A phone number in a screenshot and SIM-swap scams
WhatsApp hijacks need a number and an OTP. A chat header you forgot to cover can hand both to a stranger.

SIM swap needs a number worth swapping. WhatsApp takeover needs that number plus a code. A chat screenshot is a common way the number travels farther than you meant.
August 2026 crime reporting on WhatsApp theft talks about OTPs and SIM-swap, not about Gaussian blur. We will not invent a victim who “paid because they forgot to smear the header.” We will say this: posting a still that still shows a number or a code feeds the same crime those articles describe.
Sowetan, 3 August 2026, is the citation for that coverage in this post. Read it as a warning about ingredients, not as a novel about a named person and a highlighter.
What is the chain, without a composite story?
- Number is visible in a header or a forwarded vCard.
- Someone uses that number for social engineering or a port-out.
- The SMS code lands, and anyone with the screenshot of the code is done.
You do not need all three steps in one PNG for the PNG to help. A header-only shot still publishes the number. A code-only shot still publishes the OTP. Together they are the pair takeover reporting describes. Separately they are still fuel.
Where does the number hide in a “harmless” chat still?
WhatsApp header. Quoted replies. Group names that are just a phone number. Voice-note placeholders. Contact cards. Your own status bar is not the usual leak; the chat chrome is. Marketplace and support screenshots leak numbers the same way. Cover the header even when the joke is a sticker. hide numbers.
Crop the chrome if you do not need to prove it was WhatsApp. A cropped sticker is still a sticker. A cropped sticker with a remaining +country code is still a number.
Why never keep the OTP in Recents?
Codes expire. Gallery backups do not. People screenshot the SMS because the banner vanished. Then they post the gallery tile. Then iCloud or Google Photos has a permanent copy of a login factor. Delete it. If you must show that an SMS arrived, bar the digits and the number, then delete the original. OTP-specific note: OTP piece.
Is this the same as “hackers post screenshots”?
No. Extortion crews posting admin panels is a different beat — leak-site proof, as in reporting on groups that publish pictures of access. SIM-swap and WhatsApp hijack reporting is about numbers and codes used against a person. Do not mash the two into one villain story. Do not hang a named victim on blur. Do cover the header anyway.
What should you post instead of the still?
Words. “I got an SMS that looked like WhatsApp.” No digits. No full number. If a bank or an operator asks for evidence, use their channel, not a public comment thread. If a relative wants to see the scam format, describe the sender name. If you already posted the still, take it down, rotate what you can, tell people close to you not to read codes aloud.
Does barring only the last four digits of the number help?
A header that still shows country code plus most of the national number is still a number. Partial bars that leave a recognizable prefix help a caller who already has a guess. Cover the whole header string. Cover vCards. Cover quoted replies that repeat the number. If you need to show it was a chat, show a sticker or a timestamp with the identity chrome gone.
Group admins posting “who added this number?” screenshots are publishing the number to every member and every forward. Ask in text. Do not paste the still into a second group to investigate the first. The header is enough. You do not need a second leak to solve the first.
Cover the header. Never keep the code. Paint both in a new PNG if the file already exists, then delete Recents and empty Recently Deleted if the phone keeps a bin: bar the number in BlurThis.
