Big tech ditches SMS codes as passkeys go mainstream

Bleeping Computer

The gist

Big Tech is finally kicking SMS codes to the curb, rolling out phishing-proof passkeys and smarter verification to outsmart scammers for good.

What to know

  • By mid-2026, Microsoft and WhatsApp will phase out SMS and voice codes, replacing them with passkeys and verified emails to block phishing and SIM-swap attacks.
  • WhatsApp now supports complex alphanumeric passwords and multi-passkey logins across Android and iOS, ditching old six-digit PINs for over a billion users.
  • Signal debuted Automatic Key Verification with third-party auditors in August 2026, ending manual safety checks and launching new anti-phishing defenses against state hackers.

Microsoft’s Passkey Overhaul

Microsoft’s pivot to passkeys and verified emails marks the end of SMS authentication, tackling fraud at its root while giving administrators new controls for a seamless, secure transition.

By mid-2026, Microsoft announced a decisive move away from SMS-based authentication for personal accounts, citing the method as a leading source of fraud due to vulnerabilities like phishing and SIM-swapping. This transition, formalized in advisories on May 19 and 20, 2026, reflects a broader industry trend to phase out SMS codes across Windows and mobile platforms, marking a significant upgrade in platform-wide security.

In place of SMS and voice authentication, Microsoft introduced passkeys and verified secondary email addresses as the new default sign-in and recovery methods, starting September 2026. Passkeys, which are hardware-associated and can be stored on devices or accessed via Windows Hello biometrics, offer a phishing-resistant, passwordless experience that drastically reduces the threat surface by eliminating risks like SIM swaps and AI-powered phishing attacks.

Microsoft’s Entra ID platform will fully retire SMS and voice authentication by February 1, 2027, ending native telco-based delivery of these codes. The transition plan includes automatic user enrollment with an opt-out option for administrators until late 2026, and support for third-party telecom providers to maintain phone-based verification where necessary, underscoring a carefully managed shift balancing security improvements with operational continuity.

Sources

WhatsApp Reinvents Login Security

WhatsApp’s shift to alphanumeric passwords and multi-device passkeys not only strengthens defenses but also arms users with smarter anti-scam tools for safer communication.

In a significant overhaul of its authentication system, WhatsApp has replaced the longstanding six-digit PIN for two-step verification with a more robust alphanumeric password that includes letters, numbers, and special characters, enhancing protection against brute-force attacks. This shift marks a strategic move to strengthen account security by making passwords harder to guess and more resistant to compromise, reflecting the platform’s commitment to evolving beyond its 2017 PIN-based system.

WhatsApp’s introduction of multi-passkey support allows users to register multiple biometric passkeys across Android and iOS devices, leveraging device-native security features like Face ID and fingerprint recognition. With over one billion users already adopting passkeys, this move not only simplifies seamless login across devices without relying on passwords or SMS codes but also significantly reduces phishing risks by eliminating traditional authentication vulnerabilities.

Complementing its authentication upgrades, WhatsApp has enhanced its anti-scam capabilities by providing users on Android with richer caller context for unknown numbers, including the caller’s country and any shared WhatsApp groups. This proactive feature empowers users to better assess potential scam calls before answering, illustrating WhatsApp’s broader strategy to prevent social engineering attacks by equipping users with more information upfront.

The timing of these comprehensive security updates underscores WhatsApp’s strategic pivot towards not only fortifying account access but also proactively combating scams and account hijacks. By combining stronger passwords, biometric passkeys, and enhanced caller information, WhatsApp aims to create a layered defense that protects users before they even engage with suspicious messages or calls, signaling a new era of user-centric security on the platform.

Sources

Signal Automates Encryption Trust

Signal’s Automatic Key Verification, backed by independent auditors and new anti-phishing measures, removes manual checks and fortifies chats against even the most advanced state-level threats.

In August 2026, Signal revolutionized its defense against man-in-the-middle attacks by launching Automatic Key Verification, a groundbreaking feature that leverages third-party auditors such as Cloudflare and Trail of Bits to decentralize encryption key verification. This innovation eliminates the cumbersome need for manual safety number checks or in-person meetings, offering users seamless security transparency and flexibility while ensuring that encrypted chats remain impervious to interception. Complementing this technical leap, Signal also introduced targeted phishing warnings aimed at state-sponsored hackers and partnered with U.S. government-backed bounty programs to proactively identify and neutralize attackers, underscoring its commitment to safeguarding users against increasingly sophisticated threats.

Sources
Bleeping Computer

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.