WhatsApp is overhauling several account security features, the Meta-owned messaging app announced Tuesday, as account takeovers and scam calls remain persistent problems for its more than 2 billion users worldwide.
The changes center on three areas: a stronger two-step verification system, more information about unfamiliar callers, and expanded support for passkeys, the fingerprint- or face-based login method that has replaced passwords for a growing number of apps.
From PINs to Passwords
Two-step verification has long let WhatsApp users set a secondary code that’s required even if someone else gains access to their phone number or one-time SMS passcode. Until now, that code was a six-digit PIN — a format security researchers have repeatedly flagged as vulnerable to guessing or brute-force attacks, particularly when users choose predictable numbers like birthdays.
WhatsApp is replacing it with a full alphanumeric password that can include special characters. The company says this makes the credential harder to crack, aligning WhatsApp with standard password practices used elsewhere on the web.
The update is notable given how central account takeovers have become to WhatsApp fraud, particularly across Africa, where the app is often used for both personal communication and business transactions. Scammers frequently attempt to hijack accounts by intercepting SMS verification codes or exploiting social engineering tactics, then impersonating the account owner to solicit money from contacts.
A stronger PIN alone does not close every avenue for account theft, however. WhatsApp’s announcement does not address SIM-swap fraud, a common attack vector in which criminals convince mobile carriers to transfer a victim’s phone number to a new SIM card, bypassing SMS-based verification entirely. That vulnerability remains outside WhatsApp’s control, since it depends on telecom carrier security practices rather than the app itself.
Caller Context Arrives — But Only on Android
WhatsApp is also rolling out new information for calls from numbers not saved in a user’s contacts. On Android devices, callers will now see whether an unknown number originates from a different country and whether they share any groups in common with the caller.
The feature is aimed at scam calls, which often rely on impersonation and urgency to pressure victims into acting before they can verify who they’re speaking to. Giving users a moment to assess a caller’s context, rather than answering blind, is intended to interrupt that pressure tactic.
The rollout’s limitation to Android is notable and unexplained in WhatsApp’s announcement. The company did not say whether iPhone users will eventually get the same feature or on what timeline. Given that iOS carries meaningful market share in many of WhatsApp’s key markets, including sizable segments of users in Nigeria, Kenya and South Africa, the omission leaves a gap in protection for a substantial share of the user base, at least for now.
Passkeys Cross a Billion Users
WhatsApp said more than 1 billion people have adopted passkeys since introducing the feature, which allows users to log into the app using a device’s fingerprint, face recognition or screen-lock code instead of typing a password or code. The company is now allowing users to register multiple passkeys per account, useful for people who move between an Android phone and an iPad, for instance, or maintain both Android and iOS devices.
To set one up, WhatsApp says users can navigate to Settings, then Account, then Passkeys.
The billion-user figure, though striking, comes with no baseline for comparison. WhatsApp did not disclose passkey adoption over time, what share of its total user base that number represents, or how adoption breaks down by region. Passkey support also depends on device compatibility and operating system version, meaning users on older or lower-cost Android phones — common across much of West Africa — may not have access to the feature at all.
An Incremental, Not Structural, Fix
Taken together, the changes reflect a familiar pattern for WhatsApp: layering optional security tools onto an existing system rather than mandating stronger defaults. Two-step verification, passkeys and caller context all remain opt-in, meaning their effectiveness depends on users actively enabling them — a threshold that has historically limited adoption of similar features across messaging platforms.
Whether the update meaningfully reduces fraud, or simply shifts tactics for scammers already adept at working around existing safeguards, will depend on adoption rates WhatsApp has yet to disclose.