Published Security3 min read
WhatsApp's Scam Alert warns, does not block, and never sees the hijacked contact
Meta's on-device model flags likely scams from non-contacts in a limited beta. It carries no enforcement, no admin visibility, and no view of the vector that works best.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Meta announced it is rolling out Scam Alert, a new anti-scam feature for WhatsApp users.
- Scam Alert is an optional beta feature that uses an on-device machine-learning model.
- Scam Alert flags likely scam messages from people who are not in a user's contacts.
- Once enabled, Scam Alert downloads a machine-learning model to the device and examines incoming messages from non-contacts for scam patterns; WhatsApp says the model uses linguistic signals and conversational structure learned from scam conversations previously reported by users.
- The feature will not block anything; it alerts the user to stop and think carefully before engaging with the sender.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Meta has begun a limited beta of Scam Alert, an optional WhatsApp feature that downloads a machine learning model to the handset and checks incoming messages from people who are not in the user's contacts for scam patterns [1][2][3][4]. It flags, and it blocks nothing [5], which is the first reason not to file it as a control against employee social engineering.
The mechanics are modest and honest about it. WhatsApp says the model works from linguistic signals and conversational structure learned from scam conversations that users previously reported [4]. When it fires, the user sees a warning banner inside the chat, and the sender does not see the banner, so a scammer is not tipped off that their approach was detected [8]. From there the user can block, report the chat, keep talking, or mark the chat as trusted, which removes the warning and stops Scam Alert flagging that conversation again [9]. Every one of those outcomes depends on a person under pressure making the right call, which is the condition the attacker has already engineered.
The bigger gap is scope. According to Malwarebytes, some of the most effective WhatsApp scams arrive from a compromised contact, citing the recent "vote for my friend" account takeover campaign, and because the message appears to come from someone the victim already knows, an unknown-sender warning may never appear [11]. Put the two design facts together and the model's detection surface excludes both saved contacts and any thread the user has already marked trusted [16]. The highest-yield vector sits outside the classifier by construction.
That matters for corporate exposure specifically, because the pretexts Meta is aiming at are the ones that walk into a workplace: impersonation, fake jobs, fake sales, investment fraud, romance baiting, malicious links and payment requests [6]. The campaigns typically start on another platform and then move the target into a private chat where criminals can apply pressure and build trust [7]. A recruiter approach that begins on a social platform and lands in WhatsApp is a personal-device conversation about a work identity, and Scam Alert's contribution to it is a banner.
The privacy design is the part worth crediting. Classification is local, the feature is opt-in, and there is no automatic reporting to Meta [12], which is a reasonable set of choices for an encrypted messenger. It also means the flag lives and dies on the employee's phone and generates no signal a security team can see or measure [17]. There is no coverage number here to put in a report.
It is also early: the feature is in limited beta and is being tested with researchers in Meta's bug bounty community before wider release [13].
What to watch: whether Meta extends detection to messages from saved contacts, since that is where account takeover lands, and whether the trusted-chat setting ever expires. In the meantime the controls that actually address the compromised-contact path are account hardening, not classification. Malwarebytes recommends enabling two-step verification on WhatsApp, never following instructions to link devices or scan QR codes unless the user initiated the action, and periodically reviewing linked devices under Settings and logging out of anything unrecognised [14][15]. Those are auditable. A warning banner is not.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Meta announced it is rolling out Scam Alert, a new anti-scam feature for WhatsApp users.
- [2]
Scam Alert is an optional beta feature that uses an on-device machine-learning model.
ReportedView cited source - [3]
Scam Alert flags likely scam messages from people who are not in a user's contacts.
ReportedView cited source - [4]
Once enabled, Scam Alert downloads a machine-learning model to the device and examines incoming messages from non-contacts for scam patterns; WhatsApp says the model uses linguistic signals and conversational structure learned from scam conversations previously reported by users.
- [5]
The feature will not block anything; it alerts the user to stop and think carefully before engaging with the sender.
ReportedView cited source - [6]
Scammers increasingly use WhatsApp for impersonation, fake jobs, fake sales, investment fraud, romance baiting, malicious links and payment requests.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- malwarebytes.comAug 14WhatsApp is testing a new warning for scam messages
Additional citations
- Malwarebytes
- WhatsApp, via Malwarebytes



