Security researchers recently uncovered a worrying trend: sophisticated hacking groups are no longer relying purely on fake login pages or malware to break into accounts. Instead, they’re tricking people into approving legitimate-looking sign-in requests and device connections that Google and WhatsApp themselves provide. As reported by The Hacker News, suspected Russian cyber espionage groups have been abusing Google’s OAuth authentication system and WhatsApp’s device-linking feature to hijack accounts belonging to people in academia, government, aerospace, and think tanks. While that specific campaign targets high-profile individuals, the technique itself is far from exclusive to nation-state hackers – and it’s exactly the kind of trick that could just as easily land in the inbox of a Gippsland business owner.
Here’s the important part for small business owners: you don’t need to be a defence contractor or a university researcher to be targeted this way. Once a technique like this proves effective, it filters down to everyday cybercriminals within months. If your business relies on Google Workspace for email and files, or WhatsApp for customer communication (which many regional trades, hospitality, and retail businesses do), it’s worth understanding exactly how this attack works.
OAuth is the technology behind those “Sign in with Google” or “Connect your account” buttons you see everywhere online. It lets one app ask for permission to access parts of another app – for example, allowing a calendar tool to read your Google Calendar, or a marketing platform to send emails on your behalf. When you click “Allow,” you’re granting real, ongoing access without ever handing over your password.
That’s exactly what makes it dangerous in the wrong hands. Attackers send a link or invitation that looks like a normal Google sign-in or app connection request. Because the request is genuinely coming from Google’s own authentication system, it doesn’t look suspicious – there’s no dodgy fake login page, no misspelled domain, none of the usual red flags people are trained to spot. The victim simply clicks “Allow” on what appears to be a harmless request, and the attacker gains ongoing access to their account, often without ever needing the password at all.
WhatsApp lets you use the same account on multiple devices via a QR code or link-code feature – handy if you want WhatsApp open on your laptop as well as your phone. Attackers have worked out they can trick people into scanning a QR code or approving a device link that actually connects the attacker’s own device to the victim’s WhatsApp account.
Once that’s done, the attacker can read messages, see contacts, and in a business context, potentially impersonate you to customers or suppliers – a serious problem if WhatsApp is how you take bookings, send invoices, or manage supplier relationships. Because the linking process is a built-in, legitimate WhatsApp feature, it can also slip past a victim’s normal instinct to be suspicious.
Many small and medium businesses in regional Victoria run lean IT setups – a Google Workspace account for email and documents, WhatsApp or Facebook Messenger for quick customer contact, and maybe a handful of connected apps for invoicing, bookings, or marketing. That combination is convenient, but it also means a single successful OAuth or device-linking trick can expose your emails, customer data, financial documents, and communications channel all at once.
Unlike a traditional phishing email asking for a password, these attacks are harder to spot because:
In Google Workspace, an admin (or any user, for their personal account) can check which third-party apps have been granted access under Google Account settings, in the “Security” section, under “Third-party apps with account access.” Anything unfamiliar, unused, or overly broad in its permissions should be removed.
Open WhatsApp, go to Settings, then Linked Devices, and see what’s connected. If you don’t recognise a device, remove it immediately and consider changing your WhatsApp two-step verification PIN.
Train yourself and your staff to pause before clicking “Allow” on any sign-in or connection request – especially ones that arrive via an unexpected email, text, or link rather than something you initiated yourself. If in doubt, don’t click; go directly to the app or account settings instead.
Set a recurring reminder – quarterly is a good rhythm for a small business – to review connected apps, linked devices, and account permissions across your key business platforms. It only takes ten minutes but closes the door on access that may have been quietly sitting there for months.
This story is a reminder that cybercriminals are increasingly exploiting trust in legitimate features rather than building obvious fakes. The safest approach for a small business isn’t to distrust every notification, but to build a habit of treating unexpected “approve” or “connect” requests with the same caution you’d give an unexpected invoice or bank transfer request. A moment’s pause can be the difference between business as usual and a very disruptive week sorting out a hijacked account.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804