hack someones snapchat

After showcasing how easy it is to hijack WhatsApp accounts in 2020, I took a break from ethically hacking people’s accounts. Hacking my own accounts just didn’t have the same thrill. But now that we’re slowly returning to normalcy and socializing again, I thought it would be fun to test out my old tricks on unsuspecting victims – I mean friends – to see if it’s still possible in well-known apps. To my surprise, it remains shockingly easy.

I recently examined the top 10 free apps on the Apple App Store and decided to target one to see if I could take control of someone else’s account. These experiments not only highlight how easily it can be done but also give me an opportunity to demonstrate the available prevention methods to help secure all your accounts.

Snapchat caught my attention due to its target audience of 18-24-year-olds (although many of its users are thought to be younger). Although Generation Z is often regarded as “tech-savvy,” they are also known for cutting security corners. From neglecting to set up two-factor authentication to sharing passwords with friends, they may be vulnerable. So, I decided to test the security of the Snapchat app and see if it could be as easily compromised as WhatsApp.

The experiment

To conduct the experiment, I needed a Snapchat account. One of my friends, whom I will refer to as “Elle,” agreed to participate. With her permission, I attempted to hack into her Snapchat account as part of raising cyber-awareness. I promised not to post anything from her account if successful.

During a lunch outing in Bournemouth, I sat next to Elle, both of us engrossed in our phones while conversing. I had previously installed Snapchat on my phone but hadn’t set up an account yet. Opening the app, I was greeted with the login screen, which conveniently featured a link to “Forgot your password?”

Snapchat login form

This link is often the first point of entry for anyone attempting to hijack an account. I clicked on it, and the app presented me with two password reset options: “via phone” or “via email.” I chose the phone option and entered Elle’s phone number.

Snapchat forgotten password

As Elle continued to use her phone, I eagerly waited next to her, ready to “shoulder jack” her confirmation code. The code arrived as a drop-down notification on her iPhone screen while she was engaged in a message conversation. I quickly read the six-digit number and memorized it.

Surprisingly, Elle didn’t notice the Snapchat notification as she receives numerous notifications daily. I entered the confirmation code on my phone and was prompted to set a new password. I chose “JakeIsAwesome.1” to make it memorable. At this point, taking control of her Snapchat account was as easy as hacking someone’s WhatsApp in my previous experiment. However, Snapchat added an extra layer of security to fully commandeer the account.

Although Snapchat didn’t ask for a password (likely due to the option of creating an account without an email or username), it sent another confirmation code to Elle’s phone number via text. I wasn’t prepared for this additional step, but I was still able to view the SMS message in Elle’s notifications. With this code, I gained entry and took full control, even locking her out of her own account on her phone.

I had promised not to post anything or contact her friends, but my proof of concept succeeded. This attack could even be remotely enabled if a manipulative social engineer persuades the target to share confirmation codes over a voice call. This technique is gradually becoming more prevalent, so caution is advised.

Had the only verification option been via email, this experiment would have been nearly impossible. Elle would have needed to click on the email sent to her and follow the link within the message. I assume she would not have done those steps. Snapchat’s password recovery mechanism, via an unencrypted messaging service that displays the code in the phone’s notification panel, greatly increases the vulnerability.

How can you recover your Snapchat account?

Recovering a stolen Snapchat account is not always easy. It depends on the changes made by the hacker. If only the password has been changed, you can regain access by following the same steps mentioned above.

However, if the hacker has changed the phone number, email address, or added two-factor authentication, options become limited. Communication with social media companies can be challenging, making it difficult to undo such attacks. If you suspect your account has been compromised, Snapchat offers advice on their platform.

How can you secure your Snapchat account?

In addition to using a strong and unique passphrase (recommended for all online accounts), enable two-factor authentication within Snapchat’s settings. It’s preferable to use an authenticator app like Microsoft Authenticator or Google Authenticator rather than SMS-based 2FA.

Snapchat two-factor authentication

You may not have a Snapchat account, but you likely know someone who does. Make sure to inform them about the ‘SnapHack’ and encourage them to apply this security advice to all their online accounts.

To counteract shoulder surfing attacks, prevent others from covertly looking at your screen when entering sensitive information on apps or websites, especially in public places. Disable notification previews to hide them from prying eyes when your phone is locked. Additionally, be vigilant and actively monitor your SMS messages when using your phone or tablet in the presence of others. This would have foiled my attack on Elle’s Snapchat account.

Hacking into someone’s Snapchat account remains distressingly simple, and the popularity of shoulder surfing attacks is a cause for concern. By raising awareness about these vulnerabilities, we can encourage users to secure their accounts and protect their personal information. Remember to implement two-factor authentication, disable notification previews, and stay vigilant when using your devices in public. Stay safe and cyber-aware in the digital age!

