Meta's new username feature solves a real problem - phone number exposure - while quietly removing the one identity thread that fraud models and law enforcement could rely on. A founder's perspective from someone who built a second number to survive it.
Digital Privacy · Security · Founder's Perspective · July 2, 2026
When I moved from Sweden to India five years ago, the first thing that unsettled me had nothing to do with culture, climate, or food.
It was the phone number.
Every store asked for it. Groceries. Pharmacies. Electronics. A clothing shop on the ground floor of a mall. Hand it over before you can redeem a discount, join a loyalty programme, or sometimes simply complete a transaction.
In Sweden, a phone number sits behind layers of consent, data protection law, and cultural instinct. You share it deliberately - with people you choose, for purposes you understand. Handing it to a shopkeeper feels wrong, because culturally, it is.
In India, I watched it flow like a signature. Casual. Routine. Unavoidable.
I knew exactly where it was going. Spam calls by morning. OTP fraud attempts by afternoon. My number travelling down a chain of third-party databases I'd never agreed to enter. I spent years building infrastructure where every data point has a consequence - and that phone number, handed across a grocery counter, had fifteen of them.
So I did what anyone who builds security systems for a living would do. I got a second number. Specifically for this. A shield number - to protect my real one. Today, I still never answer unknown calls, texts, or links. My phone ignores them for me.
Now WhatsApp Wants to Solve That Problem
On June 29, 2026, Meta opened username reservations globally - @handles that, once live, will let you connect on WhatsApp without revealing your phone number to strangers. The feature itself is not yet active anywhere. Users can claim their preferred handle now, ahead of a full rollout later this year.
Meta's framing is straightforward: a phone number is too much to hand a stranger. Usernames let people interact - at events, in community groups, with new professional contacts - without surrendering their primary digital identity. Optional. Private. User-controlled.
I understand the impulse completely. Because I lived the problem it is trying to solve.
But I have spent twenty years building systems where privacy and security had to coexist simultaneously - where dropping either one had real, measurable consequences. And the one thing that experience teaches with absolute certainty is this:
A feature that protects the honest user and the fraudulent one equally is not a privacy feature. It is a gap.
What Just Got Quietly Removed
Your phone number was never just a contact detail.
It was a verification layer. Weak, imperfect - SIM swap fraud exists precisely because it can be broken - but issued, not chosen. Tied to a carrier. A registration history. The one thread an investigator can pull.
A username is chosen. By anyone. In under five minutes. Including the person about to message your elderly parent impersonating an officer from the Central Bureau of Investigation.
That scenario is not hypothetical. India's "digital arrest" scam - where criminals impersonate CBI officers, judges, and customs officials over video calls to extort money - has become one of the most widespread financial crimes in urban and semi-urban India. Victims have transferred amounts from a few thousand rupees to crores. Supreme Court judges have been targeted. Retired government servants. Ordinary families caught in calls lasting hours or days, instructed not to contact anyone, believing they were under active legal investigation. Prime Minister Modi addressed it personally in his Mann Ki Baat broadcast in October 2024, calling it among the most dangerous cyber threats facing Indian citizens.
Now consider the same scammer with a handle reading @cbi_officialunit or @rbi_fraud_alert.
Entrepreneur Ankur Warikoo tested this publicly - listing warikoo, awarikoo, ankurwarikooo, ankur_warikoo, a_warikoo, ankurwarikooofficial as handles claimable to impersonate him. He called it a potential disaster without robust anti-abuse systems. His test was live, during the reservation window. Most of those handles were available.
During WhatsApp's own rollout testing, TechCrunch found that usernames mimicking Prime Minister Modi, well-known Bollywood actors, and the Reserve Bank of India were still claimable - despite Meta's stated policy of protecting high-profile handles. The gap between what the policy says and what a researcher could register in five minutes is the detail that gets glossed over in product announcements and lands in police reports six months later.
Three Voices. One Unresolved Tension.
On July 1, 2026 - less than 48 hours after reservations opened - India's Ministry of Electronics and Information Technology issued a formal notice directing Meta not to roll out the username feature in India and to explain itself within three days. MeitY warned the feature "may materially increase the incidence of online fraud, phishing, digital arrest scams and impersonation attacks."
