HomeIntelligenceBrief
BREACH BRIEF⚪ Informational Advisory

WhatsApp Adds Multi‑Passkey Support for Phishing‑Resistant Sign‑Ins on iOS and Android

Meta announced WhatsApp now supports multiple passkeys per account, letting users on iOS and Android log in with phishing‑resistant authentication. For compliance teams, the move underscores the need to align access‑control policies with modern credential standards.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 thehackernews.com
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
thehackernews.com

WhatsApp Adds Multi‑Passkey Support for Phishing‑Resistant Sign‑Ins on iOS and Android

What Happened — Meta announced that WhatsApp now supports multiple passkeys per account, allowing users on both iOS and Android to authenticate with phishing‑resistant, FIDO2‑based credentials. The change expands on the October 2023 Android rollout and is already used by more than 1 billion passkey‑enabled accounts.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Logical Access) requires strong, MFA‑level authentication; passkeys provide a verifiable, password‑less control that auditors can evidence.
  • Continuous‑compliance programs must capture credential‑management events; multi‑passkey enrollment creates a clear audit trail for each device.
  • Security awareness training can now reference a concrete, phishing‑resistant login method, reducing reliance on risky password practices.

Who Is Affected — Consumer messaging services, enterprises that use WhatsApp Business for customer support, and any organization that integrates WhatsApp APIs for communications.

Recommended Actions

  • Update your access‑control policy to require passkey or equivalent MFA for all privileged WhatsApp Business accounts.
  • Capture passkey enrollment logs as part of your SOC 2 evidence collection (e.g., via continuous‑control monitoring).
  • Incorporate passkey usage into security‑awareness curricula to reinforce phishing‑resistant practices.

Source: The Hacker News

Technical Notes — Passkeys are built on the FIDO2/WebAuthn standards, stored in device‑specific secure enclaves (Secure Enclave on iOS, Titan M on Android). They eliminate password transmission and are resistant to phishing, man‑in‑the‑middle, and credential‑stuffing attacks. Source: same as above

📰 Original Source
https://thehackernews.com/2026/08/whatsapp-adds-multiple-passkeys-for.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →