A friend just messaged you asking for money

It is not them. Here is how to be sure, and what to do for them.

Updated 2026-09-26

A message from someone you know. They are in trouble, or they have found something great, or they need a favour involving money. It is written like them, because it is their account.

Why it is convincing

It comes from the real account, in the real conversation thread, with the real history above it. The attacker has usually read that history, so the message may reference something true.

And the ask is calibrated: small enough to be plausible, urgent enough to skip the check.

How to be sure

Ring them. On the number you already have, not one in the message. Thirty seconds ends it.

If you cannot ring, ask something the account does not know — not the dog's name, which is on their feed, but "what did we do last Tuesday". A hijacked account fails immediately and usually stops replying.

Do not ask "is this really you?" in the chat. You are asking the attacker, and the answer is yes.

The common shapes

"I've lost my phone, this is my new number." The family version of this, often with a cloned voice, is at the "Mum, I've lost my phone" scam.

"Can you receive a payment for me? My account is frozen." Money laundering with you as the mule. Refusing protects you as much as them.

"Vote for me in this competition." The link is a credential harvester, and the reward is your account sending the same message to everyone you know.

"Look what I found, is this you?" A link, a fake login page, and then it is your account doing the asking.

An investment that is doing really well. Sometimes a hijacked account, sometimes a genuine friend in an earlier layer of the same scheme.

What to do for them

Tell them on a different channel — text them if the hijacked account is Facebook, ring them if it is WhatsApp. Report the account to the platform. Warn the group chat, because you will not be the only one who got it.

If it is your account

Move quickly and in order:

1. Change the password, from a device you trust. 2. Sign out all other sessions. Every platform has this; it is the step that actually evicts them. 3. Check for changes they made: recovery email, recovery phone, forwarding rules, linked apps, two-factor method. An attacker who keeps a recovery route comes straight back. 4. Turn on two-factor, or replace it if they changed it. 5. Tell your contacts, publicly and without embarrassment. It stops the next person paying. 6. Change that password anywhere you reused it. This is where the real damage usually is.

Our password checker tells you whether a password is already circulating in breach data, and runs entirely in your browser.

WhatsApp specifically

The common takeover is simple: someone asks you to read back a six-digit code "by accident sent to your phone". That code is your WhatsApp registration code. Reading it out hands over the account.

Turn on two-step verification in WhatsApp — Settings, Account, Two-step verification. It sets a PIN that a stolen SMS code alone cannot beat, and it takes a minute.

Check a link Free, and it needs no account.

All guides

Ready when you are.

£7.99 a month, or £69.99 a year. Cancel online whenever you want.

Get Veystrix