Meta-owned messaging platform WhatsApp has rolled out a package of new account security features, including support for multiple passkeys on a single account, an expanded two-step verification system with a custom PIN, and enhanced caller identification tools, in a move the company says is aimed at reducing unauthorized access, account takeovers and impersonation.
The changes, announced this week, build on the platform’s existing end-to-end encryption and mark one of WhatsApp’s most significant expansions of user-facing authentication controls to date. They also bring the messaging service closer to industry-wide practices that have been moving away from SMS-based one-time passwords toward cryptographic, device-bound credentials endorsed by the FIDO Alliance and increasingly supported by major operating systems and browsers.
What Happened
WhatsApp confirmed three principal updates:
– Expanded two-step verification. The system now supports a custom PIN in addition to the existing SMS-based verification flow, creating a second layer of authentication when a phone number is registered on a new device. The change is designed to make it more difficult for an attacker who has obtained a verification code to take over an account.
– Multiple passkeys per account. Users can now register more than one passkey on a single account, enabling login through device-based authentication methods such as biometrics or device PINs without relying solely on SMS codes. Until this update, WhatsApp limited users to a single passkey per account.
– Enhanced caller details. The platform will surface additional contextual information about incoming calls to help users identify potential spam, scams or impersonation attempts before answering.
The features are being introduced alongside the platform’s longstanding end-to-end encryption, which WhatsApp has used to secure message content, and arrive as consumer messaging apps face growing regulatory and public scrutiny over their role in enabling fraud, scams and coordinated inauthentic behavior.
Why It Matters
Account-takeover attacks and SIM-swap fraud have remained persistent threats to users of mobile messaging platforms, with SMS-based verification widely regarded by security researchers as a weak authentication factor vulnerable to interception, phishing and social engineering. By allowing users to supplement SMS with biometric or device-PIN-based passkeys, WhatsApp is moving toward a model that is harder to phish and that does not depend on telecommunications infrastructure that can be compromised.
Allowing multiple passkeys per account addresses a longstanding usability limitation, particularly for users who switch between several devices, such as a primary phone, a secondary handset or a tablet. It also reduces the risk of account lockout if a single registered device is lost, damaged or replaced — a problem that has, until now, forced some users to choose between security and convenience.
The expanded two-step verification, which adds a custom PIN to the existing SMS flow, similarly gives users a fallback that does not depend on receiving a text message. For users in regions with inconsistent mobile network coverage, or for those targeted by SIM-swap fraud, the additional PIN can serve as a critical safeguard.
The enhanced caller details feature responds to a sustained pattern of fraud and impersonation conducted through messaging and calling tools, an area where regulators and consumer-protection agencies in multiple jurisdictions have pressed platforms to do more. Voice-based social engineering — in which callers impersonate banks, delivery services or government agencies — has been a particular focus of enforcement actions in India, the European Union, the United Kingdom and the United States.
Background and Context
Passkeys, which use public-key cryptography to authenticate users without transmitting reusable passwords or one-time codes, have been adopted at scale by a growing number of major technology companies over the past several years. The model is championed by the FIDO Alliance, a multi-stakeholder body that includes Apple, Google, Microsoft and Meta, and is intended to address weaknesses inherent in password-based and SMS-based authentication. Industry guidance from bodies such as the U.S. National Institute of Standards and Technology has progressively moved away from recommending SMS one-time passwords as a primary authentication factor.
WhatsApp’s introduction of single-passkey support in late 2024 was itself framed as part of this broader industry migration. The decision to allow multiple passkeys per account is a notable expansion of that work and brings WhatsApp closer to parity with authentication schemes used across other parts of Meta’s family of apps, including Facebook and Instagram.
The expanded two-step verification builds on a feature WhatsApp first introduced in 2017, which initially required a six-digit PIN in addition to SMS verification. The latest update formalizes the role of the custom PIN as a parallel authentication factor rather than a secondary fallback, and reflects user feedback that the previous configuration could be cumbersome when users changed devices frequently.
The enhanced caller details feature, meanwhile, extends a category of consumer protection that WhatsApp has incrementally expanded in recent years, including the introduction of context cards that surface information about unknown contacts and business accounts. Voice and video calls have become a particular vector for fraud, in part because they allow attackers to engage targets in real time and adapt their scripts, and because caller-ID spoofing remains relatively easy to execute across telecommunications networks.
Analysis
The updates reflect continued pressure on large consumer technology companies to demonstrate that they are investing in user-facing security, particularly as messaging platforms have become conduits for fraud, political manipulation and coordinated inauthentic behavior. By moving toward passkey-based authentication, WhatsApp is adopting a framework that is technically more resistant to phishing and interception than SMS-based one-time passwords, and that aligns the company with regulators and standards bodies that have flagged SMS as an inadequate primary factor.
The decision to allow multiple passkeys, rather than maintaining a one-passkey-per-account model, suggests the company has identified account lockout risk as a meaningful friction point that may have discouraged adoption. It also brings WhatsApp closer to parity with other authentication schemes used across Meta’s family of apps, an important consideration for users who interact with multiple Meta services and who may have come to expect consistent authentication behavior across them.
The enhanced caller details feature, while less technically significant than the passkey changes, addresses a category of harm that is often underreported: voice- and call-based social engineering. Its effectiveness will depend on the granularity of information surfaced to users and the extent to which the platform can detect and label fraudulent traffic in real time. WhatsApp has not publicly disclosed what signals the new caller details will incorporate — for example, whether the platform will surface metadata about a caller’s history on the network, geographic indicators or community-reported flags — and the practical value of the feature for end users will hinge on those details.
The expanded two-step verification, with its combination of a custom PIN and SMS flow, also raises a question that has followed two-factor authentication deployments for years: how the platform will handle users who lose access to both their device and their PIN. WhatsApp has not detailed the recovery flow for users who are locked out under the new system, and the absence of a clear recovery path has historically been a source of friction — and, in adversarial cases, a vector for account hijacking through support-channel social engineering.
What to Watch Next
– Rollout timeline and geographic availability. WhatsApp has not specified whether the features will be deployed globally at once or phased in by region, and adoption will depend on the pace of server-side and client-side updates across Android and iOS.
– Recovery flows for locked-out users. The platform’s response to users who lose both their device and their custom PIN will be a key test of the new system’s resilience against both accidental loss and targeted social engineering.
– Effectiveness of the enhanced caller details feature. Independent assessments of whether the new contextual information meaningfully reduces user exposure to spam and impersonation calls will be an important indicator of impact.
– Regulatory response. Consumer-protection agencies in India, the European Union, the United Kingdom and the United States have all pressed messaging platforms on fraud and impersonation in recent years. The new features may shape, or be shaped by, forthcoming regulatory expectations.
– Adoption rates for passkey-based authentication. The share of WhatsApp users who opt to register a passkey — and now multiple passkeys — will determine whether the security benefits of the model are realized in practice.
Conclusion
WhatsApp’s latest updates represent a meaningful expansion of the platform’s authentication and user-protection toolkit, and signal a continued migration away from SMS-based verification toward cryptographic, device-bound credentials. The decision to support multiple passkeys per account, in particular, addresses a usability gap that has limited the appeal of passkey-only authentication and brings WhatsApp closer to the authentication norms used elsewhere in Meta’s ecosystem. Whether the changes materially reduce fraud and account-takeover risk will depend on how the new tools are deployed, how the platform handles edge cases such as device loss, and how clearly the enhanced caller details feature communicates risk to users before they pick up the phone.
Sources
Hindustan Times: https://www.hindustantimes.com/india-news/whatsapp-tightens-account-security-with-new-safety-features-what-are-they-and-how-do-they-work-101787716263429.html
Corrections
If you believe this article contains an error, contact Herald Express with the source URL and supporting evidence.
Story synopsis gathered from: Hindustan Times – India News — source