WhatsApp is rolling out a new optional Scam Alert feature designed to warn users when scammers may be targeting them. The feature uses on-device machine learning to identify potential fraud while helping preserve the privacy of encrypted conversations.
Scam Alert is currently available through a limited beta rollout as WhatsApp tests the warning system with researchers from the Bug Bounty community.
“Today, we’re sharing an early look at Scam Alert, a new optional feature that runs on-device machine learning models to alert users of potential fraudulent messages,” WhatsApp said. “Message content never leaves the device for classification or is automatically reported to WhatsApp, Meta or anyone else. This feature complements end-to-end encryption, while also enabling user-controlled optional fraud alerts if the model determines there is a potential for fraud.”
WhatsApp’s Scam Alert model is trained using user-reported fraud conversations. It uses probabilistic classification based on linguistic signals and conversation structure to assess whether messages from unknown contacts match known scam patterns.
When WhatsApp detects a potential fraud attempt, users will receive an alert in the chat. They can then choose whether to block the contact, report the conversation, or continue chatting.
WhatsApp said users can mark an alert as a mistake by designating the conversation as trusted. Once a chat is marked as trusted, the warning will be removed and Scam Alert will not flag that conversation again. Users can also optionally share the last five messages they received on WhatsApp to help improve the feature’s accuracy.
According to the company, the on-device machine learning models and message data processed by them never leave the user’s device. WhatsApp users can also disable the Scam Alert feature at any time.
The new feature is part of WhatsApp’s broader effort to protect its users from scams and other fraudulent activity. The company has introduced several security updates designed to identify suspicious behavior before users fall victim to an attack.
In March, Meta announced that WhatsApp would warn users when behavioral signals suggested a device-linking request could be fraudulent. Attackers commonly use this technique to hijack accounts by tricking victims into scanning malicious QR codes or sharing device-linking codes.
Two months ago, WhatsApp also began rolling out Strict Account Settings, a lockdown-style security feature intended to protect journalists, celebrities and other high-risk users from advanced threats, including spyware attacks.
The feature was introduced after journalists, activists and politicians had their phones infected with spyware, including NSO Group’s Pegasus, through messaging applications such as WhatsApp. Some zero-click exploits allow attackers to compromise iOS and Android devices without requiring any interaction from the victim.
WhatsApp is used by more than 3 billion people across more than 180 countries to communicate with family, friends and colleagues, making the platform a major target for scammers and cybercriminals.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




