WhatsApp Hardens Its Defenses as a New Sotheby’s Data Breach Shows Why Account Security Matters More Than Ever + Video

Listen to this Post

Featured Image

A New Security Era Is Taking Shape

Cybersecurity is increasingly becoming a battle fought through everyday applications, trusted accounts, and seemingly ordinary interactions. A messaging app can become a target for account takeover, while a customer relationship management platform can expose personal information without attackers ever touching the most sensitive financial records.

That reality is behind two important cybersecurity developments reported on August 25, 2026. WhatsApp is rolling out a significant set of account-security improvements, including multiple passkeys, stronger two-step verification, and additional information about calls from unknown numbers. At the same time, New Zealand Sotheby’s International Realty is investigating unauthorized access to data stored on a third-party platform.

Together, these stories reveal an important trend: modern security is no longer just about building a stronger wall around a network. It is about protecting identities, reducing the value of stolen credentials, understanding third-party risk, and giving ordinary users enough information to make safer decisions.

WhatsApp Strengthens Account Protection

WhatsApp has announced several new security features designed to make account takeovers harder and suspicious communications easier to identify.

The most significant change is support for multiple passkeys. WhatsApp says more than 1 billion people have already configured a passkey, and users can now add more than one passkey to an account, particularly useful for people who move between Android and iOS devices.

This is an important evolution because passkeys eliminate much of the traditional password problem. Instead of remembering a password or depending on a temporary verification code, users can authenticate through mechanisms already protected by their device, such as a fingerprint, Face ID, or screen-lock credential.

Multiple Passkeys Could Make Recovery Easier

Allowing more than one passkey is more than a convenience feature.

Many people own several devices. A user might have an iPhone as a primary phone, an Android tablet, and another device used for work. A single authentication method can become inconvenient when people change platforms.

Multiple passkeys give users greater flexibility while maintaining a phishing-resistant authentication model.

WhatsApp specifically says users can add multiple passkeys when using both Android and iOS, with the option available under Settings > Account > Passkeys.

The broader security lesson is straightforward: authentication becomes stronger when users do not have to choose between security and convenience.

Passkeys Are Changing the Authentication Battle

Traditional passwords remain one of the weakest links in cybersecurity because they can be guessed, reused, stolen, phished, or exposed through breaches.

Passkeys approach the problem differently.

Rather than asking users to transmit a reusable secret, passkey systems rely on cryptographic credentials associated with the user’s device and protected by local authentication.

This does not make every account attack-proof, but it removes an enormous number of opportunities for attackers.

A criminal can send a convincing phishing page asking for a password. It is much harder to trick someone into remotely providing the cryptographic credential protected by their device.

WhatsApp Replaces the Six-Digit Security PIN

WhatsApp is also strengthening its two-step verification system.

Previously,

This matters because a short numerical PIN has a comparatively small search space.

A longer password dramatically increases the number of possible combinations, especially when users create genuinely unique credentials.

The change is particularly important in scenarios where an attacker has already obtained a user’s one-time login code. WhatsApp describes two-step verification as an additional barrier designed to prevent account takeover even if that one-time code has been compromised.

Security Gets Stronger When the User Gets More Control

One of the most interesting aspects of this update is that WhatsApp is not relying on a single security mechanism.

Instead, the platform is combining multiple layers:

Passkeys protect authentication.

Two-step verification adds another barrier.

Caller context helps users identify suspicious communications.

End-to-end encryption protects personal conversations and calls.

Each layer addresses a different part of the attack surface.

That layered approach is exactly what modern security architecture should look like.

Unknown Callers Will Come With More Context

WhatsApp is also changing how Android users see calls from people who are not in their contacts.

The updated interface can provide additional context, including whether the caller’s number is associated with another country and whether the caller shares groups with the recipient.

At first glance, this may look like a relatively small user-interface improvement.

It is actually a cybersecurity feature.

Why Caller Context Matters

Social engineering attacks often depend on urgency.

An attacker does not necessarily need to break encryption or exploit a software vulnerability. Sometimes all they need is for the victim to answer a call and believe the person on the other end.

A caller from an unfamiliar international number may deserve additional caution.

A caller who suddenly appears in a shared WhatsApp group may deserve a different level of attention.

Giving users more context before they answer creates a small but valuable pause between the arrival of the call and the decision to engage.

That pause can be enough to prevent a successful social-engineering attempt.

The Human Firewall Is Still Important

Technology cannot eliminate human risk.

Attackers continue to exploit curiosity, fear, urgency, authority, and trust.

WhatsApp’s caller-context feature recognizes this reality. Instead of pretending users will never encounter suspicious calls, the platform is giving them more information to make better decisions.

This is an increasingly important cybersecurity philosophy.

The strongest security system is not necessarily the one with the most complicated technology. It is the one that makes secure behavior easier for ordinary people.

A Second Incident Highlights Third-Party Risk

While WhatsApp is strengthening account security, another cybersecurity story involving New Zealand Sotheby’s International Realty demonstrates a completely different problem.

New Zealand

According to reporting from 1News, the affected platform was a customer relationship management system containing contact information used for marketing and operational purposes. Potentially exposed information includes names, addresses, phone numbers, and email addresses.

Sensitive Does Not Always Mean Financial

Sotheby’s stated that email exchanges, property documentation, and other substantive property-related material were not accessed.

The company also said the platform was not used to store information associated with customer financial transactions.

That distinction matters.

A data breach does not have to expose credit-card numbers or bank accounts to create meaningful risk.

Names, phone numbers, email addresses, and physical addresses can become valuable ingredients for phishing, impersonation, fraud, targeted social engineering, and identity-based attacks.

Personal information can become dangerous when combined with information from other databases.

The Third-Party Platform Problem

The

A business may have strong internal security controls while still depending on:

CRM providers.

Cloud hosting platforms.

Email services.

Marketing systems.

Analytics platforms.

Payment processors.

Customer support systems.

Identity providers.

Every external connection creates another potential path into sensitive information.

This is why third-party risk management has become a central part of cybersecurity strategy.

The 1.6 Million Contact Figure Needs Context

The incident has also generated discussion around a reported figure of approximately 1.6 million contacts.

However,

This is an important reminder that breach reporting can become confusing very quickly.

A number circulating online does not automatically represent the number of unique affected individuals.

Security teams need to distinguish between database records, duplicate records, unique people, affected accounts, and confirmed accessed information.

That distinction becomes particularly important when communicating with customers and regulators.

Investigation Is Still Underway

Sotheby’s says it took immediate steps to contain the incident and brought in independent cybersecurity specialists to investigate.

The company also notified New

The forensic investigation remains ongoing.

That means the final understanding of exactly what was accessed may change as investigators examine logs, authentication records, database activity, and third-party platform evidence.

Why These Two Stories Belong Together

At first, WhatsApp’s security update and the Sotheby’s incident appear unrelated.

One is about a messaging platform.

The other concerns a real-estate

But both stories point toward the same cybersecurity principle: identity and data protection must extend beyond the traditional network perimeter.

WhatsApp is attempting to protect the identity of the person logging into an account.

Sotheby’s is dealing with the consequences of unauthorized access to information held by an external platform.

One story focuses on preventing unauthorized access.

The other demonstrates what can happen when unauthorized access occurs.

Cybersecurity Is Becoming an Identity Problem

The security industry has spent decades thinking about firewalls, antivirus software, intrusion detection, and network segmentation.

Those technologies remain important.

But attackers increasingly target identities rather than machines.

They steal credentials.

They manipulate employees.

They exploit password reuse.

They compromise accounts.

They abuse legitimate cloud services.

They target third-party platforms.

This is why passkeys, strong authentication, access controls, and identity monitoring are becoming increasingly important.

What Users Should Do Right Now

WhatsApp users should check whether passkeys are available on their accounts and consider enabling them.

Users who still rely on weak two-step verification credentials should replace predictable PINs or passwords with strong, unique credentials when the new system becomes available to them.

People should also be cautious when receiving unexpected calls, particularly when the caller is unknown or the number appears unusual.

Security warnings should never be treated as background noise.

