WhatsApp is adding three new security features designed to make account takeovers and scam calls harder to pull off.
The new protections cover authentication, account access, and social engineering. WhatsApp is upgrading two-step verification, allowing more than one passkey per account, and adding caller context for numbers that aren’t saved in a user’s contacts.
The changes matter because compromising a WhatsApp account does not always require breaking its encryption. Attackers can instead target the authentication and recovery process or persuade users to hand over access themselves.
WhatsApp 2FA gets a boost
WhatsApp is strengthening its existing two-step verification by replacing the six-digit PIN with an alphanumeric password that can include special characters. The change gives users a stronger second credential, making it harder for attackers to guess their way past this additional layer of account protection.
A six-digit PIN has one million possible combinations, while a longer password using letters, numbers and symbols can provide a much larger credential space.
That does not mean WhatsApp’s existing PIN system was inherently weak, particularly when combined with platform protections against repeated attempts, but the change gives users the option to create a substantially stronger second credential.
Unknown WhatsApp calls will show more context
WhatsApp is also giving users more information about calls from unknown numbers, with Android users able to see the caller’s country and whether they share any groups together.
Shared-group information can help users determine whether an unfamiliar number may have a legitimate connection to them rather than being a completely random caller. Even so, users must be careful, as scammers can infiltrate a WhatsApp group to get access to group members.
Although both pieces of information can be obtained from the caller’s profile info, WhatsApp appears to be betting that by revealing this information outright, users can make more informed decisions before they even speak with the person, surfacing that context before users answer could help them assess an unfamiliar caller before a conversation begins.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
WhatsApp expands passkeys across devices
WhatsApp is also making passkeys more flexible by allowing users to add multiple passkeys to the same account. This is particularly useful for people who use multiple devices, including those who switch between Android and iOS, because each trusted device can have its own passkey.
The messaging platform says more than 1 billion users have already set up passkeys, making this less about introducing a new authentication method and more about making a feature already adopted by many users easier to use.
Still, the figure leaves significant room for wider adoption. WhatsApp has more than 3 billion users, meaning a large share of its user base has yet to set up the authentication method.
WhatsApp currently has over 3 billion users, yet only a billion have already implemented passkeys. By supporting multiple passkeys, WhatsApp is reducing the friction of passwordless authentication, which could help onboard more users to the method.
Where is WhatsApp headed with these changes?
WhatsApp’s latest security updates suggest the company is trying to protect not only how users access their accounts, but also how much personal information they expose while using the platform. That is particularly relevant as WhatsApp introduces usernames.
Usernames could make a difference for people joining group chats, meeting new contacts, or communicating with businesses and strangers.
But privacy and security are not the same problem, and solving one can introduce concerns around the other. Usernames reduce phone-number exposure, but they can also create opportunities for impersonation if users assume a familiar-looking username belongs to the person or organization they expect.
That makes WhatsApp’s latest security push more significant than the sum of three isolated account features. Stronger two-step verification and multiple passkeys protect account access, while caller context and usernames give users more information and control over who they interact with.
The larger test will be whether WhatsApp can keep pace with scams without weakening the features that made the platform attractive in the first place.
Other Security News: Password notebooks are making an unlikely comeback as infostealers and browser-based credential theft prompt users to reconsider whether keeping passwords offline could reduce some digital risks.