News thumbnail
Technology / Wed, 26 Aug 2026 LinkedIn

WhatsApp Strengthens Account Security With Password-Based Two-Step Verification, Multiple Passkeys and New Scam Call Warnings

WhatsApp Replaces Six-Digit Verification PINs With Stronger PasswordsThe most immediate account security change is the transition from a six-digit two-step verification PIN to a more flexible password. Why WhatsApp Account Takeovers Remain So EffectiveMessaging account takeovers are particularly attractive to criminals because compromised accounts provide immediate access to an established network of trusted contacts. The private key is retained by the user’s device, security key or credential manager, while the associated public key is registered with the online service. More Than 1 Billion WhatsApp Users Have Set Up PasskeysMeta said more than 1 billion people have already configured a passkey for their WhatsApp accounts. The FTC has issued clear guidance against sharing account verification codes, warning that people requesting those codes are often attempting to gain unauthorized access.

WhatsApp has announced a significant expansion of its account security protections, introducing stronger two-step verification, support for multiple passkeys across different mobile platforms and additional information about unfamiliar callers as the messaging service intensifies efforts to combat account takeovers, impersonation and online fraud.

The updates, announced on August 25, represent a broad attempt to address several of the most common ways criminals compromise messaging accounts: stealing verification codes, exploiting weak account protections, manipulating users into linking unauthorized devices and using unexpected calls to create pressure or urgency.

At the center of the changes is a substantial upgrade to WhatsApp’s two-step verification system. Users will be able to replace the existing six-digit security PIN with a longer alphanumeric password that can include special characters, creating a stronger additional barrier against unauthorized account registration.

WhatsApp is also expanding its passkey support, allowing users to register more than one passkey for the same account when they use both Android and iOS devices. On Android, the company is introducing additional caller information designed to help users evaluate calls from unfamiliar numbers before answering.

The company said more than 1 billion people have already established a WhatsApp passkey, highlighting how quickly passwordless authentication has become part of the platform’s security strategy.

WhatsApp Replaces Six-Digit Verification PINs With Stronger Passwords

The most immediate account security change is the transition from a six-digit two-step verification PIN to a more flexible password.

Previously, WhatsApp users could activate two-step verification by setting a numeric PIN that provided an additional layer of protection when registering their phone number with the service. That mechanism helped prevent an attacker from taking control of an account using only a stolen or intercepted verification code.

However, six-digit PINs have practical limitations. Users frequently select predictable combinations, repeated numbers or sequences that are easier to remember but also easier to guess.

The updated system allows longer passwords containing letters, numbers and special characters. This broader range of possible combinations can substantially improve resistance to guessing compared with a short numeric PIN, particularly when users choose unique passwords that are not reused elsewhere.

Meta described the new password requirement as an additional safeguard that can protect an account even if someone obtains the one-time code used during registration.

That distinction matters because attackers often do not need to defeat WhatsApp’s underlying encryption to compromise an account. Instead, they target the authentication process by persuading victims to surrender verification codes, impersonating technical support or exploiting weaknesses associated with a user’s mobile number.

A stronger second verification credential creates an additional obstacle. Even if a criminal successfully obtains a registration code, the attacker should still need the separate account password to complete the takeover where that protection is required.

The update does not mean that a password is inherently phishing-resistant. Passwords can still be stolen if users enter them into fraudulent websites or disclose them to someone posing as a trusted contact. Its value lies in adding a stronger account-level control beyond the existing one-time verification process.

Users should select a long, unique password and avoid recycling credentials already used for email, banking or social media. A password manager can help generate and store a stronger combination without relying on memorable patterns.

Why WhatsApp Account Takeovers Remain So Effective

Messaging account takeovers are particularly attractive to criminals because compromised accounts provide immediate access to an established network of trusted contacts.

Once attackers control an account, they may impersonate the legitimate owner, request emergency payments, distribute malicious links, solicit additional verification codes or attempt to compromise other people in the victim’s contact network.

