- What: WhatsApp enhances account security with passkeys and 2SV
- Impact: Improved protection for user accounts
Identity & Access WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update When Android users get a call from a non-contact, they will see more information about the caller, including their country. By Eduard Kovacs | August 25, 2026 (9:00 AM ET) Flipboard Reddit Whatsapp Whatsapp Email WhatsApp on Tuesday announced several new features designed to enhance account security, including related to passkeys, two-step verification (2SV), and caller context. The Meta-owned messaging app says more than 1 billion individuals now rely on a passkey to log in to their WhatsApp accounts. Users can now add more than one passkey, which can be useful for those who use the application on both iOS and Android devices. As for two-step verification, the one-time passcode that was previously a six-digit PIN is now being upgraded to a full password. The password can be longer and it can include alphanumeric and special characters. The last new security feature is, for the time being, only for Android users. When they get a call from a non-contact, they will see more information about the caller, including their country and whether they are members of the same WhatsApp groups. “Scammers rely on urgency – now you can take a beat with some more info before answering,” WhatsApp said. Advertisement. Scroll to continue reading. The news comes a couple of weeks after WhatsApp unveiled Scam Alert , an optional feature that uses AI to flag suspicious messages from non-contacts. Related : WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy Related : WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities Related : Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs 91 Vulnerabilities Patched in Spring Application Framework Venezuelan Gets Record Federal Prison Term for ATM Jackpotting Personal Information Exposed in Apollo Global Data Breach Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Hackers Target Zimbra Servers in Active Exploitation Campaign OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses Latest News Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference First Malware Built Specifically for Car Head Units Fuels Botnet Silent Patches Don’t Stop Attackers – They Blind Defenders Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff CISA Warns of Exploited Oracle WebLogic Vulnerability ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited Hired for One Job, Judged on Another: The CISO’s Real Problem Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital. Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer. Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer. More People On The Move Expert Insights Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email