WhatsApp has strengthened the protection surrounding its accounts at a time when messaging is becoming part of the operational infrastructure of many businesses.

On August 25, 2026, the company announced stronger two-step verification, support for multiple passkeys and additional information about calls from unknown numbers. The changes are relevant beyond personal privacy. Companies increasingly use WhatsApp for customer service, sales inquiries, appointment management, supplier coordination and payment-related communication.

When one of these accounts is compromised, the attacker may inherit something particularly valuable: the trust that customers and colleagues already place in the company’s identity.

What WhatsApp changed

The first change concerns two-step verification.

WhatsApp previously protected this layer with a six-digit PIN. According to the company’s official announcement, users can now use a longer password containing letters, numbers and special characters.

Two-step verification is designed to make an account harder to take over even when someone obtains its one-time registration code. A stronger credential increases the number of possible combinations and makes a simple or easily guessed code less effective as an attack route.

The second development is expanded passkey support. Users can now add more than one passkey to an account, which is useful when an account is accessed through devices running different operating systems.

A passkey uses the device’s security mechanism—such as a fingerprint, facial recognition or screen-lock code—to confirm the user’s identity. WhatsApp says more than one billion people have already configured one.

The FIDO Alliance, which develops authentication standards, describes passkeys as resistant to phishing because they use public-key cryptography rather than a reusable secret that can be entered into an imitation login page.

The third change provides Android users with additional context before answering calls from numbers outside their contacts. The screen may show whether the number comes from another country and whether the caller shares any WhatsApp groups with the recipient.

This information does not prove that a caller is legitimate or fraudulent. It gives the recipient more context before responding to an unfamiliar approach.

Why this matters commercially

For many small and medium-sized companies, WhatsApp is no longer simply a chat application.

It may contain ongoing sales conversations, customer names, order information, supplier contacts and records of operational decisions. Customers may also treat a message from the company’s familiar number as an authenticated business instruction.

That creates several forms of commercial risk.

An attacker controlling the account could impersonate an employee, redirect a payment, request confidential information or send fraudulent offers to existing customers. Even when the direct financial loss is limited, the incident can damage customer confidence and require significant time to investigate.

The new protections therefore matter because they defend the identity attached to the communication—not only the content of individual messages.

End-to-end encryption remains important, but it addresses a different problem. It helps prevent unauthorized parties from reading a conversation while it travels between legitimate participants. It cannot protect a company when the attacker has gained control of an authorized account or device.

What the update does not solve

Stronger authentication reduces risk; it does not remove it.

An employee can still be manipulated into disclosing information, approving an unfamiliar device or following a fraudulent payment instruction. A passkey also cannot prevent misuse by someone who already has access to an unlocked authorized device.

Unknown-caller context must be interpreted carefully. A domestic number or a shared group does not establish trustworthiness. Conversely, an international number may be legitimate for a company serving customers or suppliers in other countries.

Businesses should treat these indicators as decision-support information—not as automated proof of identity.

Recovery procedures are another important consideration. A company should know which email addresses, devices and employees are connected to an account before a phone is lost, an employee leaves or access is unexpectedly interrupted.

A practical security response for businesses

The update provides a useful opportunity to audit every WhatsApp account used professionally.

1. Identify business-controlled accounts

Create an internal list of the numbers used for sales, support, administration and marketing. Record who owns each number, which devices can access it and who is responsible for recovery.

A business account should not depend entirely on undocumented access held by one employee.

2. Strengthen authentication

Enable the strongest available two-step-verification option and avoid credentials already used for email, social media or other company systems.

Configure a passkey where it is available and appropriate. WhatsApp’s passkey instructions place this option under Settings, Account and Passkeys.

The company should also review the device security protecting that passkey. A passkey attached to a poorly protected or widely shared phone inherits the operational weakness of that device.

3. Review connected devices regularly

Remove devices that are no longer required and investigate sessions that employees do not recognize.

This review should also form part of the company’s offboarding procedure whenever an employee, contractor or agency stops managing the account.

4. Separate communication from authorization

A WhatsApp conversation should not be sufficient authorization for a sensitive transaction.

Requests involving payments, bank details, passwords, customer-data exports or account changes should be verified through a second approved channel. For example, an employee could confirm the request through a known telephone number or an internal approval system.

5. Train employees to resist urgency

Fraudulent messages and calls often attempt to create pressure: an invoice must be paid immediately, a code is supposedly needed to restore service or a manager claims to be unavailable by any other channel.

Employees should be explicitly authorized to pause, verify and escalate unusual requests without being penalized for slowing the process.

Customer experience and privacy considerations

Security controls should protect customers without making legitimate communication unnecessarily difficult.

Businesses can publish their official WhatsApp number on their website and verified social profiles so customers have a reference point. They can also state that employees will never request passwords, one-time codes or full payment credentials through messaging.

Access should be limited according to operational need. A staff member responding to appointments may not require access to conversations involving payments or sensitive customer records.

Companies should also decide how long conversations are retained, which information may be shared through WhatsApp and when a customer should be moved to a more appropriate system such as a CRM, secure portal or formal support platform.

Messaging convenience should not become an excuse for storing sensitive information without structure or control.

Security must follow the business process

WhatsApp’s new protections are useful improvements. Stronger credentials make guessing more difficult, multiple passkeys support modern device access and caller context can help people pause before answering an unfamiliar call.

Their commercial value, however, depends on how the business manages the account around them.

The strongest approach combines technical protection with documented ownership, controlled device access, employee awareness and independent verification of sensitive instructions.

From the Kozhaya Sakr Digital perspective, technology and marketing should always serve a defined business objective. For business messaging, that objective includes protecting the trust that makes customer communication valuable in the first place.

Sources