Information Security

Scam Alert: how WhatsApp will detect scams without breaking encryption

Meta has started testing its new feature against digital scams, and CodeBlog has gathered everything you need to know about it

08/21/2026

Brenda Pimentel

Present in 99% of active smartphones in Brazil, WhatsApp is the number one application among Brazilians. But this national preference also extends to an unwanted audience: scammers. According to the report The State of Scams in Brazil, by the Global Anti-Scam Alliance (GASA), released on August 7 of this year, the country recorded around 34 billion digital scam attempts between March 2025 and February 2026. Of this total, 16.5 million Brazilians lost money, totaling R$ 21.2 billion in losses (an average of R$ 1,287.00 per person). And WhatsApp clearly leads the channels used for scams, with 64% of victims stating they were contacted through the application. 

Aware of the problem, WhatsApp has been investing more and more in security and the focus of the moment is Scam Alert, an optional feature that uses a machine learning model running on the cell phone itself to identify potential scam messages, without the content of the conversation leaving the device.

Announced on August 12, 2026, by Meta Engineering, the feature is a preview, is in beta, but has already sparked the curiosity of users, companies, and technology professionals. If you are one of them, stay tuned to this article, as we will explain what it is, how it works, when it is expected to arrive in Brazil, and much more.

What is Scam Alert, exactly?

Scam Alert is a warning that appears in the chat itself when WhatsApp identifies that a message has characteristics of a scam. The identification of these frauds occurs, mainly, based on the structure of the conversation and language patterns already reported by other users. The warning is visible only to the person who receives the message; the other person does not know that the signaling occurred.

Based on the alert, the person who received the message can decide what to do:

  • Block the contact;

  • Report the conversation to WhatsApp;

  • Mark as trustworthy, removing the warning. In this case, the app will not signal that chat again.

There is also an extra option: if the user marks a chat as trustworthy, that is, indicates that the alert made a mistake, they can choose to share the last 5 messages received with WhatsApp to help train and correct the model. 

For now, the feature is in limited testing in the beta version, with a technical overview published for the security community and entered into Meta's bug bounty program, which will try to break the system under extreme conditions before a broader release.

How Meta resolves the encryption paradox

The challenge of designing Scam Alert is practically a paradox: how to alert about the content of a message without violating the promise of WhatsApp's end-to-end encryption, which guarantees that not even Meta itself can read the conversations?

The company's technical answer was to take the server out of the equation. Instead of sending the message to the cloud, the model operates on the user's smartphone, taking advantage of recent advances in mobile hardware that make it feasible to apply small AI models without consuming battery or processing power. According to Meta, the design of Scam Alert follows three principles to ensure end-to-end encryption:

1- Operates only on the device — the model and the data it processes never leave the user's cell phone for classification.

2- No automatic reporting — Meta cannot initiate data sharing on its own. The only way a message (or even the scam detection itself) reaches the company's servers is if the user actively chooses to report it, in the same way the report button on WhatsApp works today.

3- Control in the user's hands — the feature can be activated or deactivated at any time, and each alert can be corrected by the user themselves.

Technical guarantees and why they are verifiable

The most interesting point of the announcement, from a technical perspective, is that Meta is not asking the public to simply trust them. The company describes three safeguards that, according to it, can be independently audited:

The first of these is privacy-preserving telemetry. The only data that leaves the cell phone are aggregated and anonymous metrics processed within trusted execution environments (TEEs, via confidential virtual machines) and protected by differential privacy before reaching Meta.

The second is that neither Meta nor WhatsApp can send a specific version of the model to a specific user. Every version, including experimental ones, is published beforehand in a public transparency registry (an append-only ledger maintained by third parties), making a scenario where the model would be used to spy on someone in particular very difficult.

The third is that the model's behaviors are published transparently so that independent security researchers can check if it was trained only to detect scams and not for anything else.

In practice, this is a direct response to a recurring criticism of any AI moderation system: the fear that it is actually a backdoor for surveillance. The publication of the architecture was done precisely to give even more credibility to the company's positioning. 

Does Scam Alert resolve the most common scams on WhatsApp?

It is worth remembering that Scam Alert is trained to recognize patterns of fraudulent conversations already reported, meaning it tends to be more effective against classic and recurring scams than against entirely new threats. As we showed in our survey on the technology behind the most common scams on WhatsApp, a large part of the frauds circulating on the app (fake technical support, account cloning, fake relative in trouble, Pix scam) follow very similar social engineering scripts, exactly the type of pattern that a local classifier can learn to recognize over time.

This does not make Scam Alert a definitive solution. Scams with AI-generated bait, mentioned in Meta's own announcement as part of the evolution of tactics that motivated the feature, tend to vary more with each attempt, which is precisely the type of threat that is hardest for a pattern classification model to handle. The feature is more of an extra layer of protection rather than a substitute for basic caution when talking to strangers.

What to do if the alert appears on your WhatsApp

When (and if) Scam Alert arrives on your account, it is worth following a simple logic:

If the message really seems suspicious (unknown person asking for money, bank details, or verification codes), block and report it. If it is a mistaken alert, issued because a legitimate contact is not yet in your list, mark it as trustworthy so you won't be bothered again.

If you want to keep the conversation as proof for the police or the bank, pay attention to how you forward the screenshot or the message. Depending on the content and context, forwarding messages has its own legal implications, as we explain in the article "After all, is forwarding WhatsApp messages a crime?".

When Scam Alert arrives in Brazil

For now, Meta speaks of a limited release in the beta version and continues testing with the bug bounty community before expanding to all users. As of the publication of this text, there is no confirmed general availability date — and the history of WhatsApp security features suggests a gradual deployment, by region and by app version. We will update this article as Meta releases updates.

While that moment does not arrive, we have prepared a small section of questions and answers about WhatsApp's Scam Alert.

What is WhatsApp's Scam Alert?
It is an optional feature that uses an AI model running on the cell phone itself to identify potential scam messages coming from unknown contacts, without sending the content of the messages to WhatsApp or Meta servers.

Does Scam Alert read my messages?
The model processes the text locally on your device to classify the risk of a scam, but the content of the message is not sent to Meta, WhatsApp, or any other service, keeping end-to-end encryption intact.

Does Scam Alert automatically report someone who sends me a suspicious message? 
No. No reporting is done automatically. Only if the user themselves chooses to report the conversation is it sent to WhatsApp, just as it already happens today with the report button.

How do I activate (or deactivate) Scam Alert? 
The feature is optional and, according to Meta, can be activated or deactivated at any time in the app settings. As it is still in testing, it may not be available for all accounts.

Is Scam Alert already available in Brazil?
Until the publication of this article, the feature is in a limited beta testing phase, with no confirmed release date for the general public in Brazil.



Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

Shall we talk?

Select a date on our calendar and speak directly with one of our technology experts.

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546

All Rights Reserved - CodeBit

São Paulo - SP

(11) 3014-2103

171 Paulista Ave, 4th floor, Bela Vista, São Paulo - SP

Franca - SP

(11) 3014-2103

5860 Emílio Paludeto Ave.
Vila Hípica, Franca - SP

Orlando - FL

+1 (980) 890-0026

7345 W Sand Lake Rd Ste 210 Office 2546