

It is impossible to know for certain what the intentions of each of the breached parties was in terms of a search engine index, however. However, many of the WhatsApp phone numbers revealed in Google search appeared to be standard cellular or landline numbers that spammers and scammers could simply make direct calls to without using the platform. The company also claimed that owners of WhatsApp phone numbers have the option to automatically block contact attempts from unknown parties. And though these pages generally do not contain personally identifying information, some were found to include user profile pictures.įacebook rejected a bug bounty report on this issue and downplayed it, claiming that the only numbers available are those that the owners have opted to make public. This will likely be used for spam purposes or blanket attempts by threat actors, and if WhatsApp users accept these calls or chat requests they might inadvertently provide the other party with some of their identifying information. This file is also missing from the domain that the “click to chat” feature makes use of.Ĭlicking through any of the Google search results does not necessarily provide any information on the identity of the WhatsApp user, but it does allow anyone logged into the platform to attempt to initiate a chat with these users. Security researcher Athul Jayaram discovered that wa.me does not have the “robots.txt” file that is used to limit the portions of the site that the Google search spiders can index. Businesses often connect this feature to a scannable QR code to quickly provide potential customers with a contact number.

Wa.me is a convenience domain that is primarily used for “click to chat” links to user accounts, which let platform users initiate chats with other users whose names are not saved in their contact lists.

If one does a site-specific search for the domain “” and enters common dialing prefixes, Google search results return an indiscriminate list of these WhatsApp phone numbers visible in plain text. WhatsApp phone numbers visible through Google search By searching using an alternate shortened URL for the service, one can get a list of over 300,000 phone numbers currently in use on the platform.
