Simply answering an ordinary phone or WhatsApp call does not normally give the caller control of your smartphone. The much more realistic danger is what happens next: a scammer persuades you to reveal an OTP, disclose banking information, follow a malicious link or install an unfamiliar app. Rare zero-click vulnerabilities are real, but they involve exploiting software flaws and are very different from an ordinary stranger calling your number.
Can Someone Hack Your Phone Just by Calling You?
An unfamiliar number appears on your screen, you answer, and then remember a warning claiming that hackers can take over a phone simply by calling it. There is a small amount of technical truth behind some of these stories, but for most people the real danger is much more ordinary: scammers trying to convince you to reveal information, open a link or install something.
If an unfamiliar number calls and you answer, that action by itself does not normally give the caller access to your photos, WhatsApp conversations, banking applications or passwords. A normal telephone call establishes a communication connection. It is not designed to provide the person calling you with administrative access to the device receiving the call. That is why warnings such as “Never answer this number because they will immediately hack your phone” should be treated cautiously.
There is, however, a reason the myth sounds believable. Cybersecurity researchers have discovered vulnerabilities in the past that allowed sophisticated attackers to compromise smartphones without requiring the victim to deliberately open a malicious file or click a suspicious link. These are usually described as zero-click vulnerabilities.
The distinction is important: a normal phone call is not the same thing as exploiting a security flaw in the software processing that call.
Zero-click attacks are real, but they are not ordinary scam calls
A zero-click attack exploits a vulnerability without depending on the victim to perform the usual risky action, such as opening an attachment or pressing a malicious link. Google Project Zero's research into zero-click mobile exploitation has documented how sophisticated vulnerabilities can affect components that automatically process information arriving on a device.
WhatsApp has also previously patched serious vulnerabilities associated with its calling infrastructure. The NIST National Vulnerability Database entry for CVE-2019-3568 documents a vulnerability affecting older WhatsApp versions that could be remotely exploited without ordinary user interaction. The important part is what happened afterwards: vulnerabilities such as these were identified and patched.
They do not mean that somebody who discovers your phone number today automatically gains the ability to control your device simply by pressing the call button.
TechView Africa's risk check: these situations are not equally dangerous
One way to avoid unnecessary fear is to separate the different scenarios.
| Situation | Practical risk | What is actually happening |
|---|---|---|
| Unknown number calls and you answer | Usually low technical risk | A normal voice connection has been established |
| Caller asks for an OTP, PIN or password | High scam risk | Social engineering |
| Caller sends a link and pressures you to open it | High risk | Possible phishing or malware attempt |
| Caller asks you to install an unfamiliar application | High risk | Possible malware or remote-access attempt |
| Caller wants remote access to your screen/device | Very high risk | Potential account/device compromise |
| Repeated strange WhatsApp calls | Usually spam/scam risk | Could involve spam, harassment or social engineering |
| Sophisticated zero-click exploit against vulnerable software | Potentially severe but rare | Exploitation of a software vulnerability |
For most smartphone users, the middle of this table deserves much more attention than the last row.
The bigger Nigerian risk is often what the caller convinces you to do
Nigeria's national Computer Emergency Response Team has warned about phishing campaigns involving deceptive calls and messages intended to obtain personal information or financial details. In its advisory on increased phishing campaigns in the Nigerian cyberspace, ngCERT describes deceptive communication as one of the methods criminals use to manipulate victims into surrendering sensitive information or interacting with malicious content.
The Central Bank of Nigeria's fraud and scam guidance similarly warns about criminals impersonating trusted organisations and attempting to obtain confidential financial information. This means a conversation beginning with:
“Good afternoon, we are calling from your bank because there is a problem with your account.” can still be extremely dangerous. But answering the call was not necessarily the dangerous part. The attack becomes effective when the person on the other end persuades you to hand over something useful.
Short video reference
A useful example of this distinction is the concept of vishing, where scammers use voice calls to manipulate victims rather than technically hacking the phone through the call itself.
.
A phone call can be the beginning of a malware attack
A fraudulent caller can also use the conversation as the first stage of a longer attack. For example, a person pretending to represent your bank, mobile network or another trusted company may tell you that your account has a serious problem and then ask you to:
- visit a website;
- install an application;
- open a file;
- enable screen sharing;
- provide an authentication code;
- or approve a login notification.
At that point, the risk has changed completely. The caller is no longer merely speaking to you; they are attempting to get you to perform an action that may help them compromise an account or device.
This is why the useful question after a suspicious call is not simply:
“Did I answer?”
Ask instead:
“What did I do after answering?”
WhatsApp calls from unknown numbers deserve the same distinction
Anyone who has your number may potentially attempt to contact you on WhatsApp, which means unknown WhatsApp calls can also become a route for spam and scams. WhatsApp provides a feature called Silence Unknown Callers, designed to reduce interruptions from numbers you do not recognize. The company's guidance on silencing unknown callers explains that these calls can be prevented from ringing while still appearing in your call history.
