Security improvements for Clients and Partners
July 22, 2024 — by 360dialog Communications Team
As you know, scammers often try to get access to WhatsApp Business API accounts to impersonate real businesses. To ensure Clients and Partners have safer 360dialog accounts, we are implementing a series of small updates.
Updates for account security
We are constantly evaluating security updates to keep accounts safer without disrupting the experience of Clients and Partners when using 360dialog. Below are some updates that are being rolled out, and more can come in the near future.
Email notifications about account changes
Users registered in Client accounts will receive email notifications whenever key changes happen to phone numbers registered under these accounts, such as profile information.
These notifications are essential to ensure Clients are aware of any changes to their numbers, and can proactivelly act if there is anything suspicious or unexpected.
Validation (OTP) for key actions
Users will be validated when performing key actions such as creating a new template message, changing profile information, setting new Webhook URL, submitting a Partner change request or creating new API keys.
This prevents invaders with stolen credentials from taking over the account or being able to send messages on behalf of a business.
Constant monitoring
Our team runs continuous monitoring on all WABAs, identifying new risks and patterns. Flagged accounts are instantly investigated and notified for further steps to be taken.
If you noticed unknown changes or suspicious behaviour on specific accounts, please reach out to our support team as soon as possible.
Keep your account safe
To keep Partners and Clients accounts safe, make sure to follow security guidelines such as:
- Create separate users for each person who will have to access the platform, avoiding shared accounts
- Have a routine for cleaning up users registered with email addresses that are not regularly used or belong to team members no longer at the company
- Don’t keep account credentials in easily shareable files and documents
- Constantly take phishing prevention courses and share them with your team members and Clients
- Monitor email notifications and webhook events for any type of unexpected activity
Become a Partner
WhatsApp Business API built for ISVs and System Integrators
Integrate WhatsApp API into your solution
Manage all clients’ accounts in one place
Turn WhatsApp into a revenue-generating channel