WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning model. This new tool aims to function alongside the platform’s end-to-end encryption, ensuring that message classification occurs entirely on the user’s device without automatic reporting to WhatsApp or its parent company, Meta. According to reporting by SecurityWeek, the feature is currently available to a select group of users for testing.

Once activated, the feature downloads a model that analyzes incoming messages for patterns indicative of scams, utilizing conversational structure and linguistic cues. If a message is flagged, only the recipient receives a warning within the chat, while the sender remains unaware. Users can choose to block the contact, report the message, ignore the warning, or mark the conversation as trusted, which suppresses future alerts. Those who mark a chat as trusted can also share the last five messages received to enhance the model’s accuracy.

Transparency and Security Measures

WhatsApp has implemented a third-party, append-only transparency ledger to log every model release before distribution. Each release includes a manifest of SHA-256 hashes for model weights and related files, signed using Ed25519 keys held by Cloudflare, not Meta. Devices must verify this signature and cross-check it against the ledger to ensure the integrity of the downloaded files.

To monitor the feature’s effectiveness without compromising user privacy, WhatsApp has developed a confidential federated analytics pipeline. This system collects only two types of data: the frequency of triggered warnings and the actions users take afterward, such as blocking or marking a chat as trusted. The company has outlined a threat model addressing external attackers and compromised infrastructure insiders, asserting that targeting individual user data would necessitate compromising the entire system.

Future Developments

Users will have access to a transparency log within the app, allowing them to review which messages were scanned, the outcomes, and the model version that made the determination. WhatsApp is also expanding its bug bounty program to include the Scam Alert feature. The company describes this rollout as an early technical preview, indicating that the feature will evolve based on user and researcher feedback before a broader release.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Attackers Exploit CVE-2026-82329 Flaw in JFrog Artifactory to Gain Admin Access Days After Patch

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to reporting by The Hacker...

Cloudflare’s H1 2026 DDoS Report Reveals 519% Surge in 1 Tbps Attacks Amid Geopolitical Tensions

Cloudflare's recently released DDoS Threat Report H1 2026 reveals a staggering 519% increase in Distributed Denial of Service (DDoS) attacks exceeding 1 Tbps, highlighting...

Check Point Research Unveils Static Deobfuscation Techniques for JSCeal Malware

Research by: hasherezade Check Point Research (CPR) has recently unveiled significant advancements in the static deobfuscation of JSCeal, a sophisticated malware targeting cryptocurrency applications. Since...

Red Hat Releases Important Kernel Security Update for RHEL 8.8 Services

Red Hat has announced an important kernel security update for its Red Hat Enterprise Linux (RHEL) 8.8 Update Services, specifically targeting SAP Solutions and...