1. Home
  2. / Legislation and Law
  3. / STJ Rules That Mobile Carrier Must Compensate Customer for Security Flaw That Allowed Cloning of His WhatsApp for Fraudulent Activities
Reading time 4 min of reading Comments 1 comment

STJ Rules That Mobile Carrier Must Compensate Customer for Security Flaw That Allowed Cloning of His WhatsApp for Fraudulent Activities

Written by Bruno Teles
Published on 11/10/2025 at 20:47
O STJ decidiu que a operadora de celular deve indenizar clientes por falha de segurança ligada ao SIM Swap e à clonagem do WhatsApp.
O STJ decidiu que a operadora de celular deve indenizar clientes por falha de segurança ligada ao SIM Swap e à clonagem do WhatsApp.
  • Reação
  • Reação
  • Reação
  • Reação
  • Reação
  • Reação
152 pessoas reagiram a isso.
Reagir ao artigo

The Decision Consolidates That Mobile Operators Are Responsible for Security Failures That Allow SIM Swap and the Takeover of WhatsApp by Criminals, Based on the Consumer Defense Code and Objective Liability, Paving the Way for Compensation for Moral and Material Damages and Raising the Standard of User Protection

The Superior Court of Justice has consolidated the understanding that the mobile operator can be held liable when a security failure allows the cloning of the customer’s chip and, from that, the takeover of WhatsApp for fraud applications. This is a defective service that exposes the consumer to concrete risk and produces measurable losses, affecting both moral and financial domains.

In practice, the court recognizes that the unauthorized transfer of the phone line to a new chip by third parties constitutes a serious violation of security duties in the provision of the service. When the failure is proven, the victim is entitled to compensation for moral damages and to full restitution of financial losses associated with the fraud.

What the STJ Decided

STJ decides that the mobile operator is obliged to compensate the customer for a security failure that allowed the cloning of their WhatsApp for fraud applications

The STJ has been stating that operators must ensure robust identification and validation controls before allowing chip swaps.

If these controls fail and the criminal assumes the line, the service is considered defective under consumer legislation.

The liability is objective, requiring only proof of the nexus between the failure and the damage.

This understanding supports the consumer in scenarios where, after the SIM swap, the fraudster gains access to WhatsApp and impersonates the victim to ask for money from contacts.

In these cases, the operator can be ordered to compensate for moral damages due to distress and reimburse the amounts actually lost.

Security Failure and Defective Service

The cloning of the chip constitutes a serious security failure.

The problem does not lie with the application itself, but with the credentialing process of the operator, which should prevent third parties from obtaining the line.

If the authentication barrier fails, the provision of the service does not meet the expected security standard.

The Consumer Defense Code establishes that suppliers are liable for damages resulting from defects in service provision, regardless of fault.

Thus, it’s not necessary to prove specific negligence of the operator, but rather the existence of the failure that made the fraud and the damage to the consumer possible.

Moral and Material Damages: When They Apply

Moral damages arise from significant distress, the exposure of private life, and the feeling of vulnerability, elements that exceed mere annoyance.

The violation of data security and the phone line affects the dignity of the consumer.

Material damages require evidence of economic loss.

Proofs of transfers, statements, and chat logs are essential for quantifying reimbursement.

If there is proof of disbursement caused by the scam, the mobile operator may be ordered to pay the full difference.

Cloned WhatsApp Is Not Always the Same Thing

It is crucial to distinguish between two scenarios.

In the WhatsApp scam without chip swap, the criminal obtains the verification code through social engineering directly from the victim.

In this case, the liability tends not to fall on the operator, as there was no failure in the telephone service.

In the SIM Swap, the fraudster transfers the line to another chip exploiting a security gap in the operator.

This is the context in which the STJ has held the provider liable, as the fraud is only feasible due to the lack of validation in customer service and internal systems.

What Changes for the Consumer

The STJ’s understanding raises the security standard required.

Operators now have a concrete incentive to reinforce authentication and audit trails, reducing unauthorized portabilities and chip swaps.

For the user, the chance of compensation increases.

Once the service failure is confirmed and the losses demonstrated, the judicial path can ensure compensation for moral damages and reimbursement for financial losses, in addition to pressuring the market to invest in prevention.

How to Protect Yourself in Practice

Activate two-step verification on WhatsApp. It is an additional barrier that blocks attempts to revalidate the app, even if someone takes over the line through SIM Swap.

Maintain active vigilance: distrust requests for money via message, validate through another channel before transferring resources, and do not share verification codes sent via SMS or authentication apps.

What to Do if You Are a Victim

Gather evidence of the incident. File a Police Report, keep service protocols from the operator, screenshots of conversations, and proofs of transfers.

These documents support the request for compensation and the recovery of losses.

Contact the operator immediately and demand the blocking and restoration of the line.

Then, seek legal advice to evaluate the appropriate action, including the demand for moral and material damages, based on the objective liability provided in the Consumer Defense Code.

Inscreva-se
Notificar de
guest
1 Comentário
Mais recente
Mais antigos Mais votado
Feedbacks
Visualizar todos comentários
marketing service
marketing service
11/10/2025 21:17

Great article, thank you for sharing these insights! I’ve tested many methods for building backlinks, and what really worked for me was using AI-powered automation. With us, we can scale link building in a safe and efficient way. It’s amazing to see how much time this saves compared to manual outreach.

Bruno Teles

Falo sobre tecnologia, inovação, petróleo e gás. Atualizo diariamente sobre oportunidades no mercado brasileiro. Com mais de 7.000 artigos publicados nos sites CPG, Naval Porto Estaleiro, Mineração Brasil e Obras Construção Civil. Sugestão de pauta? Manda no brunotelesredator@gmail.com

Share in apps
1
0
Adoraríamos sua opnião sobre esse assunto, comente!x