01 · Guide
Treat the number as infrastructure
A business WhatsApp number is closer to a bank account than a phone number: it carries identity, customer trust, and an opt-in history. Secure it like infrastructure, not like a SIM.
- Control who can access the inbox and admin settings
- Separate roles for answering, campaigns, and billing
- Log and review access changes
- Know exactly who holds the credentials
02 · Guide
Session and login hygiene
Whether your number runs on the Cloud API or a QR session, the session is the attack surface.
- Revoke unused sessions promptly
- Never share the QR code or login link
- Use strong, unique passwords on the workspace
- Enable two-factor authentication everywhere it exists
03 · Guide
The phishing patterns aimed at businesses
The attacks on business WhatsApp are social, not technical.
- Fake 'WhatsApp support' or 'Meta verification' messages asking for codes
- Scans of QR codes promised as verification steps
- Employees tricked into forwarding the session code
- Customer impersonation: 'I lost my phone, resend the OTP'
04 · Guide
The OTP rules that prevent takeover
One-time passwords are the keys to the number. The rules are simple and absolute.
- Never share OTPs with anyone claiming to be support
- Meta and Wutt never ask for a verification code in chat
- Verify identity before resending codes to 'customers'
- Reset credentials the moment a breach is suspected
05 · Guide
What to do if the number is compromised
Act fast and in order.
- Reset the workspace password and revoke sessions immediately
- Contact Meta support about the WhatsApp number
- Warn customers if the number may have been used to send anything
- Review sends and opt-in data for tampering
- Treat the incident as a learning exercise for the team
06 · Guide
The quarterly access review
Access rots quietly: a leaving employee's session, a shared password that outlived its owner, a QR session on a retired phone. A quarterly review catches the rot while it is cheap to fix.
- List everyone with workspace access and ask if each still needs it
- Revoke sessions from devices and people no longer active
- Rotate passwords after any departure
- Document who holds the Meta Business Manager credentials
07 · Guide
How Wutt helps
Wutt's workspace applies role separation and session control to the shared inbox, and the security page documents the current controls — from $11/mo with a $1 first-month trial.
Last updated 5 August 2026
Common questions
Yes — usually through a shared OTP, QR code, or session code. The rules above are the defense.
No. Anyone asking for a code in chat is phishing.
Shared credentials and shared devices with no access control.
The shared inbox removes that need: the number runs in the workspace, not on personal devices.
The security page documents current practices and controls.