- CybAfrique Newsletter
- Posts
- Is the WhatsApp username feature a security threat?
Is the WhatsApp username feature a security threat?
This week in African infosec
CybAfriqué is a space for news and analysis on cyber, data, and information security on the African continent.
HIGHLIGHTS
Is the WhatsApp username feature a security threat?
WhatsApp is the world's largest messaging platform. 3 billion people across 180 countries talk to each other by having each other's numbers. This has its own tradeoffs, and in the past, cases like the 2019 Pegasus scandal, where NSO Group's spyware infected phones via nothing more than a WhatsApp call to a target's number, have shown that the number is a worthy security risk.
In November 2022, a database containing the phone numbers of nearly 500 million WhatsApp users from 84 countries was advertised for sale on a hacking forum, scraped by exploiting a feature that let attackers check which numbers were registered on the platform. The phone number model poses some risk for privacy at an industrial scale.
Moreover, all of WhatsApp's attempted platform-expansion drive, which has included Channels, Communities, and algorithm-based stories, means it needs a less phone-bound identity model, so it introduced its switch to usernames.
WhatsApp's VP of product, Alice Newton-Rex, told reporters it was designed as a core privacy feature, but it is also a bad move for transparency and traceability. India, WhatsApp's largest market with more than 600 million users, has moved to push back, asking Meta to delay the rollout over fears it may fuel online fraud, and last week received backing from Somalia. The explanation is pretty tenable.
There have been accounts posing as police, the CBI, and courts to extort victims over WhatsApp video calls. I4C has blocked more than 59,000 WhatsApp accounts used for digital arrests, and this year WhatsApp told the Supreme Court it removed 9,400 accounts linked to digital arrest fraud, much of it run from organised operations in Cambodia. India's notice to Meta warned that usernames may facilitate impersonation of individuals, public authorities, financial institutions, and government agencies.
In Somalia, impersonation has also been rife. The regulator cited impersonation of government institutions, financial fraud targeting the country's mobile money ecosystem, and the misuse of anonymous communications by al-Shabaab and organised cybercriminal networks.
It's hard to imagine that Somalia and India are the only countries facing these issues. It is very likely that if the objection gains traction, more countries will get behind it. Countries like Nigeria, Kenya, and Pakistan suffer the same impersonation-driven fraud epidemics and, more tellingly, share the same regulatory reflex of mandatory SIM registration and biometrics so the state can identify the owner of a SIM and infer who is making a call at any given time.
But it might help to look at the underlying tech privacy approach in both countries. India has always prioritised traceability over privacy. In 2021, it passed the IT Rules requiring messaging platforms to identify the "first originator" of a message, a demand Meta resisted on grounds that it would weaken end-to-end encryption for every user. It has since sent similar notices to Telegram and Signal about their own username systems. Somalia, too, has fallen back on identity infrastructure to compensate for weak state capacity. The 2017 telecommunications law requires telcos to register all SIM holders, and the new biometric national ID is now mandatory for opening bank accounts and for domestic air travel.
Somalia pointed out that hiding phone numbers makes it harder for the state to track individuals involved in terrorism and organised crime like al-Shabaab, which leverage mobile communication for coordination. The substitution of phone numbers may hinder Somali security agencies' ability to identify suspects, the director-general of the National Communications Authority, Mustafa Yasin Sheikh, said, adding that "Somalia is following India's example."
FEATURES
HEADLINE
Over GH¢3 million lost to online investment fraud in the first half of 2026, Ghana’s CSA
Senegal: GIABA seeks greater action against emerging financial crimes
Data Breach: Providus Bank customers confirm unauthorised transactions on card
Zimbabwe hosts Operation Serengeti 3.0 kick-off meeting to deepen Africa’s cybercrime response
Madagascar’s last-mile civil registration strategy closes the digital ID inclusion gap
Safaricom Ethiopia supports national digital ID registration across seven regions
Algeria expands digital capacity with national services center
Egypt Cybersecurity Startups Building the Country’s Digital Defenses
Reply