Technology

WhatsApp Usernames Are Already Raising Impersonation Red Flags

WhatsApp began rolling out username reservations this week ahead of a broader launch planned later this year — and within days, the feature is already generating friction with regulators, security researchers, and public figures who've discovered their names and identities are being claimed by unknown accounts before they can get to them first. What the Feature Actually Does Until now, your phone number has been your identity on WhatsApp. Anyone who wanted to message you needed that number — which creates a natural friction point that, among other things, makes impersonation harder. The new username system changes that fundamental dynamic: users will be able to find and contact each other through a chosen handle instead of a phone number, similar to how Twitter, Instagram, or Telegram work. Meta has pitched this as a privacy improvement — users can communicate without revealing their phone number — and has added the ability for creators, businesses, and organizations to claim their existing Instagram or Facebook handles to maintain a consistent identity across Meta's platforms. The reservation phase began rolling out globally on June 29, with the full feature launch expected gradually later this year. WhatsApp says it is optional — users don't have to set a username — and that private messages remain protected by end-to-end encryption regardless of whether the feature is used. The Impersonation Problem Is Already Here The problem with username systems is squatting — the practice of claiming a name that signals someone else's identity before the legitimate owner gets there. On platforms like Twitter and Instagram, this was a significant issue at launch and required ongoing verification systems and enforcement teams to manage. WhatsApp, as the world's largest messaging app with over two billion users, is running into the same problem at vastly greater scale. In India — WhatsApp's single largest market with more than 500 million users — the problem became visible almost immediately. Aam Aadmi Party leader Manish Sisodia posted publicly that when he tried to reserve his own username, he found that virtually every variation of his name combined with his party affiliation — "Manish.Sisodia.AAP," "Manish_Sisodia_AAP," "ManishSisodiaAAP" and several similar combinations — had already been claimed. Since there is no other prominent figure in Indian politics by that name associated with AAP, the implication is that someone else registered those handles ahead of him. The concern isn't theoretical: a user with a handle like "Manish_Sisodia_AAP" can contact WhatsApp users and carry implied authority they don't have. This pattern — public figures, politicians, financial institutions, and government agencies finding their name variations already claimed before they could reserve them — is the core structural risk the feature creates. Unlike phone numbers, which are issued by telecom operators and traceable, usernames on WhatsApp can be claimed by anyone on a first-come, first-served basis. That shifts the impersonation risk from "someone fakes a phone number" to "someone claims a username that implies they're someone they're not." India's Government Has Intervened The concerns reached regulators fast. India's Ministry of Electronics and Information Technology sent a formal notice to WhatsApp within days of the reservation rollout, warning that the feature could "materially increase the incidence of online fraud, phishing, digital arrest scams and impersonation attacks" — the latter being a specific type of fraud that has surged in India, where scammers impersonate police officers, bank officials, and government agencies to coerce payments. The ministry directed WhatsApp to explain why regulatory action should not be initiated under India's IT laws and asked the company not to proceed with the broader feature rollout until consultations were completed. That government intervention has itself drawn pushback. Internet Freedom Foundation, a New Delhi-based digital rights group, argued that the ministry's notice lacked a clear legal basis and risks giving the executive broad powers to dictate product design decisions at major platforms — a legitimate concern in its own right, separate from whether the underlying impersonation risk is real. What WhatsApp Says It's Doing About It WhatsApp's response has been to emphasize the protective measures it has built into the system. A spokesperson said the company has "held the highest-profile names — public figures, government entities, celebrities, verified Meta accounts — so they can only ever be claimed by their legitimate owners," and that "lookalike derivatives of known names are held as well." The company also plans to offer optional username keys — short numeric codes users can share alongside their handle — to make it harder to impersonate someone even if you've claimed a similar-sounding name. WhatsApp has also stated that it has "multiple layers of defense" in place to detect and stop abuse. The gap in that answer is obvious: the system of proactively reserving high-profile names relies on WhatsApp correctly identifying who counts as high-profile, and correctly reserving all meaningful variations of those names, before squatters get there. That is an extremely difficult problem at scale — as Sisodia's example illustrates, even a well-known opposition politician in the world's most populous country found multiple variations of his name already claimed when he went to reserve them. The Broader Tension This Exposes There is a real privacy benefit to username-based contact — removing phone numbers from the equation reduces one category of personal data exposure, particularly for women, activists, journalists, and others who face harassment risks from having their phone numbers in circulation. That benefit is genuine and worth taking seriously. But phone numbers, for all their privacy downsides, serve a verification function that usernames do not. A phone number is issued by a regulated telecom operator, linked to a real identity in most jurisdictions, and traceable when fraud occurs. A WhatsApp username is a string of characters anyone can claim. The Mozilla Foundation put the tradeoff plainly: checking a phone number can be a useful verification tool, and moving away from that anchor "permits harms by the platform's fundamental design choices," regardless of what safeguards are layered on top. WhatsApp's answer — protect high-profile names, offer optional PINs, maintain encryption — addresses the most visible cases but doesn't resolve the underlying structural question of how you maintain accountability when the identity anchor shifts from a traceable number to a self-selected handle. This is not a problem unique to WhatsApp. It's a problem that every major platform has had to grapple with as it moved from phone-number identity to username identity. WhatsApp is simply doing it last, at the largest scale, in markets where the fraud risk is highest and the regulatory environment is most active. The outcome of India's consultations with Meta over the coming weeks will be a test case for how much say regulators can exercise over product design decisions at global messaging platforms — and how much impersonation risk is considered acceptable in the name of privacy improvement.

Comments (0)

Please log in to comment

No comments yet. Be the first!