Using the feature can reduce exposure to unwanted contact. It does not mean that every unknown WhatsApp caller is technically attempting to hack your phone.
Why sophisticated attacks receive so much attention
Zero-click attacks attract enormous attention because they can remove one of the victim's most important defences: refusing to interact with suspicious content.
If an attacker can exploit software before you knowingly do anything, ordinary advice such as “don't click suspicious links” may not be enough.
That is why some technology companies provide extreme protection specifically for people considered likely targets of highly sophisticated attacks.
Apple's Lockdown Mode, for example, deliberately restricts certain device functionality to reduce the available attack surface for people who may face highly targeted threats.
Apple also maintains a system of threat notifications for users targeted by mercenary spyware.
The company emphasizes that attacks of this level are highly sophisticated and generally target a comparatively small number of people.
That context matters the existence of advanced spyware should not lead the average smartphone user to assume that every missed call from an unfamiliar international number represents a zero-click attack.
What TechView Africa would look for after a suspicious call
If you are worried because you answered an unknown number, work through what actually occurred.
You:
- answered;
- said hello;
- spoke briefly;
- gave no sensitive information;
- clicked nothing;
- installed nothing;
- approved no login request;
- and ended the call.
That scenario alone provides much less reason to believe the phone has been compromised.
Much more concerning
The caller convinced you to:
- reveal an OTP;
- disclose your password or PIN;
- provide card or banking information;
- install an unfamiliar application;
- enable screen sharing or remote access;
- follow a strange link;
- approve an unexpected authentication request;
- or change account/security settings.
Those actions deserve immediate attention because the caller may now possess information or access that can actually be used against you.
Keeping your phone updated still matters
Separating fact from fear does not mean ignoring mobile security. Past zero-click vulnerabilities demonstrate why operating-system and application updates matter.
Security updates frequently contain fixes for weaknesses discovered after software has already been released. Keeping iOS, Android, WhatsApp and other important applications updated reduces your exposure to vulnerabilities that vendors already know how to fix.
For people facing unusually sophisticated targeting, Apple recommends keeping devices updated as part of its guidance for users who receive mercenary-spyware threat notifications. For everyone else, updating software remains one of the simplest useful security habits.
What to do if a caller claims there is an emergency
Scammers often try to create urgency because urgency reduces the amount of time you spend questioning the story.
A caller may claim:
Your bank account is about to be blocked.
Someone is withdrawing money from your account.
Your SIM will stop working today.
Your WhatsApp account is being suspended.
You must give us the code that just arrived on your phone.
Do not let the caller dictate your verification process. End the conversation, then contact the bank, telecom company or other organisation through a number or application that you independently know is legitimate.
The Central Bank of Nigeria's consumer fraud guidance advises consumers to protect confidential information and verify suspicious communications rather than relying on claims made by the person contacting them.
Our Recommendation
If you answer an unknown call, there is usually no reason to assume your phone has been hacked merely because you said hello.
Instead of concentrating only on the call itself, reconstruct what happened afterwards. If you simply answered, spoke and ended the conversation without giving away credentials, opening links, installing software or approving anything, the technical risk is generally far lower than viral warnings may suggest.
If you disclosed an OTP, banking password or other sensitive information, installed something at the caller's request or allowed remote access to your device, treat the situation much more seriously.
Rare zero-click attacks demonstrate that sophisticated phone compromise is technically possible, but they should not be confused with the much more common world of scam calls and social engineering.
For most people, the strongest defence is not being afraid to answer every unfamiliar number. It is learning to recognize when a caller is trying to make you do something that gives them access they did not already have.
Verification Links
Google Project Zero — Zero-Click Mobile Exploitation Research
Frequently asked questions
Can somebody hack my phone if I only answer and say hello?
Under normal circumstances, simply answering and speaking does not give the caller control of your smartphone. The more significant risk begins when you reveal sensitive information, open malicious content or install something at the caller's request.
Can someone steal money from my bank account just because I answered their call?
An ordinary voice call does not normally provide access to your banking application. The more realistic threat is being manipulated into revealing an OTP, PIN, password or other information criminals can use.
Are zero-click hacks actually real?
Yes. Researchers and technology companies have documented vulnerabilities capable of being exploited without the victim deliberately clicking malicious content. These attacks are technically sophisticated and should not be confused with normal scam calls.
Should I never answer an unknown number?
Not necessarily. Unknown calls can be legitimate. If you receive frequent unwanted calls, your phone or messaging application may provide tools for silencing or filtering them.
What should I do if I gave a suspicious caller my OTP or password?
Change the affected credentials immediately, contact the relevant bank or service through its official channel and review the account for unauthorised activity. Where available, strengthen the account with multi-factor authentication or passkeys.
Follow TechView Africa on WhatsApp
Get TechView Africa updates on WhatsApp. Follow our channel for practical technology news, product guides and digital trends from Nigeria and across Africa.









Leave a comment
Comments cannot be edited or deleted after posting. Please review your comment before submitting.
No comments yet. Start the conversation.