Cyber Security News

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into the messaging app, marking one of the largest passwordless authentication rollouts in consumer tech history.

Alongside this milestone, Meta’s flagship messaging platform is rolling out a major upgrade to two-step verification, replacing the long-standing six-digit PIN with a full alphanumeric password, and adding new caller-context features designed to help users spot scams before they even pick up the phone.

WhatsApp Passkeys Reach 1 Billion Users

Passkeys let WhatsApp users authenticate using their device’s fingerprint sensor, Face ID, or screen lock code instead of typing in a numeric code or PIN.

Since the feature relies on cryptographic keys tied to the device rather than a shared secret transmitted over a network, it is inherently more resistant to phishing, credential stuffing, and SIM-swap-style takeover attempts than legacy verification codes.

WhatsApp says the technology has now crossed the 1 billion user mark, and the company is expanding support so that people who split their usage between an Android phone and an iPhone can register multiple passkeys on a single account.

The feature is accessible under Settings> Account> Passkeys, where users can add a new key or review existing ones tied to their device’s password manager.

The more consequential change targets two-step verification, the secondary layer of protection that has traditionally required a six-digit PIN even after a one-time SMS passcode has been entered.

WhatsApp is now letting users replace that PIN with a genuine password: longer, alphanumeric, and capable of including special characters, which meaningfully raises the difficulty of brute-force and credential-guessing attacks.

According to WhatsApp’s own security requirements outlined in the WhatsApp security announcement, a new password must be at least 8 characters long and include at least one letter and one number, with the option to strengthen it further by including symbols.

This matters because six-digit PINs, while better than nothing, offer a comparatively small keyspace and are frequently reused across services or set to easily guessable sequences like “123456.”

Security researchers have long flagged short numeric codes as a weak link in account-recovery and secondary-authentication flows, since automated guessing or social-engineering attacks can bypass them faster than a properly constructed password.

WhatsApp’s own messaging around the rollout explicitly nods to this risk, noting that anyone still relying on a simple numeric PIN should treat the update as a prompt to upgrade.

Independent reporting indicates the account password feature was first spotted in Android beta builds as early as July 2026, developed under the codename “dedicated account password system,” before receiving confirmation of a wider rollout this week.

Security FeaturePrevious ImplementationUpgraded Standard
Primary Login MethodSMS Verification CodesBiometric & Device-Bound Passkeys
Two-Step Verification6-Digit Numeric PINAlphanumeric Password (8+ Characters)
Cross-Platform SupportSingle Ecosystem KeyMulti-Device Key Registration
Inbound Call SecurityUnverified Caller DisplayContextual Indicators (Country & Shared Groups)

WhatsApp is also rolling out a lower-profile but practical anti-fraud measure for Android users, expanding ongoing efforts to improve messaging anti-scam tools.

When a call arrives from a number not saved as a contact, the incoming call screen now surfaces additional context, including whether the number is from a different country and whether the caller shares any groups with the recipient.

Since many scam and vishing operations rely on urgency and unfamiliarity to pressure victims into answering or acting quickly, this added friction gives users a moment to evaluate legitimacy before engaging.

Account takeover remains one of the most common entry points for messaging-platform abuse, from SIM-swap fraud to social-engineering scams that hijack a victim’s contact list.

By combining passwordless authentication at scale, a stronger secondary password requirement, and contextual caller information, WhatsApp is tightening multiple layers of its security stack simultaneously rather than relying on any single control.

Users who have not yet enabled two-step verification or are still using a legacy PIN should treat this rollout as a timely reminder to review their account security settings.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

10 minutes ago

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…

13 minutes ago

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…

13 minutes ago

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…

17 minutes ago

Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…

23 minutes ago

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is…

1 hour ago