On June 29, 2026, WhatsApp introduced a new feature allowing users to create usernames, a move aimed at enhancing privacy by enabling connections without revealing phone numbers. This development, however, quickly attracted the attention of the Government of India, which raised concerns about potential increases in cybercrime associated with such a feature. The scrutiny soon expanded to encompass other messaging platforms, including Telegram and Signal, highlighting a growing regulatory focus on how username-based interactions could impact user safety and accountability.
Scrutiny over Username Features
Just two days after WhatsApp’s announcement, the Ministry of Electronics and Information Technology (MeitY) issued a notice to the company, requesting a pause on the rollout of the username feature. The notice demanded an explanation as to why regulatory action should not be initiated under various laws, including the Information Technology Act, 2000. WhatsApp was instructed to provide a detailed account along with supporting documents to justify the launch of a feature perceived to heighten risks of cybercrime. This inquiry has since broadened, with similar notices dispatched to Telegram and Signal, seeking clarification on how their existing username functionalities mitigate risks associated with fraud and impersonation.
This shift in regulatory focus signifies a pivotal change in how platforms are assessed. Rather than merely addressing unlawful content post-factum, the current discourse emphasizes the architecture of platforms themselves—specifically, how design choices regarding identity and discoverability can shape the landscape of online risks.
Why These Notices Matter
The heightened scrutiny of username features across messaging platforms represents a significant evolution in regulatory oversight. The emphasis is shifting from reactive measures, such as takedown orders, to proactive assessments of platform design. This change was underscored by a recent judgment from the Delhi High Court in the case of Telegram v. Union of India, which upheld a temporary ban on Telegram during a critical examination period. The court recognized that traditional takedown strategies were often ineffective against rapidly re-emerging unlawful networks, thus acknowledging the relevance of platform architecture in assessing risks.
The username controversy shows this logic moving upstream—from platform-level restrictions to scrutiny of specific design features. Across WhatsApp, Telegram, and Signal, the central question remains the same: can platforms allow pseudonymous interaction while still ensuring accountability under law?
Importantly, the court did not deem usernames unlawful; rather, it expanded the regulatory perspective to include how platform design can complicate enforcement efforts. This evolving legal framework suggests that the architecture of a platform may be scrutinized as part of the state’s risk assessment regarding unlawful activities.
As this conversation unfolds, the implications extend beyond major players like WhatsApp, with smaller platforms such as Zoho’s Arattai reportedly reconsidering their username functionalities in light of regulatory apprehensions.
Privacy Versus Evasion
Usernames serve as pseudonymous identifiers, often touted as privacy-enhancing tools that allow users to communicate without revealing their phone numbers. In a country like India, where phone numbers are intricately linked to various services, the exposure of such information can lead to significant privacy concerns. For vulnerable groups, including women, journalists, and activists, the ability to communicate without disclosing personal numbers is a crucial safety feature. Thus, usernames are not inherently suspicious; they are designed with privacy in mind.
A fraudster hiding behind a username can appear legitimate while making identification harder for both victims and investigators. This is the privacy-evasion dilemma at the heart of the debate: the same design choice that protects users can also be the one that complicates accountability.
However, the government’s concerns are not unfounded. India has witnessed a dramatic increase in reported cybersecurity incidents, from 1.03 million in 2022 to 2.27 million in 2024, reflecting a broader environment of risk associated with cyber fraud and digital abuse. The very features designed to protect users can also empower malicious actors to create deceptive identities and evade detection. This duality encapsulates the privacy-evasion dilemma that lies at the core of the ongoing debate.
What Next for Username Features?
The solution does not lie in banning usernames or treating every privacy-enhancing feature with suspicion. The risks associated with different username systems vary significantly based on platform design. For instance, a service that can map usernames to stable account identifiers is fundamentally different from one that allows for free rotation of handles, which can facilitate abuse.
A more constructive approach would be to advocate for accountable pseudonymity. Users should be able to communicate without disclosing their phone numbers, provided that platforms maintain the capability to address abuse and respond to lawful requests. Platforms must implement measures to prevent impersonation of institutions and public figures while allowing users to control their discoverability and communication preferences.
For regulators, the emphasis should be on targeted safeguards rather than treating privacy-preserving designs as inherently problematic. Platforms can be reasonably questioned about their strategies for handling impersonation and abuse, but the mere act of concealing a phone number should not be deemed dangerous in isolation.
If every feature that complicates enforcement can be scrutinized before launch or challenged post-deployment, India risks shifting from intermediary regulation to a model akin to product-design licensing. The challenge remains to ensure that usernames do not become tools for evasion while safeguarding the essential right to privacy.
Basu Chandola is an Associate Fellow at the Observer Research Foundation.
Disclaimer: ChatGPT 5.5 was used for language refinements.
The views expressed above belong to the author(s). ORF research and analyses now available on Telegram! Click here to access our curated content — blogs, longforms, and interviews.