As messaging platforms become increasingly important for personal communication, business operations, customer engagement, and professional collaboration, protecting the accounts behind those communications has become a major cybersecurity priority.
WhatsApp is introducing several account security improvements designed to make account takeover more difficult. The updates include support for multiple passkeys, stronger two step verification, and additional information for users receiving calls from unknown contacts.
These changes reflect a broader shift in cybersecurity toward stronger identity protection and authentication methods that reduce dependence on credentials that attackers can steal or manipulate.
Multiple Passkeys Add Another Layer of Account Protection
One of the most significant updates is the ability to associate more than one passkey with a WhatsApp account.
Passkeys use device based authentication such as fingerprints, facial recognition, or a device screen lock instead of relying entirely on traditional passwords or SMS based authentication.
WhatsApp has already seen more than one billion users adopt passkeys. The new multiple passkey capability is particularly useful for people who use multiple devices or operate across different mobile platforms.
For example, a user who maintains both Android and iOS devices can have authentication credentials associated with the respective devices.
From a cybersecurity perspective, this approach can reduce exposure to risks associated with password theft, phishing, credential reuse, and interception of authentication codes.
Stronger Two Step Verification Moves Beyond Simple PINs
WhatsApp is also strengthening its two step verification mechanism.
Previously, users relied on a six digit PIN as an additional authentication factor. The updated approach allows a more complex password containing letters, numbers, and special characters.
This change is important because short numeric authentication codes can be easier to guess, particularly when users select predictable combinations.
Organizations should take this as a broader reminder that authentication policies need to evolve as attack techniques improve.
Strong passwords remain important, but organizations should also prioritize phishing resistant authentication methods such as passkeys, hardware backed credentials, and appropriately configured multifactor authentication.
Unknown Calls Can Provide More Security Context
Another improvement provides Android users with additional information when receiving calls from numbers that are not saved in their contacts.
The additional context can include information such as whether the number originates from another country and whether the caller shares groups with the recipient.
This type of contextual security information can help users make better decisions before answering unexpected calls.
That matters because social engineering remains one of the most effective methods used by attackers. A malicious actor does not necessarily need to exploit a technical vulnerability if they can convince a user to reveal information, transfer money, approve an authentication request, or provide access to another system.
Account Takeover Remains a Major Enterprise Risk
Messaging account compromise can have consequences far beyond a single individual.
When an employee’s messaging account is compromised, attackers may attempt to:
• Impersonate the employee
• Conduct social engineering attacks against colleagues
• Target customers or business partners
• Distribute malicious links or files
• Request fraudulent payments
• Obtain sensitive business information
• Conduct phishing campaigns from trusted accounts
• Use compromised accounts to support broader credential theft campaigns
For organizations that rely heavily on messaging applications for communication, account security should therefore be considered part of the broader identity and access management strategy.
Why Passkeys Matter for Businesses
Passkeys are becoming increasingly important because they can provide stronger protection against several traditional authentication threats.
Organizations should evaluate how passwordless authentication can be incorporated into their identity security programs.
Key areas to consider include:
• Phishing resistant authentication
• Device security and endpoint protection
• Identity lifecycle management
• Privileged account protection
• Multifactor authentication enforcement
• Account recovery controls
• Credential monitoring
• Session management
• User awareness training
• Continuous identity risk assessment
The goal should not simply be to introduce another authentication feature. Organizations should build a layered identity security strategy where authentication, device security, monitoring, and user awareness work together.
Security Must Extend Beyond the Login Screen
Strong authentication is only one component of account security.
Organizations should also monitor suspicious login behavior, unusual device activity, unexpected account changes, and abnormal communication patterns.
Security teams should establish procedures for quickly responding to compromised accounts and ensure employees understand how to report suspicious messages, authentication requests, and unexpected calls.
For high risk users such as executives, administrators, financial teams, security personnel, and employees with access to sensitive information, stronger authentication controls can significantly reduce the potential impact of account takeover attempts.
The Broader Cybersecurity Lesson
The WhatsApp update demonstrates an important trend in modern cybersecurity.
Attackers continue to target identity because compromised credentials can provide an easier path into systems than exploiting complex technical vulnerabilities.
Moving toward passkeys, stronger authentication, device based security, and better user context can help reduce the opportunities available to attackers.
However, technology alone cannot eliminate account takeover risk.
Organizations need a combination of identity governance, endpoint security, continuous monitoring, security awareness, incident response, and compliance controls.
What Organizations Should Consider
Businesses using messaging applications for operational or customer communication should consider the following steps:
• Enable phishing resistant authentication where available
• Encourage employees to use passkeys on supported accounts
• Enforce strong multifactor authentication for business systems
• Regularly review connected and authorized devices
• Monitor unusual authentication activity
• Establish clear account compromise response procedures
• Train employees to identify social engineering attempts
• Protect executive and privileged accounts with additional controls
• Review third party applications connected to business accounts
• Align authentication controls with organizational compliance requirements
These measures can help reduce the likelihood that a compromised identity becomes a gateway into a larger business environment.
Conclusion
WhatsApp’s introduction of multiple passkeys and stronger two step verification highlights the continuing evolution of identity security.
As cybercriminals increasingly target people rather than only infrastructure, organizations must treat identity protection as a fundamental part of cybersecurity.
Passkeys, stronger authentication, device security, user awareness, continuous monitoring, and rapid incident response can work together to create a more resilient security environment.
For businesses, the lesson is clear: protecting the identity is just as important as protecting the network, application, or endpoint.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.
In addition, COE Security helps organizations strengthen identity and access security through authentication assessments, account security reviews, phishing resilience programs, identity risk assessments, security awareness training, endpoint security assessments, and incident response planning.
For financial services and banking organizations, we help strengthen authentication and account protection against fraud and identity based attacks.
For healthcare organizations, we help protect sensitive systems and information through identity security, access controls, monitoring, and compliance focused security programs.
For retail and e-commerce organizations, we help reduce account takeover, credential theft, social engineering, and customer data security risks.
For manufacturing and technology organizations, we help secure workforce identities, privileged access, cloud environments, applications, and connected systems.
For government organizations, we help strengthen identity security, access governance, threat monitoring, and cybersecurity resilience for sensitive environments.
Our approach combines cybersecurity services, security testing, monitoring, governance, compliance support, and employee awareness to help organizations build stronger defenses against evolving identity and access threats.
Follow COE Security on LinkedIn for ongoing insights into cybersecurity, AI security, compliance, identity protection, and emerging threats to stay updated and cyber safe.
Click to read our LinkedIn feature article