India is WhatsApp's largest market - over 500 million users. Many rely on WhatsApp not just for messaging but for payments, business communication, and family connection across geographies.
But here is what most coverage missed - this conversation has three voices, not two.
Meta argues privacy. MeitY argues fraud prevention. And the Internet Freedom Foundation - India's leading digital rights organisation - challenged MeitY's own legal basis, arguing the notice "has no clear basis in law" and represents an executive attempt to decide what a company may build without statutory authority.
All three are partially right. Meta is solving a real problem. MeitY is protecting a real vulnerability. IFF is defending a real principle.
The government's position hardened further on July 2. Telegram and Signal - both of which already carry username features - received identical notices, directed to explain their safety measures. This is no longer a WhatsApp-specific dispute. India is establishing a regulatory position on digital identity infrastructure itself. When Zoho co-founder Sridhar Vembu announced he was proactively disabling the username-based account feature in Arattai - Zoho's own messaging platform - to comply with the regulatory change, the signal was unmistakable. When one of India's most respected technology builders removes a feature voluntarily before being asked, the industry has read the room.
What none of them are addressing is the actual design gap underneath all three arguments - the fact that WhatsApp removed a verification layer without building a replacement.
The Part Nobody Is Talking About
The exploit does not land on launch day. It lands in the transition.
WhatsApp is rolling out in waves - country by country - through September 2026. For the next several months, some of your contacts will be on the old phone-number system and some will have usernames. You will have no reliable way to tell which is which.
That ambiguity is not a side effect. It is a ready-made phishing pretext - "Verify your new WhatsApp ID," "Reconfirm your business account," "Claim your handle before someone else does." WhatsApp, entirely unintentionally, has written this script for scammers by making early reservation urgent, public, and widely covered in the press.
This is not speculation. India took Telegram to the Delhi High Court on exactly this argument. Solicitor General Tushar Mehta, citing Indian Cyber Crime Coordination Centre reports, told the court that Telegram's design is "uniquely resistant to conventional enforcement measures" - specifically naming username-based communication that conceals identity, and the ability for a single account to create 40 bots that can recreate mirror channels within minutes.
WhatsApp is proposing the same architecture. At 10 times the scale.
What to Do Right Now if You Run a Business
Three actions. All of them matter before the feature goes live.
1. Claim your business username immediately - defensively. Not because you want to use it today. Because a lookalike handle is worse than no handle. Business-Scoped User IDs are already live in WhatsApp's backend infrastructure globally, regardless of India's pause on the consumer-facing feature. The system is already changing beneath you.
2. Audit every customer-facing workflow that assumes a phone number is the identity anchor. The assumption that "a WhatsApp contact with this number is this person" breaks the moment usernames go mainstream. The first wave of exploitation will land exactly in the workflows nobody thought to review.
3. Tell your customers your official handle before a scammer does. Proactive communication about your verified presence is now a security decision, not just a branding one.
Where I Land
I support neither Meta nor MeitY unconditionally. I support the user.
WhatsApp is solving a real problem. Phone number exposure is a genuine harm. The instinct behind usernames is correct.
But the execution has prioritised the announcement over the architecture. And in systems design - whether you are building a telecom network, a security infrastructure, or a messaging platform for three billion people - the gap between what you announced and what you built is exactly where things break.
WhatsApp has responded with specifics - high-profile names and their derivatives are withheld globally, impersonation-detection systems are live, and new accounts face limits on how many strangers they can contact via username. The safeguards exist. Whether they hold at 500 million Indian users - in a country where digital arrest scams have already reached Supreme Court judges - is what the next 72 hours of regulatory response will determine.
The username feature removes the one piece of the identity stack that fraud models, law enforcement, and ordinary users could rely on to establish baseline trust. It does so without demonstrating what replaces it.
That is not a product decision. It is a transfer of risk - from the platform to the user. From Meta's trust and safety team to your grandmother, who does not know what a username key is and will open a message from @cbi_arrests_unit because it looks official.
Privacy without a replacement verification layer is not progress.
It is a gap with very good marketing.
And gaps always get filled. The question is only by whom.
Awadh Bajpai is Co-Founder of Intelitor, a Coimbatore-based AI-powered physical security company building intelligent protection infrastructure for homes and businesses.
Tags