WhatsApp Launches New Scam Detection Feature to Flag Potential Scam Messages
Introducing an optional “scam alert” feature that uses a local machine learning model to notify users of potential fraud attempts.
Introducing the Scam Alert Feature
A new optional “scam alert” function is being deployed, leveraging a local machine learning model to notify users when they are being targeted by fraudulent actors. This feature is currently in a restricted beta phase, with initial testing conducted among researchers participating in the company’s bug bounty program.
How the Scam Alert Works
The system operates as an on-device solution, analyzing incoming messages to identify potential scam patterns without transmitting any data to external servers. “Today, we’re introducing an early version of scam alert, an optional tool that employs a local machine learning model to notify users of possible scam attempts,” a representative stated. “The model does not send message content beyond the device for analysis or automatically report incidents to third parties. It works alongside end-to-end encryption to provide users with a voluntary warning when the algorithm detects suspicious activity.”
“If a user determines a warning is inaccurate, they can mark the conversation as trusted, which removes the alert and prevents future flags for that chat,” the statement added. “Users who trust a conversation may also choose to share the last five messages received to enhance the system’s accuracy.”
Data Handling and User Control
All data processed by the local model and the model itself remain on the user’s device, with the option to disable the feature at any time. The feature is part of ongoing efforts to strengthen user safety against evolving cyber threats.
Broader Security Initiatives
This initiative aligns with broader efforts to combat fraud, following earlier updates that introduced measures to detect suspicious behavior before users interact with malicious content. In March, the company announced a feature to alert users about suspicious device-linking requests, a common method for account hijacking involving malicious QR codes or shared verification codes. Two months prior, it launched “strict account settings,” a security enhancement designed to protect high-risk individuals such as journalists and public figures from advanced threats, including spyware attacks.
Context and Impact
This security measure was developed in response to incidents where journalists, activists, and political figures were compromised by spyware, including NSO Group’s Pegasus, through messaging apps using zero-click exploits that allow attackers to infiltrate iOS and Android devices without user interaction. The messaging platform serves over 3 billion users globally, with 37% of malicious activities blocked after attackers obtain valid credentials. The Blue Report 2026 evaluates defensive strategies across 338 million simulations conducted in customer environments.
