Meta has begun rolling out a set of account security upgrades for WhatsApp, giving its more than 3 billion users across 180-plus countries stronger tools to resist phishing and account takeover attempts.

Multiple Passkeys Per Account

WhatsApp already supported passkey logins using fingerprint, Face ID, or a device screen lock, a method Meta says more than 1 billion people use today. Previously, users were limited to a single passkey per account. The update now allows people who split their time between Android and iOS devices to register a separate passkey for each platform, making it easier to maintain phishing-resistant sign-ins regardless of which device they are using. The feature can be managed under Settings > Account > Passkeys. Passkey support first arrived on Android in October 2023.

Stronger Two-Step Verification

WhatsApp has also overhauled its two-step verification, moving away from a simple six-digit PIN in favor of a full alphanumeric password that supports special characters. Meta explicitly called out weak, easily guessed codes like “123456” as a reason for the change, positioning the longer password format as a meaningful upgrade in resistance to brute-force and social engineering attacks.

More Context on Unknown Callers

On Android, WhatsApp is adding extra information to call screens for numbers not saved in a user’s contacts, including whether the call originates from a different country and whether the user shares any groups with that number. The goal is to give recipients a moment to evaluate a call before answering, undercutting the urgency tactics that scammers commonly rely on.

Part of a Broader Anti-Fraud Push

These changes extend a string of security features WhatsApp has introduced throughout the year. In January, the company began rolling out “Strict Account Settings,” an Apple Lockdown Mode style feature aimed at protecting high-risk users such as journalists and public figures from sophisticated threats including spyware. In March, WhatsApp added warnings for potentially fraudulent device-linking requests, a technique attackers use to hijack accounts via linking codes or malicious QR codes. Earlier this month, the company also began a limited beta of “Scam Alert,” which uses an on-device machine learning model to flag likely scam conversations in real time.

Security teams supporting organizations that rely on WhatsApp for business communication should encourage users to enable passkeys on all devices and migrate to a strong alphanumeric two-step verification password as these features become available.