Press "Enter" to skip to content

WhatsApp launches optional on-device Scam Alert to flag potential fraud

WhatsApp has begun a limited beta rollout of an optional feature called “Scam Alert,” designed to warn users when incoming messages appear to be part of a scam. The feature runs a machine learning model directly on the user’s device, meaning that no message content is transmitted off the phone for analysis or reporting to WhatsApp, its parent company Meta, or any third party. By keeping the classification process local, WhatsApp says the new warning system complements its end‑to‑end encryption while giving individuals a user‑controlled tool to spot likely fraudulent conversations.

How the Scam Alert feature works

According to WhatsApp, the on‑device model was trained on scam conversations that users have reported in the past. It looks for linguistic signals and patterns in the structure of a conversation, especially when the sender is not saved in the recipient’s contacts. By applying probabilistic classification to these signals, the model determines whether a message matches known scam characteristics. If the model flags a message, the app displays a chat‑level warning that invites the user to block the sender, report the conversation, or continue the dialogue.

Users retain full control over the alert. If a warning is deemed incorrect, the chat can be marked as trusted, which removes the warning and prevents the model from flagging future messages from that contact. In that trusted state, WhatsApp also offers an optional opt‑in to share the last five messages received from the chat. This limited sharing is intended to improve the model’s accuracy over time, but only if the user chooses to participate. The feature can be turned off at any moment, and WhatsApp emphasizes that both the message data processed by the model and the model itself never leave the device.

WhatsApp’s broader security roadmap

The Scam Alert launch follows a series of security enhancements announced by WhatsApp and its parent company over the past year. In March, Meta disclosed a warning system that alerts users when behavioral signals suggest a device‑linking request may be fraudulent—a common technique that tricks individuals into scanning malicious QR codes or sharing linking codes to hijack accounts. Two months later, WhatsApp introduced “Strict Account Settings,” a lockdown‑style security suite aimed at journalists, public figures, and other high‑risk users. That feature was a response to a wave of spyware infections, including attacks that used the NSO Group’s Pegasus software to exploit zero‑click vulnerabilities on iOS and Android devices.

Those prior updates highlight WhatsApp’s ongoing effort to protect a massive user base. The messaging platform is used by more than three billion people in over 180 countries, making it a prime target for fraudsters and nation‑state actors alike. By deploying a local, privacy‑preserving machine‑learning model, WhatsApp seeks to add a layer of defense that does not compromise the confidentiality of messages while still providing an early warning against scams.

Industry analysts have noted that overall prevention scores tend to drop sharply once attackers gain initial access with valid credentials, a trend reflected in the Blue Report 2026. That report measured defensive techniques across 338 million simulations run in real‑world production environments, showing that many security controls are less effective after an intrusion has occurred. While the Blue Report is not specific to WhatsApp, its findings underscore the importance of proactive, client‑side safeguards like Scam Alert that aim to stop malicious activity before a user engages with a fraudulent message.

WhatsApp’s decision to keep the classification model on the device addresses privacy concerns that have accompanied previous security features. End‑to‑end encryption already ensures that only the sender and recipient can read message content. By guaranteeing that the Scam Alert model processes data locally and never uploads it, WhatsApp reinforces its commitment to user privacy while expanding the toolkit available to combat scams.

As the beta rollout continues, WhatsApp is testing the feature with researchers in its Bug Bounty community. Feedback from those early users will likely shape the final version of Scam Alert, including how the model handles edge cases and how the user interface presents warnings. If the feature proves effective, WhatsApp may expand it beyond the limited beta, making the optional warning a standard part of the app’s security suite.

For now, users who wish to enable the feature can do so in the app’s settings, while those who prefer not to use it can keep it disabled. The optional nature of Scam Alert reflects WhatsApp’s broader strategy of offering layered, user‑controlled security options without compromising the core promise of private, encrypted communication.

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *