Home › Intelligence › Brief
BREACH BRIEF⚪ Informational Advisory

Meta Adds Alphanumeric Two‑Step Verification, Call Context, and Multi‑Passkey Support to WhatsApp

Meta upgraded WhatsApp with an alphanumeric two‑step verification password, on‑Android call‑origin context for unknown numbers, and the ability to register multiple biometric passkeys. These changes directly support SOC 2 access‑control requirements and give enterprises stronger audit evidence.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 helpnetsecurity.com
⚪
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Meta Introduces Stronger Two‑Step Verification, Call Context, and Multi‑Passkey Support for WhatsApp

What Happened — Meta rolled out three account‑security upgrades to WhatsApp: an alphanumeric two‑step verification password, on‑Android call‑origin context for unknown numbers, and the ability to register multiple biometric passkeys per account.

Why It Matters for Compliance & Audit Readiness

  • The longer, alphanumeric two‑step verification aligns with SOC 2 CC6.1 (Multi‑Factor Authentication) and provides concrete evidence of strong access‑control enforcement.
  • Call‑origin context helps users identify social‑engineering attempts, supporting the SOC 2 CC6.2 (Security Awareness) requirement to mitigate phishing and BEC risks.
  • Multi‑passkey support expands credential diversity, giving organizations a defensible audit trail for credential lifecycle management.

Who Is Affected – Consumer messaging users worldwide; enterprises that rely on WhatsApp for business communications (e.g., sales, support, remote teams).

Recommended Actions – Review your organization’s access‑control policies to ensure MFA requirements match or exceed the new alphanumeric standard; incorporate call‑origin context into security‑awareness training; document passkey provisioning and revocation processes as audit evidence. Source: Help Net Security

Technical Notes – The two‑step verification password now accepts up to 128 characters, including special symbols; call‑origin context is displayed only on Android devices and pulls metadata from the caller’s registered country and shared groups; passkey registration leverages platform‑specific biometric APIs (Apple Face ID, Android Fingerprint, etc.). Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/26/meta-whatsapp-security-enhancements/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →