VIENNA, AUSTRIA – A research team from the University of Vienna and cybersecurity institute SBA Research uncovered a massive leak of publicly accessible WhatsApp user data, affecting roughly 3.5 billion profiles worldwide. The researchers described it as likely the largest dataset ever retrieved from the messaging service in terms of individuals affected.
Researchers retrieve billions of profiles without hacking
Using automated techniques, the team successfully downloaded phone numbers, profile details, and public encryption keys from the platform’s servers. The process required no breach of encryption or interception of messages — all data had been accessible through publicly visible user information.
According to the group, the discovery demonstrated that the entire global directory of WhatsApp accounts could be enumerated, allowing detailed analysis of users by country, platform type, and account characteristics.
Meta’s slow response
The researchers said they alerted Meta Platforms, WhatsApp’s parent company, several times from September 2024 onward. Their warnings were reportedly acknowledged but not acted upon until just before the team’s academic paper neared publication.
Meta later characterized the incident as “scraping” of publicly available data and stated that all information collected by the researchers had since been securely deleted. The company insisted there was no indication of malicious use by any outside actors and reiterated that end-to-end encryption protecting messages remained unaffected.
In its statement, Meta thanked the Viennese team for its contribution through the company’s bug bounty program, calling the study “valuable for evaluating new anti-scraping defences.”
Public data with private consequences
The analysis revealed account information that, while technically public, could expose individuals to serious personal and political risk. About 30 percent of global users had filled out the “Info” field with text often containing sensitive clues — from political or religious views to sexual orientation or substance use.
Researchers also found listings where drug dealers advertised their products, as well as details linking to Tinder, OnlyFans, or professional networks. Many accounts contained email addresses from government and military domains such as state.gov and .mil, raising the potential for targeted attacks, identity theft, or doxxing.
Widespread use despite national bans
The dataset also shed light on how WhatsApp continues to be used in countries where it is formally banned. At the time of measurement in December 2024, the researchers recorded active accounts in:
• 2.3 million in China
• 60 million in Iran
• 1.6 million in Myanmar
• 5 in North Korea
While the small number in North Korea may belong to state entities, the presence of millions of users in other restricted markets suggested significant underground activity. The researchers warned that systematic enumeration of numbers could endanger users in authoritarian states, where detection of WhatsApp use might carry severe repercussions.
After Iran lifted its ban in late 2024, the number of active Iranian accounts rose to 67 million within three months, with a notable increase in multi-device usage — including workplace logins.
Faces behind the numbers
Beyond textual data, the team accessed profile pictures for about 57 percent of all users, equivalent to multiple terabytes of image data. For the North American region alone, they downloaded 77 million publicly visible profile pictures — roughly 3.8 terabytes in total. Facial-recognition testing detected human faces in about two-thirds of a 500,000-image sample.
Such material could, in principle, be combined into searchable databases linking faces to phone numbers, exposing both private individuals and public officials. Even non‑portrait photos often contained identifying information such as car plates or street signs.
Behavioural patterns through device data
Each WhatsApp account can connect up to five devices. By observing the unique identifiers assigned to those devices, the researchers learned how accounts were used — whether linked to a stable set of phones or frequently changing. Combined with numbers, profile information, and pictures, these indicators allowed for a high‑resolution digital profile of individual users.
Meta reassures, but researchers warn of structural risks
Meta reiterated that no evidence suggested criminal exploitation and that researchers’ copies were permanently erased. However, the Viennese team described the findings as proof of a structural vulnerability within large-scale messaging ecosystems—namely, that vast amounts of “public” data can be aggregated and analyzed in ways most users never anticipate.
Cybersecurity experts caution that such systematic scraping, if performed by hostile actors, could be used for:
• surveillance and intelligence gathering
• targeted extortion or harassment
• fraud and identity abuse
“EVEN WHEN INFORMATION IS PUBLIC BY DEFAULT, ITS MASS COLLECTION CAN CREATE RISKS FAR BEYOND WHAT USERS UNDERSTAND,”
one researcher emphasized.
The case has reignited debate across the digital security community over how privacy can be safeguarded in platforms dependent on phone-number‑based identity systems — and how much “public” data should truly remain accessible at scale.
