WhatsApp is rolling out new account security features designed to improve login protection, strengthen two-step verification, and help users identify potential scams.
The updates include support for multiple passkeys, stronger password-based two-step verification, and additional information about unknown callers. These tools are intended to protect WhatsApp accounts from unauthorized access, phishing attempts, and social engineering attacks.
WhatsApp already allows users to sign in securely with a passkey using a fingerprint, Face ID, or device screen-lock code. Users can now create separate passkeys for each platform, making it easier to secure accounts across multiple Android and iOS devices.
“More than 1 billion people have already set it up. If you use both Android and iOS devices, you can now add multiple passkeys to your account. To get started, go to [Settings] > [Account] > [Passkeys],” WhatsApp said.
WhatsApp has also enhanced its two-step verification feature. Instead of relying only on a six-digit PIN, users can now create longer alphanumeric passwords that may include special characters.
“It used to be a 6-digit PIN, but now we’ve upgraded it to a full password. It’s longer, uses alphanumeric characters, and even includes special characters to make it harder to guess. If you’re using ‘123456,’ this is your sign to upgrade,” WhatsApp said.
The company is also adding more context to the WhatsApp call screen. Before answering a call from someone who is not in their address book, users may see additional details about the caller, providing another layer of protection against fraudulent calls and impersonation scams.
On Android, users can now see information about unknown callers, including whether the phone number is registered in another country and whether they share any groups with the caller. WhatsApp said this additional context can help users pause and assess suspicious calls before responding.

The new call-screen information is part of a broader WhatsApp effort to protect users from scammers. The messaging service has introduced several security features this year designed to identify suspicious activity and block attacks before users lose access to their accounts or share sensitive information.
In January, WhatsApp began rolling out “strict account settings.” The Apple Lockdown Mode-style feature is designed to protect high-risk users, including journalists, public figures, and other individuals who may be targeted by advanced threats such as spyware.
Two months later, Meta announced that WhatsApp would warn users when a device-linking request appeared suspicious. Attackers commonly use fraudulent linking requests to hijack accounts by tricking victims into sharing verification codes or scanning malicious QR codes.
Earlier this month, WhatsApp also introduced an optional “scam alert” feature in a limited beta rollout. The feature uses on-device machine learning models to warn users when they may be targeted by scam activity.
According to WhatsApp, more than 3 billion people across more than 180 countries use the messaging service to communicate with family and friends. Users should enable passkeys, choose a strong two-step verification password, and carefully review unknown calls and device-linking requests to improve their WhatsApp account security.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




