Meta Introduces Stronger Two‑Step Verification, Call Context, and Multi‑Passkey Support for WhatsApp
What Happened — Meta rolled out three account‑security upgrades to WhatsApp: an alphanumeric two‑step verification password, on‑Android call‑origin context for unknown numbers, and the ability to register multiple biometric passkeys per account.
Why It Matters for Compliance & Audit Readiness
- The longer, alphanumeric two‑step verification aligns with SOC 2 CC6.1 (Multi‑Factor Authentication) and provides concrete evidence of strong access‑control enforcement.
- Call‑origin context helps users identify social‑engineering attempts, supporting the SOC 2 CC6.2 (Security Awareness) requirement to mitigate phishing and BEC risks.
- Multi‑passkey support expands credential diversity, giving organizations a defensible audit trail for credential lifecycle management.
Who Is Affected – Consumer messaging users worldwide; enterprises that rely on WhatsApp for business communications (e.g., sales, support, remote teams).
Recommended Actions – Review your organization’s access‑control policies to ensure MFA requirements match or exceed the new alphanumeric standard; incorporate call‑origin context into security‑awareness training; document passkey provisioning and revocation processes as audit evidence. Source: Help Net Security
Technical Notes – The two‑step verification password now accepts up to 128 characters, including special symbols; call‑origin context is displayed only on Android devices and pulls metadata from the caller’s registered country and shared groups; passkey registration leverages platform‑specific biometric APIs (Apple Face ID, Android Fingerprint, etc.). Source: Help Net Security