HomeTechnology3.5 billion WhatsApp phone numbers allegedly visible online through flaw, but Meta says there was no breach

3.5 billion WhatsApp phone numbers allegedly visible online through flaw, but Meta says there was no breach

Researchers from the University of Vienna reportedly scraped 3.5 billion WhatsApp phone numbers using a flaw in the Click to Chat feature, raising global privacy concerns. Meta, however, denies any data leak and says no non-public data was exposed. Here’s what happened, what researchers found, and how WhatsApp responded.

November 21, 2025 / 12:27 IST
Story continues below Advertisement
whatsapp
whatsapp

WhatsApp is facing fresh scrutiny after reports claimed that a major privacy flaw may have exposed the phone numbers and profile photos of as many as 3.5 billion users worldwide. The issue was highlighted by cybersecurity researchers at the University of Vienna, who say they were able to gather billions of phone numbers using what they describe as a “simple” method that exploited WhatsApp’s contact-discovery system.

According to the researchers, the problem was linked to WhatsApp’s “Click to Chat” feature — the tool that lets users start a conversation without saving a number. When these links were generated, the associated information occasionally became visible in publicly searchable URLs. This meant that user data like phone numbers, profile pictures and even names could be accessed by external websites, search engines or third-party tools.

Story continues below Advertisement

Since WhatsApp has more than two billion users globally, the scale of the potential exposure raised alarms. Privacy experts warn that even the leak of a phone number can open the door to spam calls, scams, impersonation attempts and targeted harassment. The idea that such basic information might have been accessible to anyone who knew where to look has sparked concerns over how secure everyday messaging platforms really are.

However, Meta — WhatsApp’s parent company — has strongly pushed back against claims of a “data leak”. Through its official Bug Bounty program, Meta said the reports were misleading and that no non-public data was ever exposed.