WhatsApp Adds New Security Features to Fight Scams and Account Hacking: Here’s What’s Changing

WhatsApp is strengthening account protection with a new set of security features designed to make it harder for scammers and attackers to take control of user accounts. The latest changes include support for multiple passkeys, stronger two-step verification credentials and additional information about calls coming from unknown numbers.

The updates are particularly useful as WhatsApp accounts are increasingly targeted through phishing, fake verification requests, social engineering and other online scams. The new protections aim to give users stronger authentication options while also providing more context before they interact with an unfamiliar caller.

Multiple Passkeys Can Be Added to One WhatsApp Account

One of the biggest changes involves passkeys.

WhatsApp already allows users to use passkeys as an alternative authentication method. Instead of relying only on verification codes, passkeys can use security mechanisms available on the device, such as a fingerprint, face recognition or screen lock.

According to the update, users will now be able to associate more than one passkey with the same WhatsApp account.

This could be particularly useful for people who use WhatsApp across different devices or ecosystems, such as Android and iOS.

Users can look for the option under:

WhatsApp > Settings > Account > Passkeys

Availability may depend on the app version, operating system and the rollout status for individual accounts.

Why Passkeys Can Improve Account Security

Traditional passwords can be stolen through phishing websites or exposed through data breaches. Verification codes can also be targeted by scammers who trick victims into sharing them.

Passkeys work differently because authentication is tied to cryptographic credentials and the user's device.

That means a user may be able to verify their identity using their phone's fingerprint sensor, facial authentication or device PIN rather than manually entering a conventional password.

Passkeys are also designed to be resistant to many common phishing techniques.

Two-Step Verification Is Getting Stronger

WhatsApp is also upgrading its two-step verification protection.

Until now, users have typically protected this feature using a six-digit PIN. The new system is designed to allow stronger credentials using combinations of letters, numbers and special characters.

A stronger password can make it significantly harder for attackers to guess or brute-force account security credentials.

Users should avoid easily predictable combinations such as:

  • 123456
  • Their mobile number
  • Their name or date of birth
  • Repeated numbers or characters
  • Passwords already used on other services

A unique and difficult-to-guess credential provides considerably better protection.

Unknown WhatsApp Calls Will Show More Information

Another security improvement targets suspicious calls.

Scammers frequently contact victims from unfamiliar numbers and attempt to create urgency—for example, claiming there is a banking problem, account suspension, emergency or financial opportunity.

WhatsApp plans to provide additional information when calls arrive from numbers that users haven't saved.

On supported Android devices, users may be able to see information such as whether the number appears to be from another country and whether the caller shares a WhatsApp group with them.

This extra context could make suspicious calls easier to identify before answering them.

Why the Unknown-Caller Information Matters

An international number is not automatically fraudulent, and sharing a group with someone does not guarantee that the person is trustworthy.

However, these signals provide additional context.

For example, if someone receives an unexpected international WhatsApp call from a person they don't know and with whom they share no groups, they may want to be especially cautious before answering or providing any information.

Users should also remember that legitimate organisations generally should not ask for OTPs, verification codes, passwords or other confidential credentials through an unsolicited WhatsApp call.

End-to-End Encryption Remains in Place

The new security tools do not replace WhatsApp's existing privacy protections.

Personal WhatsApp messages and calls continue to use end-to-end encryption, meaning their content is designed to remain between the sender and recipient.

The new features instead focus primarily on account authentication and scam prevention—helping users protect their accounts and make better decisions when interacting with unfamiliar contacts.

WhatsApp Users Should Check Their Security Settings

As the features roll out, users should keep WhatsApp updated and periodically review the security options available under the Account and Privacy sections.

Enabling passkeys and two-step verification, reviewing linked devices, avoiding suspicious links and never sharing registration or verification codes can substantially reduce the chances of an account takeover.

Users should also be cautious when an unknown caller creates urgency or asks for money, banking information, OTPs or account credentials.

The new protections add another security layer, but user awareness remains important because many WhatsApp scams rely on social engineering rather than directly breaking the app's encryption.

For the latest availability and security guidance, users can check WhatsApp's official website and keep the app updated to the newest version.