WhatsApp adds call context and alphanumeric passwords to fight impersonation
The messaging giant is rolling out Android-specific call details and stronger verification to curb social engineering scams.
WhatsApp is introducing new security layers designed to protect users from fraud and impersonation during voice and video calls. The updates focus on providing more transparency regarding unknown callers and hardening account access through stronger verification methods.
For Android users, the platform is deploying a "call context" feature. When a call arrives from a number not saved in the user's contact list, WhatsApp will now display the caller's country of origin and any shared groups. This information is intended to help users identify potential social engineering attacks by providing immediate clues about the nature of the incoming call before they answer.
Hardening Account Access
Beyond call transparency, WhatsApp is overhauling its account security. The company is replacing the traditional six-digit two-step verification (2SV) PIN with a full alphanumeric password, significantly increasing the complexity required to breach an account.
Additionally, the platform now supports multiple passkeys per account. This allows users to register a separate, device-specific passkey for every piece of hardware they use, reducing reliance on single-point-of-failure credentials and streamlining the secure login process across multiple devices.
The Rise of Social Engineering
These updates arrive as WhatsApp faces mounting pressure to combat sophisticated phishing and scamming operations. Bad actors have increasingly used voice calls to deceive users into transferring funds or revealing sensitive personal information.
The threat landscape has been further complicated by the rise of AI-driven voice cloning, which allows scammers to mimic the voices of trusted individuals with high precision. By adding concrete context to calls and strengthening the verification wall, WhatsApp aims to reduce the success rate of these impersonation scams.
Industry Implications
This shift reflects a broader trend in communication security where identity verification is moving away from simple codes toward contextual and biometric-backed authentication. For the industry, it signals that basic encryption is no longer sufficient; platforms must now actively mitigate the human element of security—the vulnerability to deception.
What to Watch
While the call context feature is currently limited to Android, users on other platforms will likely be watching for a similar rollout to iOS. It remains to be seen how quickly these features will be adopted by the general user base and whether the move to alphanumeric passwords will significantly decrease the volume of account takeover reports.