correct that moving to Signal (with usernames) and Session fully mitigates this kind of metadata exposure?

I’d really appreciate insights from anyone who works with telecom security, SS7, or has deep knowledge of WhatsApp’s metadata handling.

Thanks for reading.

submitted by /u/RefrigeratorLanky642
[link] [comments]
Article: Possible SS7 + WhatsApp metadata surveillance – need expert input - published 30 days ago.

https://www.reddit.com/r/netsec/comments/1n9dq5p/possible_ss7_whatsapp_metadata_surveillance_need/   
Published: 2025 09 05 18:54:35
Received: 2025 09 05 18:59:24
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 11

Custom HTML Block

Click to Open Code Editor