WhatsApp is tightening account-security controls with a set of updates focused on login protection and scam resistance. TechCrunch reports that the Meta-owned messaging app announced the changes Tuesday, while BleepingComputer says the company has started rolling them out. The most direct change is to two-step verification. Until now, both outlets report, WhatsApp’s extra account-protection layer relied on a six-digit PIN. Users can now choose a longer password that supports letters, numbers, and special characters, making the credential harder to guess than a simple numeric code. The second change is support for more than one passkey on a single WhatsApp account. TechCrunch reports that WhatsApp says this should help people who use both iOS and Android, while BleepingComputer says users can create separate passkeys for each platform. BleepingComputer also reports that WhatsApp said more than a billion people have already set up a passkey. Passkeys are meant to reduce reliance on traditional password logins. TechCrunch notes that WhatsApp launched passkey support in 2024 and describes the mechanism as using device-based authentication such as Face ID or a fingerprint. Because the user’s part of the passkey is stored on a device, TechCrunch reports, remote account access becomes harder for an attacker without physical access to that device. WhatsApp is also adding more context to calls from unknown numbers on Android. Both TechCrunch and BleepingComputer report that users will see information such as whether the number appears to be from another country and whether the caller shares any groups with them. BleepingComputer frames the feature as an added layer against scams, giving users more information before they answer. The updates fit into a broader year of anti-abuse and account-protection features for WhatsApp. BleepingComputer reports that WhatsApp began rolling out “Strict Account Settings” in January for high-risk users such as journalists and public figures, and that Meta announced in March that WhatsApp would warn users when a device-linking request may be fraudulent. BleepingComputer also says WhatsApp introduced an optional “Scam Alert” feature in a limited beta rollout earlier this month, using a local machine-learning model to warn users about possible scams. The practical direction is clear: WhatsApp is trying to move more account protection onto stronger credentials and more contextual warnings, rather than relying only on user judgment at the moment of attack. For a messaging app used for personal, business, and cross-border communication, account takeover and social-engineering defenses are now core product work, not optional security settings. Who benefits: WhatsApp users who have higher takeover risk, use both Android and iOS, or receive calls from unknown numbers get more tools to verify access and assess suspicious outreach. Meta also benefits if stronger defaults and optional protections reduce account-abuse incidents across WhatsApp. Who's exposed: Attackers who rely on guessed PINs, stolen one-time codes, malicious device-linking prompts, or urgent calls from unknown numbers face more friction. Users who keep weak settings or ignore the new controls remain exposed to social-engineering attempts.