Home › Intelligence › Brief
BREACH BRIEF🟡 Medium ThreatIntel

WhatsApp Introduces Passkey Login and Stronger Two‑Step Verification for Over 1 B Users

WhatsApp now lets more than a billion users log in with FIDO‑compatible passkeys and replaces its six‑digit PIN with a complex alphanumeric password. The changes cut phishing and credential‑theft risk, a key focus for SOC 2 access‑control compliance.

LiveThreat™ Intelligence · 📅 August 29, 2026· 📰 malwarebytes.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

WhatsApp Introduces Passkey Login and Stronger Two‑Step Verification for Over 1 B Users

What Happened — WhatsApp announced that more than one billion users can now log in with FIDO‑compatible passkeys and that its two‑step verification has been upgraded from a six‑digit PIN to a longer alphanumeric password. The Android client also shows contextual information for calls from unknown numbers to help users spot scams.

Why It Matters for Compliance & Audit Readiness

  • Passkey authentication eliminates shared secrets, directly addressing SOC 2 CC6.1 (Logical Access) and reducing the likelihood of credential‑theft findings during an audit.
  • The stronger two‑step verification password satisfies the “password complexity” requirement of the SOC 2 security principle and provides concrete evidence for access‑control policies.
  • Caller‑context information helps demonstrate a documented anti‑phishing awareness control, useful when auditors review user‑training and incident‑response evidence.

Who Is Affected – Consumer‑messaging platforms, telecom operators, and any organization that relies on WhatsApp for business communications (e.g., support centers, sales teams).

Recommended Actions – Review your own account‑access policies, require password‑less or MFA solutions that meet FIDO standards, update two‑step verification settings to meet complexity guidelines, and log authentication events for continuous‑monitoring evidence. Source: Malwarebytes Labs

Technical Notes – Passkeys are stored in the device’s credential manager and unlocked via biometrics or screen‑lock; they are resistant to phishing because no secret is typed. The new two‑step verification password can include upper‑/lower‑case letters, numbers, and symbols, raising the brute‑force cost dramatically. Caller‑context pulls contact‑group and geographic data to flag potentially fraudulent calls. Source: same as above

📰 Original Source
https://www.malwarebytes.com/blog/mobile/2026/08/protect-your-whatsapp-account-with-new-passkey-and-2fa-upgrades ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →