WhatsApp’s ‘Usernames’ feature: A need for caution

Recently, WhatsApp announced the phased global rollout of its new ‘username’ feature, allowing users to create a unique identifier, eg @XYZ999, for their WhatsApp account. This username will hide the phone number of the user, and when one initiates a conversation or shares contact details on WhatsApp using this ‘username’, the receiver will only see the username, not the actual number. The parent company of WhatsApp, Meta, claims that the agenda behind this policy is user privacy. Well, the Indian Government surely has a different viewpoint on the claims of Meta and, in consequence, the Ministry of Electronics and Information Technology (MeitY) directed Meta to hold the rollout of its proposed ‘username’ feature in India.
The ‘rollout’ has come at a time when India is already drastically hit by an increased number of cybercrimes, making India one of the most vulnerable countries to cybercrime globally. As per statistics revealed by the Ministry of Home Affairs and the National Human Rights Commission, Indians have seen a whopping loss of Rs 52,976 crore in cybercrime offences over the last six years, with the number of cases going up by a massive 24 per cent in 2025 alone. Among these huge losses, highly organised ‘digital arrest’ crimes have quickly become a serious socio-economic problem, causing almost 8 per cent of the financial damage and significant psychological harm to citizens. The most significant vulnerability is India’s unprecedented growth in internet connectivity, with more than 86 per cent of households now connected and millions of first-time smartphone users entering the digital sphere without adequate digital literacy, making them susceptible to high-level social engineering. An in-depth study by the Ministry of Home Affairs shows that the adoption of UPI has progressed at a fast pace and cross-border scam factories have further turned this exposure into a weapon.
The major issue with WhatsApp’s ‘username’ feature is that it will replace one of the most trusted digital anchors, i.e., the verified mobile number. In the Indian digital ecosystem, a mobile number is already tied to a physical identity using Know Your Customer (KYC) protocols run by telecom operators. By hiding this identifier, cybercriminals are getting almost zero barriers to committing fraud and greater confidence to hide themselves behind random handles. If left unchecked, this structural opacity will only continue to amplify complex cybercrimes, aggravating the current crisis. Cyber fraudsters representing themselves as officials from the CBI, ED or as judges will be able to add a further layer of anonymity to carry out cyber offences like digital arrests, while a malicious actor could easily create a fake version of an official’s handle to establish artificial institutional legitimacy.
The present penal law, ie the Bharatiya Nyaya Sanhita, 2023, caters to cyber offences to a large extent and provides for strong punishments as well. Cyber offences like digital arrest and identity-based fraud are prosecuted under provisions governing cheating (Section 318), cheating by personation (Section 319), extortion (Section 308), forgery of electronic records (Section 336), and even organised crime (Sections 111 and 112), if committed by cross-border syndicates. Additionally, these offences are also charged under the Information Technology Act, 2000, such as provisions governing identity theft (Section 66C) and cheating by personation using a communication device or computer resource (Section 66D).
However, allowing an untraceable username policy creates systematic tension in the criminal justice system, especially when it comes to the admissibility of digital evidence under the Bharatiya Sakshya Adhiniyam, 2023 (BSA). The BSA imposes a mandatory requirement for the validation of electronic records. If a crime is committed using a username, not a KYC-authenticated mobile number, then securing the chain of custody, proving the identity of the sender and tracing the electronic record to the real wrongdoer can be a forensic nightmare before a court of law. It deprives law enforcement of the basic information needed to meet judicial scrutiny standards under the BSA.
The Indian government has been active in curbing the increasing rate of digital financial fraud, impersonation and digital arrests, with the introduction of well-crafted digital policies and dedicated applications. The National Cybercrime Reporting Portal (NCRP) and Sanchar Saathi’s advanced feature called ‘Chakshu’ are some of the initiatives that enable citizens to report suspected fraudulent communications, WhatsApp numbers and fake URLs in real time. In addition, systems such as the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) and toll-free helpline ‘1930’ have effectively frozen and saved thousands of crores of rupees defrauded from citizens. However, an outright ban or complete rejection of the WhatsApp username policy is not a viable solution; the solution is to ensure strict platform and technical compliance. Though WhatsApp does not really share a friendly relationship with the Indian Government, it has shown resistance to complying with Indian laws, notably in its landmark challenge to the ‘traceability’ clause of the IT Rules, 2021 (Rule 4(2)) in WhatsApp LLC v Union of India, where it has fought against the requirement to trace the first originator of malicious communications under the shield of end-to-end encryption. Such resistance is part of a larger trend of opposition to Indian sovereignty. It can be seen in Karmanya Singh Sareen v Union of India, in which the platform’s ‘take-it-or-leave-it’ privacy updates were subjected to strong criticism for providing lesser protections for Indian users than for users in Europe. Also, in Meta Platforms & WhatsApp v. Competition Commission of India (2024-2025), WhatsApp made several attempts to evade local market investigation proceedings regarding its data-sharing policies across different platforms, leading to a Rs 213 crore fine for anti-competitive practices. The Indian judiciary has continually stated that foreign tech giants doing business in the local market are not free from domestic laws and are required to follow domestic laws and rules.
However, instead of a blanket ban, the legal and legitimate approach is to implement a two-tiered verification system, where Meta uses usernames but they are closely linked to backend KYC systems. Technical advances should not be allowed to take precedence at the expense of personal safety, and tech platforms should be fully responsible and liable for systemic weaknesses and criminal channels they bring to society.
Siddhartha Mishra is Associate Professor, Faculty of Law, University of Delhi and Bhavna Sharma is Advocate & Cyberlaw Expert Legal Consultant Delhi Police; Views presented are personal.















