WhatsApp launching usernames: does it perpetuate or prevent fraud?

August 5th, 2026

Publication : Blog
Themes : Digital ecosystemEmerging Tech

WhatsApp launching usernames: does it perpetuate or prevent fraud?

Image sourced by www.pexels.com

On 30th June, Whatsapp invited its users to reserve ‘usernames’ claiming that users could soon use the platform without requiring mobile numbers. This moment is a significant departure from Whatsapp’s seventeen year old history of using only  mobile numbers for users to contact other users. Two days later, the Ministry of Electronics and Information Technology (MeitY), issued a notice to Whatsapp, seeking a detailed explanation on the proposed feature of usernames and to pause roll-out. Subsequently, the Government of India, had sent notices to Telegram and Signal. News reports indicate that all the companies have responded to the notices.

What’s in a name? And the many hats Whatsapp dons 

Usernames for technology platforms are not new, in fact Whatsapp using a mobile number as an identity for a digital platform was an exception. If most other platforms rely on usernames as the norm, why does Whatsapp’s shift to usernames raise concerns, especially for the government? The answer lies in two interconnected reasons. Firstly, Whatsapp’s reach remains unmatched to any other digital platform. The numbers speak for themselves,  85.3 crore Indians use Whatsapp, while only 15 crore use its closest competitor, Telegram. Secondly, despite being classified as a social media platform, it primarily functions as a messaging platform that has virtually replaced the SMS market (which is subject to government regulations). This has made Whatsapp a platform for several official purposes(such as communicating with government officials and for serving  court summons) and commercial purposes (such as banking, ticketing and shopping). 

As a result, to avail these services on Whatsapp, users have to end up sharing their phone numbers. Despite this being a significant violation of privacy for many users, particularly for women who also receive unsolicited personal messages through unauthorised use.  

How usernames could be exploited: Fraud and Impersonations 

With the usernames being introduced without sufficient guardrails, it could become a field day for bad actors including fraudsters. Bad actors and scamsters alike prey on trusted identifiable markers, such as prominent personalities, institutions, logos. These are often visual cues that are used to gain the trust of victims, which is  then exploited for financial gain. This is precisely the reason that most popular forms of frauds in India, are done under the guise of an institution such as the CBI, Cybercell, a bank, SEBI or an institutional process such as KYC or account freezing. As usernames are being introduced, bad actors could use this feature to reserve institutional usernames and use these to exploit trust. Merely blocking certain specific usernames of institutions would not suffice as bad actors adopt several techniques to impersonate institutions. These involve using usernames with minor misspellings or adding geographic locations to institutional names, and the strong visual cues of the usernames make it easy for users to overlook the specifics.  

This is not a hypothetical situation. Within a day of allowing users to reserve usernames, former Delhi Minister Manish Sisodia posted on X as to how many usernames related to his name and political party were already reserved by others. Despite there being no other person with the same name in his political party. People could use usernames that impersonate or closely mimic names or positions of government officials and politicians, not just institutions alone. Without any means of verification from the user’s end, such as access to a public list of official numbers and details, it could potentially mean that many end up being lured into an impersonator’s trap. The question of impersonation is not limited to public figures, it could also be used in personal lives, that could hamper safety and security of users, particularly women. 

Similarly, the fraudster could adopt names similar to many banking, financial and shopping platforms pretending to offer those services. At the time of writing, usernames of many popular platforms and banks remain available to be reserved. With scamsters adopting many innovative approaches, there could be potentially lakhs of usernames that could be used by fraudsters with some minor variations. Even, in this case, users may not necessarily be able to verify it is a legitimate platform or not. 

This is particularly concerning as research has shown that messaging platforms are a common mode of initial contact by fraudsters, second only to phone calls. Most of these Whatsapp messages are from users impersonating government officials, banks or e-commerce platforms. 

WhatsApp has reportedly replied that they will take steps to permanently ban accounts of those engaged in impersonation, this could be significantly challenging, considering the creative means that fraudster could adopt.  

Opportunity in disguise?

Tech platforms have often considered trust and safety as an afterthought after design a new feature, or a product. While usernames without adequate safeguards on WhatsApp could aid fraud, with a thoughtful rollout and  embedding safety by design, it could instead reduce fraud while enhancing user privacy and security. This could be achieved by a three phased rolling-out process. 

Government officials could be provided the opportunity to first to reserve specific usernames and launch a verification portal of all official usernames used by departments and agencies. This could provide a space for institutions to create a trusted mode of communication with users, eliminating access to impersonators. After implementation of the first phase, e-commerce platforms and other businesses could be provided an opportunity to reserve names with sufficient business verification and due diligence being done. Lastly, users could be allowed to reserve names, meanwhile being prevented from being impersonated or impersonating at the official or commercial level. This staged roll-out of verification has benefited platforms like Twitter (now X) before the blue-tick was monetised. 

Through this staged roll-out, Whatsapp could use this as a move not only to enhance the privacy of users, but also enable institutions to build trusted communication channels and thereby curb cyber fraud significantly. This could create a paradigm shift, one that builds trust in technology and enhances institutional trust, where historically there has been a deficit.