These attacks are effective because messages appear to originate from a familiar person rather than an unknown account.

A criminal posing as a relative, colleague or close friend can exploit that trust to request money or sensitive information. In professional environments, a compromised account could also be used to impersonate an executive, approach employees, gather internal information or initiate payment fraud.

The risk is not limited to ordinary cybercrime. The United Kingdom's National Cyber Security Centre (NCSC) has warned that messaging applications can also be targeted in campaigns directed at individuals and organizations, recommending that users enable two-step verification and passkeys, refuse unexpected QR code requests and regularly review linked devices.

The practical lesson is that encrypted communications do not eliminate account-level risk. End-to-end encryption protects communications in transit, but it cannot protect a conversation from someone who gains access through an authorized account or linked device.

That makes authentication, device management and user awareness essential companions to encrypted messaging.

Multiple Passkeys Expand Protection Across Android and iOS

WhatsApp’s second major update introduces support for more than one passkey per account, addressing the realities of users who move between different devices and operating systems.

A passkey allows a user to verify their identity using the security mechanism already configured on their device, such as fingerprint recognition, facial authentication or a screen-lock code.

Instead of manually entering a password or relying on a verification code delivered by text message, the authentication process uses cryptographic credentials associated with the user’s device or credential manager.

WhatsApp said users who operate across both Android and iOS can now add more than one passkey to the same account. The company directs users to the Settings > Account > Passkeys section of the application to configure the feature.

The change is particularly relevant for people who maintain devices across different ecosystems, switch between personal and work phones, or replace an Android device with an iPhone and want to retain secure authentication options.

Multiple passkeys can also reduce dependence on a single device or platform-specific credential store. However, the precise recovery and synchronization experience will still depend on the device, operating system, credential provider and account settings involved.

The announcement does not explain whether WhatsApp imposes a maximum number of passkeys, which credential providers are supported in every configuration, or whether all users will receive the update simultaneously. Those details may vary as the rollout progresses.

How Passkeys Improve Protection Against Phishing

Passkeys are built around public-key cryptography rather than a reusable secret that a person must remember and type.

When a user creates a passkey, a cryptographic key pair is generated. The private key is retained by the user’s device, security key or credential manager, while the associated public key is registered with the online service.

During authentication, the service sends a challenge that is signed using the private key. The service then verifies that response using the public key it already holds.

Because the private key is not manually typed into a login form, attackers cannot capture it through a conventional fake password page in the same way they might steal a password or one-time code.

The FIDO Alliance, which develops and promotes widely used authentication standards, explains that passkeys are designed to be tied to the legitimate service for which they were created. This binding makes them resistant to common phishing techniques that depend on tricking a user into entering credentials into a fraudulent website.

The organization also notes that biometric information used to unlock a passkey remains on the user’s device. WhatsApp does not receive a copy of the user’s fingerprint or facial image as part of the authentication process. Instead, it receives the cryptographic proof needed to verify the login.

Passkeys can also reduce exposure to some risks associated with SMS-based authentication, including social engineering attacks that persuade users to reveal one-time codes and certain situations involving mobile-number compromise.

However, adopting a passkey does not automatically eliminate every other account recovery method. If weaker fallback mechanisms remain available, an attacker may still attempt to exploit those alternatives.

The FIDO Alliance has emphasized that phishing resistance depends not only on the primary authentication method but also on the security of account recovery and alternative sign-in processes.

For WhatsApp users, the strongest practical approach is therefore to combine passkeys with the upgraded two-step verification password, secure mobile account protections and careful management of linked devices.

More Than 1 Billion WhatsApp Users Have Set Up Passkeys

Meta said more than 1 billion people have already configured a passkey for their WhatsApp accounts.

That figure indicates that passwordless authentication has moved beyond early adoption into widespread consumer use on one of the world’s largest messaging platforms.

