WhatsApp is rolling out multiple passkeys, password-based two-step verification, and unknown-caller context to counter rising phishing and account-takeover fraud.

WhatsApp Adds Passkeys, Password-Based 2FA and Caller Context as Account Takeovers Rise

The420 Web Correspondent
5 Min Read

WhatsApp is rolling out three account security upgrades that, taken together, target the two weakest points in how most people protect their accounts: guessable verification codes and blind trust in an unfamiliar caller. Meta announced the changes on August 25, and for a platform with more than three billion users worldwide, and several hundred million in India alone, even incremental fixes carry outsized weight.

The most visible change lets users attach more than one passkey to a single WhatsApp account. Previously, a person switching between an Android phone and an iPhone, a common reality in Indian households where family members often share or rotate devices, could register only one passkey at a time. Now they can set up authentication on multiple devices simultaneously, each verified through a fingerprint, Face ID or screen lock rather than a password typed into an app.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

From a Six-Digit PIN to a Real Password

The more consequential upgrade concerns Two-Step Verification, the additional PIN layer WhatsApp has offered since 2017 to stop someone from hijacking an account even after obtaining a one-time passcode. Until now, that layer was a six-digit number, precisely the kind of credential prone to being reused, guessed or lifted through social engineering. WhatsApp is now allowing users to replace it with a full alphanumeric password of at least eight characters, including letters, numbers and, optionally, special characters.

The company’s own framing was blunt: users still relying on sequences like “123456” were told this is their cue to upgrade. The shift matters because six-digit PINs have long been a soft target in account-takeover fraud, where criminals combine a stolen SIM, a phished OTP and a predictable PIN to seize control of a victim’s number entirely. A longer, harder-to-guess password closes one of the easier paths into that chain.

More Context Before You Pick Up

The third change, currently limited to Android, adds information to incoming calls from numbers that are not saved in a user’s contacts, including the country the call originates from and whether the caller shares any WhatsApp groups with the recipient. It is a modest addition, but it directly answers a tactic that has become central to phone-based fraud in India: the unexpected call demanding urgent action, timed precisely so the recipient has no chance to verify who is actually speaking.

Security researchers have noted that these three measures work as a pair rather than in isolation. Passkeys and stronger passwords raise the cost of breaking into an account in the first place; caller context helps a user pause before a criminal, having failed to break in, simply tries to talk their way past the victim instead. Both failure modes have driven a meaningful share of India’s cybercrime losses over the past year.

Why the Timing Matters for Indian Users

These updates land against a backdrop in which WhatsApp itself has repeatedly become the delivery mechanism for large-scale fraud in India, from senior-executive impersonation scams that hijack an account’s identity to convince finance teams to wire crores, to routine phishing attempts that lean on a stolen OTP and a weak PIN. Indians reported losing more than ₹22,000 crore to cyber fraud in 2025, with the national 1930 helpline logging over three crore calls through the year, and a large share of that activity begins with exactly the kind of unverified message or unfamiliar call these new features are designed to interrupt.

None of the three changes are mandatory, and their real-world effect will depend heavily on how many users actually switch on a passkey, replace a lazy PIN, or pay attention to the caller information Android now surfaces. Meta has not published a rollout timeline, saying only that the features will appear gradually, with the caller-context tool for now confined to Android and no confirmed date for an iOS equivalent. For a platform this deeply embedded in how Indian businesses and families communicate, the gap between a feature existing and a feature being used remains the more important number to watch.

Stay Connected