How Your Number Ends Up in WhatsApp Spam Lists
How WhatsApp spam and bombing tools get your number, which privacy settings close the collection surface, and why an OTP or PIN request on WhatsApp is always a scam.
WhatsApp needs your number, so they collect your number
WhatsApp bombing and spam tools cannot reach a number they do not have. Unlike a phone call, which can be placed to any dialable number, a WhatsApp message requires a registered account on that number. So the entire industry of WhatsApp spam runs on a supply chain of collected phone numbers.
Understanding that supply chain tells you exactly which settings matter, because each setting closes a different collection surface.
The surfaces your number is visible on
Your number is exposed wherever you have not restricted visibility. The main ones are your profile picture, your status updates, the About section, and any group where your number is visible to members you do not know.
A scraper does not need to break anything. It reads what is publicly available, and it only needs a partial number to confirm a match. Closing these surfaces removes most of the supply.
- Profile photo visible to everyone: closes with My contacts
- About section visible to everyone: closes with My contacts
- Status updates: closes with My contacts except for selected people
- Group member lists: restrict who can add you, and leave unknown groups
- Last seen and Online: closing these also reduces a profile-completion signal
The exact settings to change
In WhatsApp, go to Settings, then Privacy. Set Last seen and Online to Nobody. Set Profile photo to My contacts. Set About to My contacts. Set Groups to My contacts, so only people you have added can add you to a group. Turn off Read receipts.
Each of these takes about fifteen seconds in total, and together they close every surface a scraper reads.
- Settings, then Privacy, then Last seen and Online, set to Nobody
- Settings, then Privacy, then Profile photo, set to My contacts
- Settings, then Privacy, then About, set to My contacts
- Settings, then Privacy, then Groups, set to My contacts
- Settings, then Privacy, then Read receipts, turned off
The flood is usually a phishing delivery mechanism
Once a scraper has your number, there are two things they can do. Send spam, which is irritating. Or send a targeted phishing message, which is profitable. The second is why WhatsApp spam has become much more sophisticated than SMS spam ever was.
A typical flow is a message that looks like a delivery notification, a bank alert, a job offer or a prize, with a link. The link goes to a convincing copy of a real site, and the goal is an OTP you then enter on the phishing page, which completes the account takeover on the real site.
The rule that catches every scam
If a WhatsApp message asks for an OTP, a PIN, a password, a UPI PIN or a card detail, it is a scam. Every time, without exception. No bank, no employer, no courier, no government department and no prize scheme ever asks for any of these over WhatsApp.
If you receive one, do not use the link. Open the app or the website yourself, by typing the address or using the official app, and check whether anything is actually pending. It almost never is.
If you already clicked
Close the page immediately. Do not enter anything, even if it seems to be asking for a detail you have already given. Then revoke any session the page opened, and if you did enter an OTP, call your bank on its official number and report an unauthorised transaction.
Also change your WhatsApp two-step verification PIN if you ever shared it, and check linked devices under Settings, then Linked devices, logging out anything you do not recognise.