The company did not provide a detailed breakdown by operating system, geography or user activity, nor did it explain how many registered passkeys are actively used during account recovery or device migration.

Nevertheless, the reported adoption level suggests that biometric and device-based authentication is becoming increasingly familiar to mainstream users.

For security teams, the broader significance is that passkeys are no longer confined to enterprise identity platforms or specialized security applications. Their integration into consumer services means users may increasingly encounter the same authentication model across personal messaging, cloud accounts and workplace systems.

That familiarity could make stronger authentication easier to adopt across organizations, although enterprise environments may still need to evaluate whether synchronized passkeys, hardware-backed credentials or device-bound authentication best match their security requirements.

The FIDO Alliance distinguishes between synchronized passkeys, which can be shared securely across devices through supported credential ecosystems, and device-bound passkeys, which remain tied to a particular physical device or security key. Each model carries different considerations for portability, account recovery and assurance.

Android Users Will See More Information About Unknown Callers

WhatsApp is also adding new context to call screens when an incoming call comes from a number that is not saved in the user’s contacts.

On Android, the application will display information such as whether the number appears to originate from a different country and whether the caller shares any groups with the recipient.

The additional details are intended to help users make a more informed decision before answering.

An unexpected international call may not automatically indicate fraud, and a shared group does not establish that a caller is trustworthy. However, those details can help users identify circumstances that warrant additional caution.

For example, a caller claiming to represent a local organization may appear less credible if the number is associated with another country and no existing connection is visible.

Likewise, an unknown caller who shares a professional or community group may be easier to identify, although attackers can also join public groups or compromise legitimate accounts.

The feature is designed to disrupt the sense of urgency that often drives telephone-based fraud. Criminals frequently attempt to keep victims engaged, pressure them into making immediate decisions and discourage them from independently verifying the caller’s identity.

The U.S. Federal Trade Commission has warned that scammers routinely impersonate trusted organizations and create artificial emergencies to obtain account credentials, financial information and verification codes.

WhatsApp’s announcement specifically identifies Android for the enhanced call-screen information. It does not state when, or whether, the same feature will be introduced for iOS.

Verification Code Scams Continue to Drive Account Hijacking

One of the most common attack patterns against messaging accounts involves persuading a user to disclose a one-time verification code.

A criminal may initiate a WhatsApp registration attempt using the victim’s phone number, causing the legitimate user to receive a verification code.

The attacker then contacts the victim while pretending to be a friend, support representative or employee of a trusted organization, claiming the code was sent accidentally or is needed to resolve a security issue.

If the victim shares the code, the attacker may be able to register the account on another device unless additional security protections prevent the attempt.

The FTC has issued clear guidance against sharing account verification codes, warning that people requesting those codes are often attempting to gain unauthorized access.

Another related risk involves SIM-swapping attacks, in which criminals attempt to transfer a victim’s mobile number to a SIM card or device under their control.

If successful, attackers may receive text messages or calls intended for the victim, including verification codes associated with online accounts.

The FTC recommends setting a PIN or password on mobile carrier accounts to reduce the risk of unauthorized changes.

Passkeys and stronger two-step verification can make these attacks more difficult by reducing reliance on a single verification mechanism, although the overall level of protection depends on how account registration and recovery are implemented.

Device-Linking Scams Remain a Separate Threat

The August security updates follow another major anti-fraud initiative introduced earlier this year to combat unauthorized device linking.

In March, Meta announced that WhatsApp would begin warning users when behavioral signals suggest that a device-linking request may be suspicious.

Those attacks often involve criminals persuading victims to scan a QR code or provide a device-linking code under false pretenses.

The attacker may claim the code is required to vote in an online competition, join a group, confirm an appointment, resolve an account problem or access a special offer.

In reality, the code or QR scan may connect the attacker’s device to the victim’s WhatsApp account.

That method differs from a traditional account takeover because an attacker may gain access through an approved linked session rather than by fully re-registering the account.