A suspicious call can be the first step in a much larger social-engineering campaign.

What Businesses Should Learn From the

Organizations should not treat third-party software providers as invisible extensions of their internal infrastructure.

Every external platform should be treated as part of the organization’s effective attack surface.

Security teams should understand what information is stored there, who can access it, how authentication is enforced, how logs are retained, and what happens if the vendor itself is compromised.

The most important question is not simply, “Is our company secure?”

It is also, “Is every company that holds our data secure enough?”

What Undercode Say:

The Authentication Layer Is Moving Forward

WhatsApp’s passkey expansion is part of a much larger migration away from password-centric authentication.

Passwords are fundamentally difficult for humans to manage securely.

Users reuse them.

Users choose predictable passwords.

Users enter them into fake websites.

Users accidentally expose them.

Passkeys attack the problem at its foundation.

They reduce the number of reusable secrets that attackers can steal.

They also make phishing considerably more difficult.

The Real Advantage Is Phishing Resistance

The strongest argument for passkeys is not convenience.

It is resistance to credential theft.

A traditional phishing campaign can convince a victim to type a password into a malicious page.

A properly implemented passkey cannot simply be copied and pasted into an attacker’s website.

That changes the economics of account takeover.

Multiple Devices Create a Practical Security Challenge

Security systems fail when they become too inconvenient.

If users have multiple devices, forcing them to maintain a single authentication path can create unnecessary friction.

Multiple passkeys address this problem.

A user can maintain separate authentication credentials for different devices without abandoning the security advantages of passkey-based authentication.

Stronger 2FA Is Still Valuable

Passkeys should not mean that secondary authentication becomes irrelevant.

Security architecture benefits from defense in depth.

If one layer fails, another should remain standing.

A stronger two-step verification password gives WhatsApp another barrier against account takeover.

Caller Context Attacks Social Engineering

The unknown-caller feature is particularly interesting because it targets psychology rather than software.

Attackers often need victims to participate.

They need a response.

They need trust.

They need urgency.

Caller context introduces friction before that interaction begins.

Small Friction Can Create Big Security Gains

A few seconds of hesitation can stop a scam.

A country indicator can reveal an unexpected international call.

A shared-group indicator can provide useful context.

Neither feature is revolutionary by itself.

Together, they can improve the

Third-Party Risk Is the Other Side of the Story

The Sotheby’s incident demonstrates that security cannot stop at an organization’s own servers.

The moment sensitive information enters an external CRM system, the vendor becomes part of the security equation.

This is increasingly true for almost every modern company.

Data Minimization Matters

Organizations should ask why a third-party platform needs particular information in the first place.

If information does not need to be stored, it does not need to be protected there.

Reducing unnecessary data is one of the simplest ways to reduce breach impact.

Duplicate Records Can Distort Breach Numbers

The dispute over the reported 1.6 million contacts also demonstrates why raw database numbers can be misleading.

One person may appear multiple times.

One contact may exist in multiple records.

A database row is not necessarily a unique victim.

Security reporting needs precision.

Incident Response Must Be Fast

Sotheby’s says it acted quickly to contain the incident.

That is critical.

The longer unauthorized access continues, the greater the opportunity for attackers to move through connected systems or extract additional information.

Logging Becomes Critical

Organizations cannot investigate what they cannot see.

Authentication logs.

API logs.

Database access records.

Administrative activity.

Cloud audit trails.

These records can become essential evidence during a forensic investigation.

Vendor Security Must Be Tested

A security questionnaire alone is not enough.

Organizations should evaluate vendor authentication controls, encryption, incident response procedures, access management, vulnerability management, and logging capabilities.

Zero Trust Is Becoming Practical Reality

The traditional idea of a trusted corporate perimeter is fading.

Users connect from everywhere.

Applications run in clouds.

Data moves between providers.

Employees use multiple devices.

Third parties process sensitive information.

Zero-trust principles are therefore becoming increasingly practical.

Identity Is the New Perimeter

The modern perimeter is increasingly defined by identity.

Who are you?

What device are you using?

What are you authorized to access?

What behavior is normal?

What changed?

Those questions are becoming more important than the physical location of the user.

Security Must Be Designed Around Real People

A complicated security system that nobody uses correctly is not necessarily secure.

WhatsApp’s approach is interesting because it combines stronger cryptography with simpler user decisions.

The best security controls often operate quietly in the background.

Attackers Will Adapt

Every successful defensive improvement eventually changes attacker behavior.

As passkeys become widespread, criminals will increasingly focus on device compromise, social engineering, recovery processes, malicious applications, and session theft.

Security is therefore a continuous process rather than a final destination.

Recovery Accounts Deserve Attention

Account recovery remains one of the most overlooked parts of authentication.

A strong login mechanism can still be undermined by a weak recovery process.

Organizations should therefore protect recovery channels as carefully as primary authentication.

The Biggest Risk May Be Outside the Organization

The

A company can secure its own infrastructure while still being exposed through a supplier.

That means cybersecurity teams need visibility across the entire digital supply chain.

Security Teams Need Better Asset Maps

Organizations should maintain accurate inventories of:

Customer data.

Third-party applications.

API integrations.

Privileged accounts.

Cloud environments.

Authentication providers.

Critical vendors.

Without this visibility, risk assessments become incomplete.

Passkeys Could Reduce Account Takeovers

If passkeys continue gaining adoption, the volume of password-based account attacks could decline.

That does not eliminate cybercrime.

It changes where criminals spend their effort.

The Human Element Will Remain

Technology can make phishing harder.

It cannot eliminate deception.

Users will still receive convincing messages, calls, emails, and fake support requests.

Security awareness therefore remains necessary.

The Strongest Security Model Is Layered

Passkeys.

Strong passwords.

Two-step verification.

Device security.

Caller context.

Monitoring.

Incident response.

Vendor controls.

Each layer contributes something different.

Cybersecurity Is Becoming More Preventive

The industry is gradually moving from detecting attacks after they happen toward preventing entire categories of attacks.

Passkeys are an example.

They do not merely detect phishing.

They make certain forms of credential theft substantially less useful.

Data Breaches Are Becoming More Complex

A breach is rarely a simple question of “what database was hacked?”

Modern investigations must determine:

Who accessed the system?

How did they authenticate?

What records were viewed?

What was downloaded?

Were records duplicated?

Were credentials compromised?

Were other systems affected?

Transparency Builds Trust

Companies facing security incidents need to communicate clearly.

Customers want to know what happened.

They want to know what information was involved.

They want to know what was not affected.

They also need practical advice.

The Security Race Never Ends

Attackers innovate.

Defenders innovate.

Technology changes.

Human behavior changes.

The organizations that remain safest are usually those willing to continuously improve rather than assume yesterday’s controls will protect tomorrow’s systems.

The Bigger Message

WhatsApp’s update shows how security can become easier for consumers.

The

Together, they demonstrate the same fundamental lesson:

Cybersecurity is no longer simply about protecting systems. It is about protecting identities, decisions, relationships, and data wherever they exist.

Deep Analysis: Test Your Security Posture From the Command Line

Check Linux Authentication Activity

On a Linux server, administrators can begin by reviewing recent authentication activity:

last -a

This can help identify unexpected successful logins and unusual access patterns.

Inspect Failed Login Attempts

To examine failed authentication attempts on systems using traditional authentication logs:

sudo grep "Failed password" /var/log/auth.log

Unexpected geographic or temporal patterns can indicate password attacks.

Review Privileged Access

Administrators should regularly examine privileged accounts:

sudo getent group sudo

Unexpected members of privileged groups should immediately trigger investigation.

Check Listening Network Services

A basic local exposure check can be performed with:

sudo ss -tulpn

This displays listening TCP and UDP services and can reveal applications that should not be exposed.

Review Active Connections

Administrators can inspect active network connections using:

sudo ss -tunap

This can help identify unusual outbound or inbound connections.

Examine System Logs

On systems using systemd:

sudo journalctl --since "24 hours ago"

Security teams can narrow this further to authentication-related events.

