Table of Contents
WhatsApp account security gained three new protections on Tuesday, August 25, 2026, when Meta rolled out a set of changes for the messaging app’s users. The company owns the platform and its roughly three billion subscribers.
The update lets people register more than one passkey, upgrades two-step verification (2SV) from a PIN to a full password, and shows Android users more detail about calls from numbers they do not recognize.
With more than 1 billion people already signing in through a passkey, Meta says the goal is to slow account takeovers and the scam calls that pressure victims into acting fast.
WhatsApp Account Security: Key Takeaway
- WhatsApp now supports multiple passkeys, swaps its 2SV PIN for a full password, and gives Android users more context on unknown callers.
This section contains affiliate links; we may earn a commission at no cost to you.
Stronger login and 2SV start with the credentials themselves. These tools help you manage passwords, passkeys, and personal data that scammers use to break in:
- 1Password: store passkeys and long, unique passwords across every device, so your WhatsApp 2SV password is not one you reuse anywhere else.
- Passpack: a straightforward password manager for individuals and teams who want organized, encrypted credential storage.
- Optery: remove your phone number and personal details from data broker sites, cutting the raw material scammers use for targeted calls.
What WhatsApp Changed
Meta announced the features in a post on the official WhatsApp blog, framing them as part of an ongoing effort to keep accounts in their owners’ hands. The company paired login upgrades with a tool aimed squarely at scam calls.
Multiple Passkeys Across iOS and Android
A passkey is a login credential tied to your device rather than a memorized secret. Instead of typing a code, you confirm your identity with a fingerprint, a face scan, or your device screen lock, and no password travels across the network.
WhatsApp first introduced passkeys on Android in October 2023 and brought them to iOS in early 2024, according to reporting from The Hacker News, which also notes Meta added passkey logins to Facebook in June 2025. The company now says more than 1 billion people use one to sign back into WhatsApp.
The new part is quantity. Until now an account was limited to a single passkey, which was awkward for anyone who runs WhatsApp on more than one device. Users can now add several, a practical benefit for people who carry both an iPhone and an Android handset, or a work phone and a personal one.
Setup lives in the same place for everyone. Open the app, then go to Settings, then Account, then Passkeys, and register the device you are holding. Repeat on each phone you want to enroll.
Two-Step Verification Moves From a PIN to a Full Password
Two-step verification (2SV) is an extra layer that sits behind the code WhatsApp sends when a phone number is registered on a new device. Even if an attacker intercepts that single use code, 2SV asks for a second secret before the account will open.
For years that second secret was a PIN of six digits. WhatsApp is replacing it with a full password that can be longer and can mix letters, numbers, and special characters, which widens the range of possible combinations an attacker would have to work through.
Meta pointed to the obvious weak choice in its announcement, suggesting that anyone still using an easy string such as “123456” treat the change as a prompt to upgrade.
The move matters most against SIM swap fraud, where a criminal convinces a mobile carrier to move a victim’s number to a new SIM and then receives the registration code themselves.
More Caller Context for Android Users
The third feature is limited to Android for now. When a call arrives from a number that is not saved in the user’s contacts, WhatsApp displays extra detail before the person decides whether to pick up.
That detail includes the country the number appears to originate from and whether the caller shares any WhatsApp groups with the recipient. Both signals help a user judge, in a second or two, whether an unexpected call is plausible or a likely scam.
WhatsApp tied the design to how fraud works, saying scammers rely on urgency and that the new context lets users “take a beat with some more info before answering.” The company has not said when the feature will reach iPhone users.
The caller tool follows Scam Alert, an optional feature WhatsApp introduced a couple of weeks earlier that uses artificial intelligence to flag suspicious messages from people who are not in a user’s contacts. Together they point to a broader focus on the social side of attacks rather than only the technical side.
Background: Why These WhatsApp Account Security Features Matter
Each change targets a specific failure mode that security teams have watched play out for years. Understanding the weaknesses helps explain why Meta chose these three fixes.
How Passkeys Resist Phishing
Phishing is a con that tricks a target into handing over credentials, usually through a fake login page or a message that imitates a trusted brand. It works because a password is a shared secret that can be typed into the wrong box.
Passkeys remove that shared secret. Under the hood, your device keeps a private key that never leaves it, while the service holds a matching public key, and the two prove each other without any reusable password crossing the wire.
There is nothing to paste into a counterfeit page, which is why the method is considered resistant to phishing.
For a service the size of WhatsApp, that property scales. Attackers who run mass credential theft campaigns, including the newer kits that sit between a user and a real login page, gain far less from a target who signs in with a face or fingerprint.
SecurityWeek has covered how attackers automate these interception schemes in its report on phishing-as-a-service kits that defeat basic two-factor codes.
The Weakness of a Short PIN
A PIN of six digits offers one million possible combinations. That sounds large, but against automated guessing, or against an attacker who has already grabbed the one time registration code, it is a modest barrier.
A full password changes the math. Length and character variety expand the search space by orders of magnitude, so a criminal who obtains the registration code through a SIM swap still hits a wall they cannot easily brute force.
The upgrade is quiet, but it meaningfully raises the effort required for a full account takeover.
Scam Calls and Social Engineering
Not every attack targets software. Vishing, short for voice phishing, uses a phone call to manipulate a victim into revealing information or moving money, often by impersonating a bank, a delivery service, or a relative in trouble.
These calls thrive on speed and unfamiliarity. A number from an unexpected country, with no shared groups and no history, is a useful warning sign, and surfacing it before the call is answered gives the recipient a moment to think.
Readers can learn more about the tactic in this primer on how vishing attacks work and how to prevent them, and more broadly on how to recognize phishing scams and stay safe.
Who Is Affected and How
The update reaches a very large audience. WhatsApp counts roughly three billion users worldwide, spanning private individuals, small businesses, and organizations that treat the app as a primary channel with customers.
The passkey and 2SV changes apply across both major mobile platforms, so most users can act on them immediately through account settings. The caller context feature, by contrast, is available only to Android users at launch, which leaves iPhone owners waiting for parity.
People at higher risk stand to gain the most. Journalists, activists, business owners, and anyone whose number is publicly known face more targeted attempts, and multiple passkeys plus a strong 2SV password give them a sturdier baseline without adding much daily friction.
Implications of Stronger WhatsApp Account Security
The features are incremental on their own, but read together they say something about where consumer security is heading. Several angles are worth drawing out.
A Push Toward a Passwordless Future
Passing 1 billion passkey users is a milestone that goes beyond WhatsApp. It is one of the largest real world demonstrations that ordinary people will adopt passwordless login when it is fast and built into a device they already trust.
That matters for the wider industry. Every consumer service weighing whether to invest in passkeys can now point to a deployment at this scale as evidence that the friction is manageable, which tends to accelerate adoption elsewhere.
Consumer Messaging as Identity Infrastructure
A WhatsApp account is no longer just a chat log. It carries group memberships, business relationships, payment interactions in some regions, and a web of trust that a hijacker can exploit to defraud a victim’s contacts.
Hardening the login therefore protects more than the individual. When an account is harder to take over, the scams that spread by impersonating a trusted friend or company lose one of their most effective launch points.
Shifting the Scammer’s Playbook
The caller context tool signals a strategic move from blocking bad code to interrupting bad decisions. Since so many losses come from manipulation rather than exploitation, giving users a decision aid at the exact moment of risk can pay off more than another technical control.
It also raises costs for fraud operations. If a growing share of recipients see a foreign country code and no shared groups and simply decline, the economics of high volume scam calling weaken, at least until attackers adapt with new pretexts.
What It Means for Businesses and High-Risk Users
For organizations that run support or sales through WhatsApp, the update is a reason to revisit account hygiene. A compromised business account can be used to phish an entire customer base, so enrolling multiple passkeys on staff devices and enforcing a strong 2SV password is a low cost improvement.
Security leaders should also treat the change as a teaching moment. The most valuable outcome is not any single setting but a workforce that understands why a fingerprint beats a reused password, and why urgency on an unexpected call is a reason to slow down rather than speed up.
This section contains affiliate links; we may earn a commission at no cost to you.
Caller context and Scam Alert tackle social engineering. These services extend that same defensive posture to verification, email, and private storage:
- GetTrusted: identity and trust verification that helps confirm who you are actually dealing with before you act on a request.
- EasyDMARC: email security and DMARC enforcement that blocks the brand impersonation many scam campaigns start with.
- Tresorit: encrypted cloud storage for the sensitive files you would never want exposed in an account takeover.
Looking Forward
These WhatsApp account security features do not reinvent the app, but together they close familiar gaps. Passkeys reduce reliance on codes that can be intercepted, and a full 2SV password raises the cost of a successful guess.
The caller context tool addresses a different problem, the human one. Most scams succeed because a victim reacts quickly, so a few extra details before answering can be the difference between a lost afternoon and a lost bank balance.
Meta has not published a complete rollout timeline, and the caller feature remains limited to Android for now. Users who want the strongest protection can open Settings, add a passkey, and replace any weak PIN with a long password today.
Questions Worth Answering
What did WhatsApp announce on August 25, 2026?
- Meta announced three account security features: support for multiple passkeys, an upgrade from a 2SV PIN to a full password, and more caller context for Android users receiving calls from unknown numbers.
What is a passkey?
- A passkey is a device based login credential that verifies you with a fingerprint, face scan, or screen lock, with no password sent across the network, which makes it resistant to phishing.
How many people use passkeys on WhatsApp?
- Meta says more than 1 billion people now use a passkey to log back into their WhatsApp accounts.
Why does adding multiple passkeys matter?
- An account was previously limited to one passkey. Allowing several lets people who use WhatsApp on both iOS and Android, or on a work and personal phone, secure each device with biometrics.
How is two-step verification changing?
- The second secret behind the registration code was a PIN of six digits. It is being upgraded to a full password that can be longer and can include letters, numbers, and special characters.
Where do I set up passkeys and 2SV?
- Open WhatsApp and go to Settings, then Account, then Passkeys to add a passkey. The two-step verification password lives in the same account settings area.
What extra caller information does WhatsApp show?
- When an Android user gets a call from a number not in their contacts, WhatsApp shows the caller’s likely country and whether they share any WhatsApp groups with the recipient.
Is the caller context feature available on iPhone?
- Not yet. At launch the feature is limited to Android, and WhatsApp has not announced a date for iOS support.
How does this help against scams?
- Passkeys and a stronger 2SV password make account takeover harder, while caller context gives users a moment to judge an unexpected call before answering, countering the urgency scammers rely on.
This section contains affiliate links; we may earn a commission at no cost to you.
Also worth exploring: IDrive for automatic cloud backup, CyberUpgrade to manage security compliance, and Tenable to find the vulnerabilities attackers hunt for.
Sources: SecurityWeek (primary), the official WhatsApp blog, and The Hacker News.