Meta described new WhatsApp account-security features on August 25. Two-step verification is moving from a six-digit PIN to a full password that can include letters and special characters. On Android, an incoming call from a person outside the contact list can show more context, such as whether the number is from another country and whether groups are shared. WhatsApp also allows a user to add more than one passkey when using Android and iOS devices. These controls can reduce account-takeover and urgency risks. For an export sales team, they protect the account entry point but do not complete the business continuity design.

Give every business account an accountable company owner

Many export teams attach a business number to one salesperson's personal device. The recovery email, device list and backup process may not exist in a company record. If that person leaves, loses a phone or faces an account incident, buyer conversations and active projects can become inaccessible at the same time.

Maintain an account register with an owner, operating role, phone number, authorized devices, recovery route, last verification and backup owner. A device holding a passkey also belongs in the asset register.

Passwords, one-time codes and recovery secrets should not be copied into a group chat or ordinary shared document. Use an approved credential or identity process with access logging and revocation.

Ownership is not about reading every conversation. It makes responsibility for access, recovery and role changes visible before an incident occurs.

Strong authentication does not prove every instruction is genuine

Two-step verification and passkeys help establish who can enter an account. They do not prove that every transaction instruction inside a conversation is valid. A buyer's account can also be compromised, a contact may appear from a new number, and a fraud attempt can create urgency around payment or shipment.

A change to bank details, contracting entity, delivery address, exceptional discount or urgent release should be confirmed through a previously registered second channel. Use a known corporate email, company phone or CRM contact rather than a new route supplied in the suspicious message.

The confirmation should identify the requested change, responsible person, time and outcome. It belongs in the opportunity or order record rather than only in the chat history.

This targeted control protects the highest-impact changes without turning ordinary buyer communication into a slow approval chain.

Treat unknown-caller context as a clue, not an identity decision

Country information and shared groups can give a recipient a moment to assess an unknown call. A common group does not establish a commercial identity, and an international number is not automatically suspicious.

Use a consistent intake rule. Do not disclose customer, order or employee information immediately. Ask for company, role, referral source and purpose, then verify the minimum necessary details through a website, corporate email or established contact.

A first call can be logged as an unverified lead. The team can confirm it before attaching the person to a customer or opportunity. Declining one unknown call should not permanently exclude a market, while a familiar profile picture should not remove the transaction checks.

The same principle applies to links and attachments. Familiar context lowers friction; it does not establish that a new file is safe or within scope.

Rehearse recovery and role transfer

An account-security policy is useful only if it works when a device is lost or a role changes. Review recovery email, backup responsibility, authorized devices, revocation steps and chat-retention boundaries on a defined cycle.

Before removing a former user's device, confirm that key business state exists in CRM or another governed system. A customer relationship should not survive only inside one conversation thread.

For active work, retain the buyer identity, opportunity state, quotation version, next action, stated limitations and controlled document links. The successor does not need unrestricted historical access to understand the current commitment.

Run a short exercise for device loss, employee departure and suspected account takeover. Record the owner, expected response time, escalation route and evidence of recovery. Repair any step that depends on one person's memory.

What this means for Chinese exporters

WhatsApp often sits between export discovery and a real transaction. Account security directly affects response continuity and buyer trust. The platform can strengthen login and caller context; the company must turn a personal messaging tool into an owned, recoverable and transferable business channel.

Good security does not mean more approval for every message. It means ordinary communication remains fast while changes involving money, identity and delivery receive a second-channel check and a CRM record.

Action checklist

Sources