Blogs
Nikhil Singh

Author

  • Published: Jan 29 2026 12:08 PM
  • Last Updated: Jan 29 2026 12:22 PM

WhatsApp launches Strict Account Settings in 2026 to block unknown files, silence stranger calls, and prevent spyware-style attacks.



Newsletter

wave

WhatsApp has introduced an important security upgrade called Strict Account Settings, which provides additional protection for users experiencing greater digital risks, such as journalists, activists, business owners, and those who are publicly visible.

There are over 500 million people using WhatsApp in India, and this change is very timely. Scams, spyware-like spying, and account theft are no longer uncommon; they have become a common occurrence in our daily lives, whether it be through a missed phone call, sharing a file, or joining a group that appears to be harmless.

This does not take away the fact that WhatsApp is an end-to-end encrypted app; this is an addition to the existing level of security but changes how we think of security from that of a passive form of protection to one that creates a proactive prevention measure.

Why WhatsApp Felt the Need to Go Further

For years, WhatsApp’s strongest defense has been encryption — messages locked so tightly that even WhatsApp can’t read them. But attackers adapted. Instead of breaking encryption, they started targeting users themselves.

The most common entry points have been:

  • Unknown file attachments carrying malicious code

  • Missed calls or video calls triggering hidden exploits

  • Forced group additions used for phishing and impersonation

These tactics mirror global spyware campaigns seen over the past few years, including tools capable of infecting phones without user interaction. WhatsApp’s new approach acknowledges a hard truth: encryption alone isn’t enough when the front door is left open.

What Strict Account Settings Actually Does

Strict Account Settings is an opt-in lockdown mode. When enabled, it sharply limits how strangers can interact with your account. The goal is simple: reduce the number of ways an attacker can even try to reach you.

Once turned on, WhatsApp automatically:

  • Blocks media files and attachments from unknown contacts

  • Silences audio and video calls from people not in your contacts

  • Restricts who can add you to groups

  • Requires a mandatory 6-digit security PIN

  • Applies tighter checks during login or device changes

This creates a quieter, more controlled WhatsApp experience — less convenient, but significantly harder to exploit.

The Hidden Tech Upgrade Powering It: Rust

One of the least visible but most important parts of this update is WhatsApp’s backend rewrite using Rust, a programming language known for memory safety.

Why this matters:

  • Many advanced spyware attacks rely on memory-related bugs

  • Rust is designed to eliminate entire classes of such vulnerabilities

  • Media handling (photos, videos, files) becomes far harder to exploit

According to Meta engineers, core components handling media were rebuilt and tested over more than a year. The result: stronger resistance against silent attacks, without noticeable slowdowns for users.

Who Should Consider Using It

WhatsApp is clear that this mode is not for everyone. It’s designed for users who face higher exposure to digital threats.

Best suited for:

  • Journalists and reporters

  • Activists and researchers

  • Small business owners handling payments

  • Public figures and influencers

  • Users frequently contacted by unknown numbers

For families and casual users, default settings may still be sufficient. Strict mode intentionally reduces interaction flexibility, which can feel restrictive in daily social use.

How to Enable Strict Account Settings

Enabling the feature takes less than a minute:

  1. Open WhatsApp
  2. Go to Settings
  3. Tap Privacy
  4. Open Advanced
  5. Select Strict Account Settings
  6. Set or confirm your 6-digit PIN

The feature can be turned off anytime, and WhatsApp logs changes for transparency.

OTHER ARTICLES TO READ:

The Trade-Off: Security vs Convenience

There’s no sugarcoating it — Strict mode changes how WhatsApp feels.

What you lose:

  • Media from unknown senders won’t auto-download

  • Calls from new contacts won’t ring

  • Group invites become more controlled

What you gain:

  • Far lower exposure to scams and spyware

  • Stronger account integrity

  • Peace of mind if your work or profile attracts attention

For many professionals, that’s a fair exchange.

How It Stacks Up Against Other Platforms

WhatsApp isn’t alone in this direction. Apple introduced Lockdown Mode years earlier, while Google offers Advanced Protection for accounts.

The difference:

  • Apple focuses on system-wide link and attachment limits

  • Google emphasizes account monitoring

  • WhatsApp concentrates on messaging vectors, where most real-world scams occur

The Rust backend also sets WhatsApp apart, especially in how it handles media safely at scale.

Conclusion

Strict Account Settings marks a shift in how WhatsApp thinks about safety — from protecting messages to protecting identities. For users who live online, handle money, or speak publicly, this update offers something rare in consumer tech: quiet, practical security that actually changes outcomes.

FAQ

Yes. End-to-end encryption remains active by default. Strict mode adds extra protection for higher-risk users.

No. Message content stays encrypted and unreadable to WhatsApp.

No system can stop everything, but it significantly reduces common attack methods.

Yes, once you save them as a contact or disable Strict mode.

Yes, with similar protections. Enterprise variants are being tested.

No noticeable performance impact has been reported.

Only if they frequently face unknown contacts. Otherwise, default settings are usually fine.

Search Anything...!