If your business takes orders, books appointments, or answers customer questions over WhatsApp, an update Meta rolled out in late August is worth five minutes of your time. WhatsApp announced it is upgrading two-step verification from a six-digit PIN to a longer, alphanumeric password, and expanding passkey support so you can register more than one device with fingerprint, face ID, or screen-lock verification instead of a code. According to WhatsApp, more than a billion accounts already use a passkey to log in.
That sounds like routine app maintenance. For a lot of local businesses, it’s actually a chance to fix a soft spot that scammers have been actively exploiting.
Why your WhatsApp account is worth stealing
A personal WhatsApp account getting hijacked is annoying. A business account getting hijacked is a direct line to your customers’ money. Security researchers have documented small retailers losing thousands of dollars after a scammer impersonated a supplier over WhatsApp Business, and travel agency customers being tricked into wiring deposits to a cloned business account. TechCrunch reported that the update is a direct response to the growing volume of these takeover attempts.
The mechanics are almost always the same. A scammer calls or texts pretending to be WhatsApp support, a supplier, or even one of your own employees, and talks the target into forwarding a one-time verification code or approving a “linked device” request. Once they’re in, the account, your chat history, your contact list, and your reputation with every customer who has your number saved, belongs to them. Malwarebytes recently flagged an active scam campaign that uses a fake “vote for my friend” link to hijack the Linked Devices feature specifically, which is exactly the kind of social engineering that works better against a busy shop owner than a security professional.
What makes business accounts a softer target
Most owners set up WhatsApp Business once, hand the phone to whoever’s on shift, and never touch the security settings again. A few things make that risky:
- The number is public by design. It’s on your storefront, your Google listing, your receipts. Scammers don’t have to guess who to target.
- Trust is baked in. Customers who’ve ordered from you before will believe a message that “looks like” your business, especially if the scammer is using your actual profile photo and business name after a takeover.
- Multiple people often have access. Shared devices and shared logins mean more chances for a code to get forwarded to the wrong person.
- Recovery is slow. Once you’re locked out, getting a business account back can take days, during which customers may be messaging a scammer instead of you.
Four things to do this week
Turn on the new two-step verification. Go to Settings > Account > Two-step verification and replace the old six-digit PIN with the full password option now available. A longer, alphanumeric password is much harder to guess or brute-force than a six-digit number.
Add a passkey if your business phone supports it. Passkeys tie login to the physical device (fingerprint, face ID, or screen lock) rather than a code that can be intercepted or socially engineered out of an employee. If more than one person needs access, WhatsApp now lets you register multiple passkeys across devices instead of sharing one login.
Check Linked Devices weekly, not just when something feels wrong. Under Settings > Linked Devices, log out anything you don’t recognize. This is the single fastest way to catch an intrusion before it turns into a customer-facing scam.
Train whoever answers the phone. The failure point is almost never the software, it’s a staff member reading a six-digit code out loud to someone who called claiming to be “WhatsApp support” or a supplier confirming an order. Make it a standing rule: verification codes never leave the building, for any reason, to anyone who asks for one.
The bigger habit this points to
This isn’t really a story about one app update. It’s a reminder that the tools local businesses now depend on for day-to-day revenue, messaging apps, booking links, payment QR codes, carry the same account-takeover risk as a bank login, and most owners don’t treat them that way. The FTC’s small business scam guidance makes the same point about email and phishing: attackers go after the channel your customers already trust, not the one with the strongest lock. WhatsApp happens to be the one getting an upgrade this month; the same weak spots exist on Instagram DMs, Facebook Messenger, and any booking tool tied to a shared login.
Take the fifteen minutes this week to update your two-step verification, add a passkey, and walk your staff through the “never share a code” rule. It’s a small investment against a scam that has already cost other small business owners real money and real customer trust.