Full Report
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
Analysis Summary
# Industry News: WhatsApp Scales Phishing Resistance with Multi-Device Passkeys
## Summary
Meta has announced a significant expansion of WhatsApp’s security framework, introducing support for multiple passkeys to a single account to streamline secure logins across iOS and Android ecosystems. The update also replaces traditional six-digit PINs with complex alphanumeric passwords for two-step verification and introduces enhanced caller context to mitigate social engineering attacks.
## Key Details
- **Date:** August 25, 2026
- **Companies Involved:** Meta (WhatsApp)
- **Category:** Product Update / Cybersecurity Infrastructure
## The Story
Building on its 2023 rollout of passkeys for Android, Meta is now enabling "cross-platform" passkey flexibility for WhatsApp's user base of over 2 billion people. The core of this update allows a single account to host multiple passkeys, solving a major friction point for users who operate across different device ecosystems (e.g., using an iPad and an Android phone).
In a push to move away from legacy authentication, WhatsApp is also evolving its "Two-Step Verification." Previously limited to a six-digit PIN—often criticized for its vulnerability to brute-forcing or simple guessing—users can now opt for full alphanumeric passwords including special characters. Finally, the platform is addressing the rise in "Wangiri" and WhatsApp-based phishing calls by providing Android users with enhanced metadata on unknown callers, including geographic origin and shared group associations.
## Business Impact
### For the Companies Involved
- **Meta:** By integrating passkeys across its suite (WhatsApp, Facebook, Instagram), Meta reduces the high costs associated with SMS-based OTP (One-Time Password) delivery and account recovery support.
### For Competitors
- **Signal and Telegram:** These platforms are now under increased pressure to match Meta’s phishing-resistant hardware-backed authentication to maintain their "secure messenger" branding.
### For Customers
- **End Users:** Users gain a "best of both worlds" experience: the convenience of biometric login (FaceID/Fingerprint) combined with the superior security of FIDO2 standards, reducing the risk of account takeovers via SIM swapping.
### For the Market
- **Standardization:** This move accelerates the global "passwordless" transition. With over 1 billion WhatsApp users already utilizing passkeys, Meta is effectively forcing passkey adoption into the mainstream consciousness.
## Technical Implications
The shift to multiple passkeys per account implies a more robust implementation of the WebAuthn/FIDO2 standard, allowing for credential syncing across different keychains (e.g., iCloud Keychain and Google Password Manager) or the use of physical security keys as backups.
## Strategic Analysis
- **Market Positioning:** Meta is positioning WhatsApp not just as a messenger, but as a secure identity hub.
- **Competitive Advantage:** Phishing resistance is a major differentiator; by making "un-phishable" credentials the default, WhatsApp reduces the platform's utility for large-scale botnet operators.
- **Challenges:** The transition from a 6-digit PIN to alphanumeric passwords may cause user friction, and educating a global, non-technical user base on "Passkeys" remains a significant UX hurdle.
## Industry Reactions
- **Analyst Opinions:** Analysts view this as a necessary evolution to combat the industrialization of social engineering.
- **Market Response:** The move is seen as a validation of the FIDO Alliance’s mission, signaling the beginning of the end for SMS-based 2FA in the social media sector.
## Future Outlook
- **Predictions:** Expect Meta to eventually deprecate SMS-based verification entirely in favor of passkey-first onboarding.
- **Watch For:** Integration of these features into WhatsApp Business to protect enterprise-customer interactions from spoofing.
## For Security Professionals
Practitioners should note the shift toward **phishing-resistant MFA** at scale. The move from 6-digit PINs to alphanumeric passwords for 2FA is a clear signal that legacy MFA is no longer sufficient against modern adversary-in-the-middle (AiTM) attacks. Organizations should use this as a case study for transitioning their own workforce to FIDO2-backed credentials.