---
title: The Cost Implications of the WhatsApp Hack
description: The attackers could eavesdrop on users’ phones by simply placing a special WhatsApp call to the device. The user didn’t even have to answer it.
image: https://reflare.com/hubfs/Blog%20image%20in%20post/The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack.png
---

[![Reflare home](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=421&height=150&name=reflare%20logo.png "Reflare home")](https://reflare.com)

[![logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png?width=262&height=82&name=logo.png "logo")](https://reflare.com/act3)

[![reflare logo](https://reflare.com/hs-fs/hubfs/Reflare%20website%20images/Reflare%20Logos/reflare%20logo.png?width=168&height=60&name=reflare%20logo.png "reflare logo")](https://reflare.com/act3)

- [Galena](https://reflare.com/galena) 
    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training 
    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit 
    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research) 
    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about) 
    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Login](https://reflare.com/login)

[Buy Now](https://www.hubspot.com/)

[Login](https://www.hubspot.com/)Login to your Reflare account

- [Galena](https://reflare.com/galena)

    - [Galena Overview](https://reflare.com/galena)
    - [Galena for Tech Teams](https://reflare.com/technical-teams)
    - [Galena for L&D Teams](https://reflare.com/learning-development)
    - [Galena Security and Deployment](https://reflare.com/security-deployment)
- Training

    - [Capture the Flag](https://reflare.com/rctf-reflare-capture-the-flag)
    - [Developers](https://reflare.com/rcsd)
    - [Administrators](https://reflare.com/rcsa)
    - [PCI DSS](https://reflare.com/rcsd)
- Audit

    - [PCI DSS](https://reflare.com/pcidss)
    - [PCI 3DS](https://reflare.com/pci3ds)
    - [PCI PIN](https://reflare.com/pcipin)
    - [PCI DSS ASV](https://reflare.com/pcidssasv)
    - [Penetration Testing](https://reflare.com/penetration)
    - [Vulnerability Scanning](https://reflare.com/vulnerability)
    - [Advisory and Management](https://reflare.com/advisory)
- [Research](https://reflare.com/research)

    - [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)
    - [High Tech](https://reflare.com/research/tag/high-tech)
    - [Infosec Culture](https://reflare.com/research/tag/infosec-culture)
    - [Infrastructure](https://reflare.com/research/tag/infrastructure)
    - [Normal People and Infosec](https://reflare.com/research/tag/normal-people-and-infosec)
    - [WTFWIB](https://whythefuckwasibreached.com/)
- [About](https://reflare.com/about)

    - [Contact](https://reflare.com/contact)
    - [Company](https://reflare.com/about)
    - [Careers](https://reflare.com/careers)
    - [Service Status](https://statuspage.reflare.com/)
- [日本語](https://jp.reflare.com/)

[Buy Now](https://www.hubspot.com/)

<https://reflare.com/research> Research

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack&text=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack&t=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack&t=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack)

# The Cost Implications of the WhatsApp Hack

 by [**Reflare Research Team**](https://reflare.com/research/author/reflare-research-team) on May 21, 2019, 5:28:00 PM

What’s perhaps most concerning is the ease with which this attack was carried out. The attackers were able to eavesdrop on users’ phones by simply placing a special WhatsApp call to the device. The user didn’t even have to answer it.

First Published 21st May 2019

![The Cost Implications of the WhatsApp Hack](https://reflare.com/hs-fs/hubfs/Blog%20image%20in%20post/The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack.png?width=672&height=448&name=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack.png)

*That feeling when the Israelis ghost you right after texting "I love you".*

4 min read  |  Reflare Research Team

Early last week, reports of WhatsApp being targeted by attackers [were reported](https://www.bbc.com/news/technology-48262681) in the media. Since then, more details about the creator of the attack and their motivations for it have surfaced. In this briefing, we will provide you with a summary of the incident and then take a look at an element overlooked in the current coverage - the cost of development and what it means for information security.

