logo
Guide

WhatsApp Security Best Practices for Business Numbers

How to secure a business WhatsApp number: access control, session hygiene, phishing, and incident response.

The short answer Securing a business WhatsApp number is mostly access discipline: who can open the inbox, who can send campaigns, and who holds the credentials. The number itself is an asset — a hijacked number can impersonate your business to every customer in your history. The practices below are the standard baseline.
01 · Guide

Treat the number as infrastructure

A business WhatsApp number is closer to a bank account than a phone number: it carries identity, customer trust, and an opt-in history. Secure it like infrastructure, not like a SIM.

  • Control who can access the inbox and admin settings
  • Separate roles for answering, campaigns, and billing
  • Log and review access changes
  • Know exactly who holds the credentials
02 · Guide

Session and login hygiene

Whether your number runs on the Cloud API or a QR session, the session is the attack surface.

  • Revoke unused sessions promptly
  • Never share the QR code or login link
  • Use strong, unique passwords on the workspace
  • Enable two-factor authentication everywhere it exists
03 · Guide

The phishing patterns aimed at businesses

The attacks on business WhatsApp are social, not technical.

  • Fake 'WhatsApp support' or 'Meta verification' messages asking for codes
  • Scans of QR codes promised as verification steps
  • Employees tricked into forwarding the session code
  • Customer impersonation: 'I lost my phone, resend the OTP'
04 · Guide

The OTP rules that prevent takeover

One-time passwords are the keys to the number. The rules are simple and absolute.

  • Never share OTPs with anyone claiming to be support
  • Meta and Wutt never ask for a verification code in chat
  • Verify identity before resending codes to 'customers'
  • Reset credentials the moment a breach is suspected
05 · Guide

What to do if the number is compromised

Act fast and in order.

  • Reset the workspace password and revoke sessions immediately
  • Contact Meta support about the WhatsApp number
  • Warn customers if the number may have been used to send anything
  • Review sends and opt-in data for tampering
  • Treat the incident as a learning exercise for the team
06 · Guide

The quarterly access review

Access rots quietly: a leaving employee's session, a shared password that outlived its owner, a QR session on a retired phone. A quarterly review catches the rot while it is cheap to fix.

  • List everyone with workspace access and ask if each still needs it
  • Revoke sessions from devices and people no longer active
  • Rotate passwords after any departure
  • Document who holds the Meta Business Manager credentials
07 · Guide

How Wutt helps

Wutt's workspace applies role separation and session control to the shared inbox, and the security page documents the current controls — from $11/mo with a $1 first-month trial.

Last updated 5 August 2026

Common questions

Yes — usually through a shared OTP, QR code, or session code. The rules above are the defense.

No. Anyone asking for a code in chat is phishing.

Shared credentials and shared devices with no access control.

The shared inbox removes that need: the number runs in the workspace, not on personal devices.

The security page documents current practices and controls.

Wutt enforces these rules for you

Approved templates, opt-in friendly flows, and campaign volume checks are built into the workspace.

Start the $1 Trial Flat pricing from $11/month. No markup on Meta fees.