As a result, a strong password or passkey does not necessarily prevent the user from authorizing a malicious device if the victim is deceived into completing the linking process.

Meta said the warnings can provide information about where a linking request originates and alert users when the request may be fraudulent.

Users should regularly review the devices connected to their accounts and immediately remove unfamiliar sessions.

The NCSC also recommends independently verifying unexpected requests, avoiding unrecognized QR codes and reviewing group participants for suspicious or unfamiliar accounts.

Strict Account Settings Offer Additional Protection for High-Risk Users

The latest security improvements also build on WhatsApp’s introduction of Strict Account Settings in January.

That feature applies more restrictive protections for people who may face sophisticated targeting, including journalists, public figures and other individuals at elevated risk.

According to Meta, enabling the setting can automatically block attachments and media from unknown senders, silence calls from unfamiliar contacts and restrict other functions that could increase exposure to advanced attacks.

The company describes the feature as a lockdown-style security option intended to reduce opportunities for exploitation and unwanted contact.

Strict Account Settings can be accessed through Settings > Privacy > Advanced

Unlike the newly announced password and passkey improvements, which are designed for broad account security, Strict Account Settings addresses situations in which a user’s threat profile may justify additional restrictions on how the application functions.

The trade-off is that tighter controls can reduce convenience, particularly for people who routinely communicate with new contacts or receive documents from unfamiliar numbers.

For highly targeted users, however, reducing exposure to unexpected attachments, unknown callers and unsolicited interactions may be more important than preserving every convenience feature.

What the Updates Mean for Businesses and Security Teams

Although WhatsApp is primarily associated with personal communication, it is also widely used for customer engagement, informal workplace discussions and business coordination.

That creates potential security and governance challenges when employees use personal messaging accounts to communicate with colleagues, clients, suppliers or executives.

A compromised WhatsApp account can become a channel for impersonation, payment fraud, unauthorized information requests or targeted phishing against an organization’s workforce.

Attackers may use access to group conversations to identify reporting relationships, learn the names of senior personnel or gather contextual information that makes subsequent fraud more convincing.

The NCSC advises organizations to use approved corporate messaging services and managed devices for work communications where possible, particularly when sensitive information is involved.

Security teams should consider whether messaging-app account protections form part of their broader employee awareness programs. Training should cover verification-code theft, malicious QR codes, unauthorized linked devices, unexpected international calls and impersonation attempts that appear to originate from known contacts.

Organizations that rely on WhatsApp for customer communication or operational coordination should also establish clear procedures for verifying payment requests, changes to bank details and instructions attributed to senior executives.

Independent confirmation through a separate, trusted communication channel remains particularly important when a message requests money, sensitive information or urgent action.

Stronger Security Depends on Using Multiple Controls Together

The new features illustrate a broader shift in messaging security: protecting an account requires more than encrypting messages or offering a single authentication safeguard.

Stronger two-step verification passwords can reduce the effectiveness of stolen registration codes. Passkeys can provide phishing-resistant authentication. Unknown-caller context can help users evaluate suspicious contact attempts. Device-linking warnings can interrupt attempts to establish unauthorized account sessions.

However, each control addresses a different part of the attack surface, and none should be treated as a complete defense on its own.

Users remain vulnerable if they approve fraudulent device-linking requests, disclose account credentials, ignore suspicious activity or trust unexpected requests solely because they appear to come from a known contact.

WhatsApp users should update the application, enable a strong and unique two-step verification password when the feature becomes available, configure passkeys on supported devices and review linked sessions regularly.

Unexpected requests for verification codes, QR scans, account passwords or urgent payments should be treated with caution and verified independently.

For users at elevated risk, Strict Account Settings may provide additional protection by limiting interactions with unknown contacts and reducing exposure to potentially dangerous content.

WhatsApp has not published a detailed rollout schedule covering every country, operating system or account type. Availability may therefore differ between users as the new protections are introduced.

© All Rights Reserved.