Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps
August 25, 2026
AI Security Startup Alice Raises $140M Amid Surging Enterprise AI Threats
August 25, 2026
SynkLoader Malware Impersonates IT Support on Microsoft Teams
August 25, 2026
Home/CyberSecurity News/WhatsApp Adds Passkey Support for 1 Billion Users, Bolstering Two-Step Verification
CyberSecurity News

WhatsApp Adds Passkey Support for 1 Billion Users, Bolstering Two-Step Verification

Key Takeaways WhatsApp has significantly enhanced account security for over a billion users by expanding passkey support. The platform is upgrading its two-step verification from a six-digit PIN to a...

Sarah simpson
Sarah simpson
August 25, 2026 4 Min Read
4 0

Key Takeaways

  • WhatsApp has significantly enhanced account security for over a billion users by expanding passkey support.
  • The platform is upgrading its two-step verification from a six-digit PIN to a stronger, alphanumeric password.
  • New anti-scam features are being introduced for Android users, providing additional context for unknown incoming calls.
  • These updates aim to bolster defenses against phishing, SIM-swap attacks, and social engineering fraud.

WhatsApp Fortifies Account Security with Passkeys for Over a Billion Users and Enhanced Two-Step Verification

WhatsApp, the Meta-owned messaging giant, has announced a substantial upgrade to its account security features, confirming that over one billion users now utilize passkeys for authentication. This rollout represents one of the most extensive implementations of passwordless authentication in the consumer technology sector to date.

Table Of Content

  • Key Takeaways
  • WhatsApp Fortifies Account Security with Passkeys for Over a Billion Users and Enhanced Two-Step Verification
  • Passkeys Reach Critical Mass
  • Upgrading Two-Step Verification to Alphanumeric Passwords
  • New Anti-Scam Measures for Inbound Calls
  • What You Should Do

In parallel with this milestone, the platform is introducing a significant enhancement to its two-step verification process, replacing the traditional six-digit PIN with a robust alphanumeric password. Additionally, new caller-context features are being deployed to help users identify potential scams before responding to unknown calls.

Passkeys Reach Critical Mass

Passkeys enable WhatsApp users to authenticate their accounts using their device’s built-in biometric sensors, such as fingerprint or Face ID, or by entering their device’s screen lock code. This method eliminates the need for users to type in a numeric code or PIN, streamlining the login process while significantly boosting security.

The inherent cryptographic nature of passkeys, which are tied directly to a user’s device rather than relying on shared secrets transmitted over networks, makes them considerably more resilient to common attack vectors. These include phishing attempts, credential stuffing attacks, and SIM-swap fraud, which often target legacy verification codes.

WhatsApp reports that passkey adoption has now surpassed the one billion user mark. The company is also expanding support for this feature, allowing users who operate across both Android and iOS devices to register multiple passkeys to a single account. Users can manage their passkeys by navigating to Settings > Account > Passkeys, where they can add new keys or review existing ones linked to their device’s password manager.

Upgrading Two-Step Verification to Alphanumeric Passwords

Perhaps the most impactful change for overall account security involves the two-step verification (2SV) system. Previously, 2SV on WhatsApp required a six-digit PIN after the initial SMS one-time passcode. WhatsApp is now allowing users to replace this PIN with a full-fledged alphanumeric password, capable of including special characters.

This upgrade dramatically increases the complexity of the secondary authentication layer, making brute-force and credential-guessing attacks far more difficult. According to the WhatsApp security announcement, new passwords must be a minimum of eight characters long and include at least one letter and one number, with an option to further strengthen them using symbols.

The move addresses a long-standing vulnerability associated with short numeric PINs. While better than no protection, six-digit PINs offer a comparatively small “keyspace” and are frequently chosen as easily guessable sequences like “123456” or reused across multiple services. Cybersecurity researchers have consistently highlighted such short numeric codes as a weak point in account recovery and secondary authentication flows, as they can often be bypassed through automated guessing or social engineering tactics more quickly than a properly constructed password.

WhatsApp’s communication surrounding this rollout explicitly acknowledges this risk, urging users still relying on simple numeric PINs to upgrade their security settings. Independent reports suggest that this account password feature was initially observed in Android beta builds as early as July 2026, under the codename “dedicated account password system,” before its confirmed wider release this week.

Security Feature Previous Implementation Upgraded Standard
Primary Login Method SMS Verification Codes Biometric & Device-Bound Passkeys
Two-Step Verification 6-Digit Numeric PIN Alphanumeric Password (8+ Characters)
Cross-Platform Support Single Ecosystem Key Multi-Device Key Registration
Inbound Call Security Unverified Caller Display Contextual Indicators (Country & Shared Groups)

New Anti-Scam Measures for Inbound Calls

WhatsApp is also rolling out a practical, albeit lower-profile, anti-fraud measure specifically for Android users, building on its ongoing efforts to combat messaging scams. When a call originates from a number not saved in a user’s contacts, the incoming call screen will now display additional contextual information. This includes details such as whether the number is from a different country and if the caller shares any common groups with the recipient.

Many scam and vishing operations exploit urgency and unfamiliarity to pressure victims into answering or acting impulsively. This added contextual friction provides users with a crucial moment to assess the legitimacy of an incoming call before engaging, potentially preventing them from falling victim to fraud.

Account takeover remains one of the most prevalent entry points for various forms of abuse on messaging platforms, ranging from SIM-swap fraud to social engineering scams that hijack a victim’s contact list. By simultaneously integrating scaled passwordless authentication, a more robust secondary password requirement, and intelligent contextual caller information, WhatsApp is reinforcing multiple layers of its security architecture, rather than relying on a single control.

What You Should Do

  • Enable Passkeys: Navigate to Settings > Account > Passkeys and set up a passkey for your WhatsApp account using your device’s biometric or screen lock authentication.
  • Upgrade Two-Step Verification: If you are still using a six-digit PIN for two-step verification, update it to a strong, alphanumeric password (at least 8 characters, including letters, numbers, and ideally symbols).
  • Review Account Security: Regularly check your WhatsApp security settings to ensure all available protections are enabled and up-to-date.
  • Exercise Caution with Unknown Calls: Pay attention to the new caller context information for unknown numbers on Android and always be wary of unsolicited calls, especially those demanding immediate action or personal information.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks

Next Post

ASOS Warns Customers of Credential Stuffing Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
WhatsApp Adds Passkey Support for 1 Billion Users, Bolstering Two-Step Verification
August 25, 2026
ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks
August 25, 2026
Fake Microsoft Security Scan Tricks Users into Removing Antivirus
August 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us