Search for Suspicious Privilege Changes

A useful investigation step is reviewing logs around changes to users and permissions:

sudo journalctl | grep -Ei "sudo|useradd|usermod|passwd|authentication"

Check Installed Software

Unexpected packages can indicate unauthorized changes:

dpkg -l

On RPM-based systems:

rpm -qa

Review Scheduled Tasks

Attackers sometimes establish persistence through scheduled jobs:

crontab -l
sudo ls -la /etc/cron.

Inspect Recently Modified Files

For a basic review of recent filesystem changes:

sudo find /etc -type f -mtime -1 -ls

This is not a complete forensic method, but it can highlight unexpected recent modifications.

Examine SSH Configuration

SSH remains a major attack surface on internet-facing Linux systems:
sudo sshd -T | grep -Ei "passwordauthentication|permitrootlogin|pubkeyauthentication"

Organizations should verify that authentication settings match their security policies.

Audit Cloud and Third-Party Access

Command-line checks are only one part of a modern security program.

Cloud audit logs, SaaS authentication events, API activity, and vendor access logs must also be reviewed.

A secure Linux server cannot compensate for an exposed third-party CRM account.

Security Must Follow the Data

The most important lesson from these incidents is that security teams must follow information wherever it travels.

If customer data moves from a local database to a cloud CRM, security controls must follow it.

If an employee accesses an account from another device, identity controls must follow them.

If a user receives an unexpected WhatsApp call, contextual security information should follow the interaction.

That is the future of cybersecurity.

✅ WhatsApp Security Update Is Confirmed

Meta officially announced stronger two-step verification, multiple passkeys, and additional context for unknown callers on August 25, 2026. Meta also confirmed that more than 1 billion people have configured a WhatsApp passkey.

✅ New Zealand Sotheby’s Incident Is Confirmed

New Zealand

❌ The 1.6 Million Contact Figure Should Not Be Treated as 1.6 Million Unique Victims

The reported 1.6 million figure has been disputed by Sotheby’s, which said its database does not contain anywhere near that number of contacts and that duplicate entries may explain the figure. The investigation is still ongoing.

Prediction

(+1) Passkeys Will Become the Default Authentication Model

As more major platforms adopt passkeys, password-based authentication will gradually become less central to everyday account security.

(+1) Messaging Platforms Will Add More Anti-Scam Context

WhatsApp’s caller-context feature points toward a broader trend in which messaging applications provide users with risk information before they interact with unknown accounts.

(+1) Stronger Authentication Will Reduce Traditional Account Takeovers

Passkeys and stronger secondary authentication should make many credential-phishing attacks less effective, particularly when users keep their devices properly secured.

(+1) Third-Party Risk Management Will Receive More Attention

Incidents involving external SaaS and CRM providers will continue pushing companies toward stronger vendor assessments, tighter access controls, and better monitoring.

(-1) Attackers Will Not Disappear

As passwords become harder to exploit, criminals will likely shift toward social engineering, device compromise, session theft, malicious applications, and attacks against account-recovery mechanisms.

(-1) Data Exposure Will Remain a Major Problem

Even when financial records are not exposed, basic personal information can still fuel highly convincing phishing and impersonation campaigns.

The Bigger Cybersecurity Lesson

The most important message from these two stories is not simply that WhatsApp has added new security features or that Sotheby’s is investigating a third-party incident.

It is that the cybersecurity battlefield is moving closer to everyday life.

Your phone is an authentication device.

Your messaging account is an identity.

Your contact information is valuable intelligence.

A third-party CRM is part of a company’s effective attack surface.

A single unexpected phone call can become a social-engineering opportunity.

Security therefore has to exist at every stage, from the moment a user authenticates to the moment data is stored, processed, transferred, or accessed by a third-party provider.

WhatsApp’s passkeys and stronger verification represent the defensive side of that evolution.

The Sotheby’s incident represents the other side: the uncomfortable reminder that even organizations with security controls can face exposure through systems beyond their direct control.

The future of cybersecurity will belong to organizations and users that understand both sides of the equation.

Stronger authentication protects the door. Better visibility tells you who is approaching it. Strong third-party controls make sure there is not another door hidden somewhere else.

▶️ Related Video (72% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube