Platforms

WhatsApp's new security upgrade targets the account takeover risk that's haunting brand teams

Written by Lucy Hall and reviewed, fact-checked and signed off by a SocialDay editor before publication. Read our editorial standards and corrections policy. Spotted something wrong? Tell the newsroom.

WhatsApp's new security upgrade targets the account takeover risk that's haunting brand teams

WhatsApp has upgraded two-step verification from a six-digit PIN to a full password that supports alphanumeric characters and special symbols, the platform said on 25 August. The company also added support for multiple passkeys per account and introduced extra context for incoming calls from unknown numbers on Android.

The changes sound incremental. They are not. For any brand using WhatsApp Business to handle customer service, community management, or campaign activation, these updates directly address the account takeover threat that has become one of the most underestimated security risks in social media marketing operations.

Why this matters now

Cloned WhatsApp Business accounts have become a real threat to businesses, with compromised profiles used by scammers to demand money from contacts. A common scam involves hackers impersonating companies, gaining access to WhatsApp through social engineering, and using it to defraud contacts.

The risk is not theoretical. Scammers have been hijacking real WhatsApp Business accounts to deceive users, and the stakes extend well beyond a locked account. When someone else controls your customer service channel, they control your customer relationships, your brand reputation, and potentially sensitive customer data. Total account takeovers can result in prolonged downtime, and every day a compromised account stays live, audiences are vulnerable to brand impersonation attacks.

The difference between consumer messaging and business use is that WhatsApp Business sits at the centre of operations for many brands. It is not just a comms channel. It is where orders come through, where payments are confirmed, where support tickets close. For those using WhatsApp Business to manage orders or internal communications, attackers can request payments, modify sensitive information, obtain customer data, or damage brand reputation with fraudulent messages.

1 billion people now use passkeys on WhatsApp WhatsApp, August 2026

What has actually changed

The headline update is the shift from PIN to password. Until now, WhatsApp's two-step verification used a six-digit PIN as extra protection to prevent account takeover even if someone obtained a user's one-time passcode. That PIN is now replaceable with a longer, alphanumeric password that can include special characters.

The second update is support for multiple passkeys. Users can now add more than one passkey to an account, a change intended for people who use the service across Android and iOS devices. A passkey lets a user verify access to WhatsApp with the same method used to unlock a device, such as fingerprint, facial recognition, or screen-lock code.

The third change is Android-only but operationally useful: when a call comes from a number not saved in contacts, WhatsApp will show additional context before the call is answered, including whether the number is registered in another country and whether the caller shares any groups with the recipient. WhatsApp said the information gives users more context before deciding whether to answer an unfamiliar call, noting that scammers often rely on urgency to pressure people into responding quickly.

The real implication: control over who accesses what

For social and customer service teams, the operational question is usually not whether security features exist. It is whether the team actually uses them, and whether those features map to how work actually happens.

Common risk factors for a potential account takeover include sharing 2FA codes on Slack or WhatsApp, continued account access for former staff and vendors, and poor social media auditing. The new password option makes brute-forcing two-step verification harder, but only if teams adopt it and treat it as seriously as they would treat access to a CRM or payment gateway.

The multiple passkey support is more directly useful. Teams that run WhatsApp Business across devices (a support lead on iOS, a campaign manager on Android) previously had to share a single passkey or revert to less secure methods. Users can now store more than one passkey for an account, which Meta said was particularly useful for those using both iOS and Android devices. That eliminates a common workaround where one person holds the passkey and everyone else uses less secure login flows.

The more useful and mobile an account becomes, the more valuable it becomes to attackers, scammers, and impersonators.

WERSM analysis, August 2026

The caller context feature is narrower but speaks to a specific problem: distinguishing legitimate inbound contact from scams in real time. Calls will now show the country associated with the number and whether the caller shares any group chats with the recipient, information Meta said could help users identify potential scammers. For customer service teams managing high volumes of inbound WhatsApp queries, knowing whether an unfamiliar caller shares a community group or is calling from an unexpected country helps filter noise faster.

What to do if you are running WhatsApp Business

The features are rolling out now, but adoption is manual. Here is what changes operationally:

Upgrade your two-step verification immediately. Go to Settings, then Account, then Two-step verification. Replace your six-digit PIN with a longer password that uses a mix of letters, numbers, and symbols. Treat it with the same security hygiene as your email password. The feature can be activated by navigating to settings and turning on two-step verification under the account section, then entering the password and adding an email address in case it needs to be reset.

Set up multiple passkeys if you run multi-device. Users can manage their passkeys by navigating to Settings, then Account, then Passkeys. If your team accesses WhatsApp Business from both iOS and Android, this eliminates the single point of failure that comes from one person holding the only biometric login.

Audit who still has access. Account takeover often happens not through sophisticated hacks but through old credentials that never got revoked. Restrict access to WhatsApp Business accounts and data based on roles, and secure user accounts with strong passwords and multi-factor authentication. If someone leaves the team or a contractor finishes a project, remove their access that day.

Train your team on the new caller context. The Android feature showing country and shared groups before a call is answered only helps if your team knows to check it and understands what a red flag looks like. The top tip to keep WhatsApp Business accounts secure is to pause before responding to an unexpected message, because scammers rely on urgency and distraction.

Do not share 2FA codes or passwords in Slack, email, or other WhatsApp accounts. WhatsApp support will never ask you to pay or share verification codes via chat. If a workflow requires that, the workflow is the vulnerability.

What this does not fix

These updates reduce the attack surface, but they do not eliminate the structural risks that come with using a consumer messaging platform for business-critical workflows.

Running business communications without proper administrative controls is a massive risk, and WhatsApp in its native form does not offer the kind of user management tools businesses actually need, with no central authentication system, no ability to assign roles, set permissions, or grant team-level access control. While WhatsApp messages are encrypted, backups stored in cloud services may not be, and organisations should enable encryption for backups to ensure that data remains secure.

If your WhatsApp Business account is mission-critical and handles sensitive customer data, payment information, or high-value transactions, the platform's consumer-grade architecture may not be sufficient even with stronger passwords. Most large businesses using WhatsApp API work with a reliable Business Solution Provider adhering to security protocols, and making the right choice is crucial to provide complete safety to customers.

Meta has rolled out new security features several times in the past few months. The company launched usernames in late June to allow people to share their profiles without disclosing their phone number. In June, WhatsApp added a warning screen that appears before users open a chat with an unfamiliar phone number, showing details like the country code and shared groups. The trajectory is clear: WhatsApp is hardening account-level security in response to growing abuse of business accounts.

For social media and customer service teams, the responsibility is to keep pace. These features only work if they are turned on, understood, and enforced across everyone who touches the account. The risk of not doing that is no longer hypothetical.