WhatsApp Usernames: Privacy Feature Brings New Impersonation Risks
WhatsApp has begun rolling out usernames, letting people connect without sharing their phone number. The feature adds privacy for individual users but opens fresh territory for impersonation, lookalike accounts, and smishing, particularly as usernames are reserved on a country-by-country basis.

Key takeaways
- WhatsApp usernames let users connect using a handle of three to 35 characters instead of a phone number, with no public directory or search function.
- An optional username key adds a further access code before a new contact can message the account holder.
- WhatsApp is reserving usernames tied to celebrities, public figures, and organisations, and allowing Instagram or Facebook handles to carry across, to reduce impersonation.
- The shift away from phone number verification creates new opportunities for threat actors to register lookalike company usernames and run smishing campaigns that appear more credible.
- Usernames are being reserved on a country-by-country basis, meaning brand protection teams should check availability of their organisation's name early.
WhatsApp usernames: a privacy upgrade with a security catch
WhatsApp has shared further detail on the rollout of usernames, a feature that lets people connect and message each other without exchanging phone numbers. Users will be able to choose a handle of between three and 35 characters, with reservations opening ahead of a phased rollout that WhatsApp has confirmed will continue through the rest of 2026, following waves that began in select countries in July.
There are no public directory and no username search built into the app, so a new contact will need to already know someone's exact handle before reaching out. Phone numbers remain attached to every account in the background, but a user who prefers to communicate by username can keep that number hidden from the person they are messaging. As an additional layer of control, WhatsApp is introducing an optional username key, a further code that can be required before an unfamiliar contact is able to send a message at all.
Why this matters for impersonation
WhatsApp has said it will reserve certain usernames connected to celebrities, public figures, and organisations, a measure intended to stop impersonation before it starts. The company has also confirmed that individuals and businesses may be able to claim a username that matches one they already use on Instagram or Facebook, giving people a consistent identity across Meta's platforms.
These protections address some of the more obvious impersonation routes, but the underlying shift is still significant. Moving away from a phone number as the primary identifier removes a verification signal that has underpinned WhatsApp since 2009. Phone number verification has been an imperfect but consistent friction point for threat actors; usernames remove that friction for legitimate users and, potentially, for attackers too.
Username reservation itself is open globally right now, while the phased rollout of the feature to send and receive messages by username is happening on a country-by-country basis. That gap matters: a threat actor can reserve a handle closely resembling a real company name today, in any market, well before the organisation itself gets around to claiming it or before the feature even goes live for users in that country to message by username. The earlier a business reserves its own handle, the smaller that window of exposure.
A convincing lookalike username attached to a business name gives a phishing message a level of surface credibility that a random phone number never could. Given that smishing volumes grew by 30 to 40 percent quarter on quarter through late 2025, the incentive for threat actors to exploit any new impersonation surface is clear.
The scale of the problem this sits inside
UK organisations are already absorbing significant losses from phishing and impersonation-style fraud across existing channels. UK Finance's Annual Fraud Report puts 2025 losses from phishing-related scams at over £1.2 billion, a figure reported by Security Journal UK that is expected to climb further through 2026. Ofcom's most recent Scams Tracker found that around four in five UK adults received a suspected scam call or text in the previous three months, with people aged 75 and over disproportionately targeted.
Trust in familiar brands is consistently the mechanism attackers rely on most. Any feature that gives threat actors a cleaner way to present as a recognisable company name, rather than an unfamiliar number, fits neatly into that pattern. Security and brand protection teams should treat the WhatsApp username rollout as a prompt to check whether their organisation's name is available to reserve in each market where the feature has gone live, and to monitor for lookalike registrations once it does.
What organisations should do now
Security teams do not need to wait for a confirmed incident to act. Reserving official usernames early, briefing customer-facing teams on the change, and updating phishing awareness material to reference username-based impersonation are practical steps that can be taken during the current rollout window. Monitoring for close variants of a brand's name as usernames become available in each country is a sensible addition to existing brand protection and dark web monitoring activity.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.