## What happened?

The [Financial Times first reported](https://www.ft.com/content/4da1117e-756c-11e9-be7d-6d846537acab) that attackers were able to eavesdrop on users’ phones by simply placing a special WhatsApp call to the device. The user didn’t even have to answer it. Preliminary investigations by both Facebook (the owner of WhatsApp) and media sources revealed that the attack was developed by Israeli surveillance technology company [NSO Group](https://en.wikipedia.org/wiki/NSO_Group). The company was previously best known for its surveillance suite “Pegasus” which it licenses to government agencies. Facebook has since [issued a CVE](https://www.facebook.com/security/advisories/cve-2019-3568) for the vulnerability and has released updates to mitigate it.

## What does the CVE say?

The CVE is short and worth being covered in its entirety.

**Description: A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number.**

In plain language this means that a coding mistake in the part of the application that handles calls on the lowest level allowed attackers to execute arbitrary code. Since these low level functions are used even before the user answers the call (they are the sort of functions needed to make the phone ring in the first place), the attack could stay completely hidden - which is what media outlets are reporting.

Affected Versions: The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15.

In short, the current versions of WhatsApp were affected on all major mobile platforms. Notably, there is no mention of the version of the device’s OS or any requirement for it to be jailbroken. We will return to these points in the next segment.

Buffer overflow vulnerabilities in something as complex as VoiP software are - unfortunately - common. A lot of the low-level progress in information security over the past decade has tried to prevent this specific attack.

## Who used the attack?

In theory, NSO Group only sells their products to approved law enforcement agencies. These agencies then use the tools as they see fit. A notable example was the arrest of Mexican drug kingpin El Chapo, who was in part captured [because the Pegasus surveillance software was used](https://www.ynetnews.com/articles/0,7340,L-5444330,00.html). No further details are available at this point in time. It is however important to note that government agencies in many countries do not require court approval to perform cyber-attacks against non-citizen suspects, and that any tool used without oversight is prone to abuse. At this moment the most poignant example may be the confirmed [targeting of a lawyer](https://www.nytimes.com/2019/05/13/technology/nso-group-whatsapp-spying.html?action=click&module=Top%20Stories&pgtype=Homepage) litigating against NSO group. While it is possible that the lawyer in question was targeted by UK law enforcement for reasons unrelated to the case, the fact that NSO’s tools were effectively used to attack one of their opponents - whether legally or not - creates all sorts of moral issues.

## The overlooked cost argument

What struck us when researching this case is the immense cost that such an exploit would entail. Since the attack appears to persist across restarts of the application, these devices have to either be re-infected regularly or the attack must permanently embed itself into the device. Constantly re-infecting devices would require a massive organizational effort and precise timing while incurring a significant risk of detection. Doing so well, would require an immense level of organizational structure, skill and money.

However, the alternative would be even more expensive. All major mobile operating systems use a technology called Sandboxing, where applications run inside a private environment and are prevented from communicating with other software. The contents of this sandbox are verified using cryptographic algorithms, meaning that they cannot be changed.

The process of bypassing these safeguards is commonly known as “Jailbreaking”. While some Android devices can enable “root” mode through specific user actions, most other devices don’t allow direct system access for the user under any circumstances. Quite complicated exploits are required to circumvent all of the device’s protections and gain raw control.

This is where the large number of operating systems and lack of minimum versions comes in. If only a small number of older operating systems were supported, the cost of the attack would be relatively low. After all, jailbreak exploits for - for example - iOS 9 are readily available. However, there seem to be no version requirements for the attack to work. If this is not an oversight (or purposeful omission) on Facebook’s end, this would indicate that NSO Group is in possession of not publicly known jailbreak exploits for the newest versions of all mobile operating systems.

While such vulnerabilities and exploits certainly exist, and while a company specializing in mobile surveillance would be just the kind of company to own them, it is worth it to consider the cost involved: Unknown vulnerabilities that can lead to full system access to the latest versions of mobile operating systems can easily cost millions of US dollars. With a large number of operating systems and versions covered, exploits worth US$50m - US$100m may well be in use.

Of course, there is always a chance that only specific versions of older operating systems are supported and that this information has not yet made it to the public.

## What can I do?

As a first step, you should manually update the WhatsApp Application installed on your phone. If you believe that you may have been targeted by the attack, it would also be good practice to perform a factory reset on your device. This is likely - but not guaranteed - to remove all persistent malware.

If you are dealing with very highly classified information and using WhatsApp then a change of Phones would be the only reasonable course of action to rule out that left-over malware puts your information at risk.

Topics: [Anatomy of a Breach](https://reflare.com/research/tag/anatomy-of-a-breach)

#### Share this

[Share on Twitter](https://twitter.com/share?url=https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack&text=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack&t=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack&t=The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack)

- Recent
- Topics
- Archive

Recent

Topics

- [Infosec Culture (113)](https://reflare.com/research/tag/infosec-culture)
- [Anatomy of a Breach (60)](https://reflare.com/research/tag/anatomy-of-a-breach)
- [Normal People and Infosec (42)](https://reflare.com/research/tag/normal-people-and-infosec)
- [High Tech (33)](https://reflare.com/research/tag/high-tech)
- [Infrastructure (21)](https://reflare.com/research/tag/infrastructure)
- [Capture the Flag (8)](https://reflare.com/research/tag/capture-the-flag)

See all

Archive

- [September 2026 (1)](https://reflare.com/research/archive/2026/09)
- [August 2026 (1)](https://reflare.com/research/archive/2026/08)
- [June 2026 (1)](https://reflare.com/research/archive/2026/06)
- [May 2026 (1)](https://reflare.com/research/archive/2026/05)
- [April 2026 (1)](https://reflare.com/research/archive/2026/04)
- [March 2026 (1)](https://reflare.com/research/archive/2026/03)
- [February 2026 (1)](https://reflare.com/research/archive/2026/02)
- [January 2026 (1)](https://reflare.com/research/archive/2026/01)
- [December 2025 (1)](https://reflare.com/research/archive/2025/12)
- [November 2025 (1)](https://reflare.com/research/archive/2025/11)
- [October 2025 (1)](https://reflare.com/research/archive/2025/10)
- [September 2025 (1)](https://reflare.com/research/archive/2025/09)
- [August 2025 (1)](https://reflare.com/research/archive/2025/08)
- [July 2025 (1)](https://reflare.com/research/archive/2025/07)
- [June 2025 (1)](https://reflare.com/research/archive/2025/06)
- [May 2025 (1)](https://reflare.com/research/archive/2025/05)
- [April 2025 (1)](https://reflare.com/research/archive/2025/04)
- [March 2025 (1)](https://reflare.com/research/archive/2025/03)
- [February 2025 (1)](https://reflare.com/research/archive/2025/02)
- [January 2025 (1)](https://reflare.com/research/archive/2025/01)
- [December 2024 (1)](https://reflare.com/research/archive/2024/12)
- [November 2024 (1)](https://reflare.com/research/archive/2024/11)
- [October 2024 (1)](https://reflare.com/research/archive/2024/10)
- [September 2024 (1)](https://reflare.com/research/archive/2024/09)
- [August 2024 (1)](https://reflare.com/research/archive/2024/08)
- [July 2024 (1)](https://reflare.com/research/archive/2024/07)
- [June 2024 (1)](https://reflare.com/research/archive/2024/06)
- [April 2024 (2)](https://reflare.com/research/archive/2024/04)
- [February 2024 (1)](https://reflare.com/research/archive/2024/02)
- [January 2024 (1)](https://reflare.com/research/archive/2024/01)
- [December 2023 (1)](https://reflare.com/research/archive/2023/12)
- [November 2023 (1)](https://reflare.com/research/archive/2023/11)
- [October 2023 (1)](https://reflare.com/research/archive/2023/10)
- [September 2023 (1)](https://reflare.com/research/archive/2023/09)
- [August 2023 (1)](https://reflare.com/research/archive/2023/08)
- [July 2023 (1)](https://reflare.com/research/archive/2023/07)
- [June 2023 (2)](https://reflare.com/research/archive/2023/06)
- [May 2023 (2)](https://reflare.com/research/archive/2023/05)
- [April 2023 (3)](https://reflare.com/research/archive/2023/04)
- [March 2023 (4)](https://reflare.com/research/archive/2023/03)
- [February 2023 (3)](https://reflare.com/research/archive/2023/02)
- [January 2023 (5)](https://reflare.com/research/archive/2023/01)
- [December 2022 (1)](https://reflare.com/research/archive/2022/12)
- [November 2022 (2)](https://reflare.com/research/archive/2022/11)
- [October 2022 (1)](https://reflare.com/research/archive/2022/10)
- [September 2022 (11)](https://reflare.com/research/archive/2022/09)
- [August 2022 (5)](https://reflare.com/research/archive/2022/08)
- [July 2022 (1)](https://reflare.com/research/archive/2022/07)
- [May 2022 (3)](https://reflare.com/research/archive/2022/05)
- [April 2022 (1)](https://reflare.com/research/archive/2022/04)
- [February 2022 (4)](https://reflare.com/research/archive/2022/02)
- [January 2022 (3)](https://reflare.com/research/archive/2022/01)
- [December 2021 (2)](https://reflare.com/research/archive/2021/12)
- [November 2021 (3)](https://reflare.com/research/archive/2021/11)
- [October 2021 (2)](https://reflare.com/research/archive/2021/10)
- [September 2021 (1)](https://reflare.com/research/archive/2021/09)
- [August 2021 (1)](https://reflare.com/research/archive/2021/08)
- [June 2021 (1)](https://reflare.com/research/archive/2021/06)
- [May 2021 (14)](https://reflare.com/research/archive/2021/05)
- [February 2021 (1)](https://reflare.com/research/archive/2021/02)
- [October 2020 (1)](https://reflare.com/research/archive/2020/10)
- [September 2020 (1)](https://reflare.com/research/archive/2020/09)
- [July 2020 (1)](https://reflare.com/research/archive/2020/07)
- [June 2020 (1)](https://reflare.com/research/archive/2020/06)
- [May 2020 (1)](https://reflare.com/research/archive/2020/05)
- [April 2020 (2)](https://reflare.com/research/archive/2020/04)
- [March 2020 (1)](https://reflare.com/research/archive/2020/03)
- [February 2020 (1)](https://reflare.com/research/archive/2020/02)
- [January 2020 (3)](https://reflare.com/research/archive/2020/01)
- [December 2019 (1)](https://reflare.com/research/archive/2019/12)
- [November 2019 (2)](https://reflare.com/research/archive/2019/11)
- [October 2019 (3)](https://reflare.com/research/archive/2019/10)
- [September 2019 (5)](https://reflare.com/research/archive/2019/09)
- [August 2019 (2)](https://reflare.com/research/archive/2019/08)
- [July 2019 (3)](https://reflare.com/research/archive/2019/07)
- [June 2019 (3)](https://reflare.com/research/archive/2019/06)
- [May 2019 (2)](https://reflare.com/research/archive/2019/05)
- [April 2019 (3)](https://reflare.com/research/archive/2019/04)
- [March 2019 (2)](https://reflare.com/research/archive/2019/03)
- [February 2019 (3)](https://reflare.com/research/archive/2019/02)
- [January 2019 (1)](https://reflare.com/research/archive/2019/01)
- [December 2018 (3)](https://reflare.com/research/archive/2018/12)
- [November 2018 (5)](https://reflare.com/research/archive/2018/11)
- [October 2018 (4)](https://reflare.com/research/archive/2018/10)
- [September 2018 (3)](https://reflare.com/research/archive/2018/09)
- [August 2018 (3)](https://reflare.com/research/archive/2018/08)
- [July 2018 (4)](https://reflare.com/research/archive/2018/07)
- [June 2018 (4)](https://reflare.com/research/archive/2018/06)
- [May 2018 (2)](https://reflare.com/research/archive/2018/05)
- [April 2018 (4)](https://reflare.com/research/archive/2018/04)
- [March 2018 (5)](https://reflare.com/research/archive/2018/03)
- [February 2018 (3)](https://reflare.com/research/archive/2018/02)
- [January 2018 (3)](https://reflare.com/research/archive/2018/01)
- [December 2017 (2)](https://reflare.com/research/archive/2017/12)
- [November 2017 (4)](https://reflare.com/research/archive/2017/11)
- [October 2017 (3)](https://reflare.com/research/archive/2017/10)
- [September 2017 (5)](https://reflare.com/research/archive/2017/09)
- [August 2017 (3)](https://reflare.com/research/archive/2017/08)
- [July 2017 (3)](https://reflare.com/research/archive/2017/07)
- [June 2017 (4)](https://reflare.com/research/archive/2017/06)
- [May 2017 (4)](https://reflare.com/research/archive/2017/05)
- [April 2017 (2)](https://reflare.com/research/archive/2017/04)
- [March 2017 (4)](https://reflare.com/research/archive/2017/03)
- [February 2017 (2)](https://reflare.com/research/archive/2017/02)
- [January 2017 (1)](https://reflare.com/research/archive/2017/01)
- [December 2016 (1)](https://reflare.com/research/archive/2016/12)
- [November 2016 (4)](https://reflare.com/research/archive/2016/11)
- [October 2016 (2)](https://reflare.com/research/archive/2016/10)
- [September 2016 (4)](https://reflare.com/research/archive/2016/09)
- [August 2016 (5)](https://reflare.com/research/archive/2016/08)
- [July 2016 (3)](https://reflare.com/research/archive/2016/07)
- [June 2016 (5)](https://reflare.com/research/archive/2016/06)
- [May 2016 (3)](https://reflare.com/research/archive/2016/05)
- [April 2016 (4)](https://reflare.com/research/archive/2016/04)
- [March 2016 (5)](https://reflare.com/research/archive/2016/03)
- [February 2016 (4)](https://reflare.com/research/archive/2016/02)

See all

### Subscribe by email

#### About Reflare

We help customers increase cyber resilience with the #1 hands-on IT security training platform.

Our developer, administrator, and non-technical user training programs enhance user skills, fulfil your compliance needs, and contribute to developing more secure technologies.

<https://x.com/reflarehq><https://www.linkedin.com/company/reflare-ltd.>

Legal

- [Terms of Service](https://reflare.com/terms)
- [Privacy Statement](https://reflare.com/privacy)
- [Cookie Info](https://reflare.com/cookies)
- [Copyright and Citation Enquiries](https://reflare.com/citation)
- [Contact](https://reflare.com/contact)

 © 2026 Reflare Ltd, and/or its affiliates.   /   In business since 2009.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Reflare Research Team",
    "url" : "https://reflare.com/research/author/reflare-research-team"
  },
  "dateModified" : "2023-11-21T13:11:48.188Z",
  "datePublished" : "2019-05-21T16:28:00.000Z",
  "headline" : "The Cost Implications of the WhatsApp Hack",
  "image" : [ "https://reflare.com/hubfs/Blog%20image%20in%20post/The%20Cost%20Implications%20of%20the%20WhatsApp%20Hack.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://reflare.com/research/the-cost-implications-of-the-whatsapp-hack",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://reflare.com/hubfs/Reflare%20website%20images/Reflare%20Logos/logo.png"
    },
    "name" : "Reflare"
  }
}
```