WhatsApp is preparing to introduce unique usernames that would let people message each other without sharing phone numbers, a change positioned as a privacy improvement for group chats, events, and first-time contacts. The feature is designed without a public directory, requiring users to know an exact username, but officials and cybersecurity authorities have warned it could also make impersonation and phishing easier by allowing attackers to register lookalike names resembling trusted individuals, brands, banks, or government bodies.
India’s Ministry of Electronics and Information Technology (MeitY) has asked WhatsApp to suspend the rollout until it receives government approval, arguing the feature could fuel phishing, so-called digital arrest scams, and fraud targeting public authorities and financial institutions in WhatsApp’s largest market of more than 850 million users. WhatsApp said it plans safeguards including contextual warnings, reserved usernames for legitimate organizations, lookalike protections, contact-initiation limits, anti-enumeration controls, and abuse-detection systems, while security guidance has urged users to verify suspicious contacts through official channels and advised organizations to reserve official usernames early and clearly communicate their legitimate accounts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Finland’s Traficom warned that WhatsApp’s planned introduction of unique usernames could increase impersonation and phishing attempts, as attackers may register lookalike names resembling trusted people, brands, or organizations. It advised users to verify suspicious contacts through official channels and urged organizations to reserve official usernames early.
India’s Ministry of Electronics and Information Technology sent WhatsApp a letter demanding that it suspend deployment of planned usernames until it receives government approval, citing risks of phishing, impersonation, and scam abuse. The ministry gave WhatsApp three days to respond.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.