Free Phishing Test
NEWS

WhatsApp Usernames: Will Phone Numbers Stop Being a Gateway to Phishing?

07-jul-2026 11 minutes read

WhatsApp is changing the way users identify themselves on the platform. From June 2026 Meta allows you to reserve unique usernames that will eventually replace your phone number as your primary contact ID. The change affects over 3 billion users in 180 countries and has a direct impact on one of the most common fraud vectors in recent years – phishing conducted by WhatsApp.

What is WhatsApp?

WhatsApp is Meta’s messaging app, used by over 3 billion people in 180 countries for private conversations, voice and video calls, and communication with businesses. The application encrypts messages end-to-end, which means that only the sender and recipient can read the content of chats, not WhatsApp itself.

Why is a change in the application important for company security?

For organizations, WhatsApp has long gone beyond the private sphere:

  • sales and customer service teams conduct conversations with customers through it,
  • employees use it on work devices,
  • and many companies have informal team groups.

This means that any change in the mechanism for identifying WhatsApp users is important not only for the individual, but also for the risk model of the entire organization.

The very need that Meta addresses with the introduction of usernames is simple and well known to anyone who has used group chats. As the company describes it, joining a chat with parents from your child’s sports team or neighborhood group previously required giving your phone number to people you didn’t know.

The phone number, unlike the username, is permanently linked to your identity, credit history, bank account and many other services – hence sharing it with strangers carried a risk that went far beyond the application itself.

What are usernames in WhatsApp and how do they work

A WhatsApp username is a unique identifier that the person sharing it shares instead of a phone number.

A contact who does not have a number in his address book will only see username after implementing the function, not numbers. The mechanism works on Android, iOS, Windows and the web version.

Source: https://wabetainfo.com/whatsapp-is-rolling-out-the-username-feature-on-android-and-ios/

Reservation and username generator

Reservations can be made now, although the full launch of the function will take place in the second half of 2026, gradually, country by country.

The path is short: Settings > Account > Username, after updating to the latest version of the application. The name must be between 3 and 35 characters long, contain at least one letter, and can consist of lowercase letters, numbers, dots, and underscores. It cannot start with “www.” or end with a domain such as “.com” or “.net” – this is protection against names imitating website addresses. Since over 3 billion people use WhatsApp, many obvious names are already taken, so Meta has also provided a generator that suggests variants of available usernames.

Username key as first contact control layer

In addition to the name itself, you can set an optional username key – a short code that a person contacting you for the first time must know together with the username. Without the key, the name itself is not enough to write the message. WhatsApp does not maintain any directory or search engine for users and does not suggest contacts – you need to know the exact name to start a conversation.

Option for creators, companies and organizations

Businesses who want to maintain a consistent online presence can take over a username on WhatsApp that they already have on Instagram or Facebook, after ownership is verified by the Accounts Center. This choice facilitates brand recognition, but it also has consequences, which I return to in the section about new risks.

Naming rules and restrictions

The username must be available on WhatsApp, Instagram and Facebook at the same time – if someone has previously taken it on one of these platforms, it cannot be used on WhatsApp without proof of ownership. Some names are reserved in advance for governments, public figures and companies and will not be available to you as a regular user. You can change or delete the name at any time, but once it is released, it becomes available to someone else.

Why has the phone number been WhatsApp’s weak point so far?

The phone number as an account identifier had one fundamental flaw: it was permanent, public and used many times outside of WhatsApp itself – in banking, with the operator, in two-step verification systems of other services. Each data leak that included phone numbers automatically gave criminals a ready-made list of potential WhatsApp victims.

How phishers used the phone number – verification code and call forwarding mechanism

A large group of methods is to use the WhatsApp registration process itself, for which a telephone number is required.

Verification code as the easiest way to take over your account

The attacker does not have to break any of WhatsApp’s security measures – he just needs to know the victim’s phone number. The pattern looks like this: the victim’s phone number, a request to register an account on the attacker’s device, a real six-digit code sent by WhatsApp to the victim’s number, a fake website or message prompting him to reveal this code, transfer of the code, account takeover.

The Singapore Police Force described a wave of such attacks in November 2025, in which, after taking over an account, the fraudster sent loan requests to the victim’s contacts, impersonating their credible identity (source). The mechanism is simple precisely because it is based on knowledge of the number and a moment of inattention of the account owner, not on a technical loophole in the application itself.

Call forwarding and USSD codes – limitations of the mechanism

The Indian I4C center warned in December 2025 against fraudsters impersonating couriers who persuaded victims to dial a USSD code starting with *21 and containing a number controlled by the criminal, which activated call forwarding.

It is worth being precise here: call redirection does not mean the automatic transmission of standard SMS messages, and an attack on WhatsApp is possible primarily when the attacker has previously activated the account registration on the victim’s number and chooses to transmit the code in an automatic voice call – WhatsApp officially allows receiving a six-digit code both via SMS and by phone call.

The USSD codes themselves and their operation vary depending on the country, operator and network configuration, so it is impossible to talk about one universal “Whatsapp hijacking code”.

Malicious links, QRLJacking and fake app versions – from WhatsApp Gold to today

The same goal of taking control of an account or device is also achieved without any verification code. QR codes shared in chats can, when scanned, connect the attacker’s device to the victim’s WhatsApp Web session – a technique known as QRLJacking.

The lure of “WhatsApp Gold,” a supposedly enhanced version of the app with additional features, has been circulating on chain messages since at least 2016 and recurs periodically, leading to malware or fake paywalls.

This shows that tricks based on fake updates and links are not new for 2025 or 2026 – only the packaging changes, as in the previously mentioned VBS file campaign described by Microsoft.

Other examples of cyberattacks using WhatsApp

Takeover of group administrator accounts

In a group of parents from a sports team, the administrator asked participants to provide a code supposedly needed to participate in the meeting. In fact, it was a security code for their WhatsApp accounts – an attack that Derbyshire Police and Castle Gresley Parish Council described as a wave of group account takeovers in early 2025 (source). The telephone number of each group member was the account identifier for which the attacker initiated the takeover process, and the group itself provided him with a ready list of subsequent victims and a credible excuse.

GhostPairing – hijacked by a fake pairing link

Gen Digital and Avast researchers described an attack in which the victim received an “I found your photo” message from a friend’s already compromised account, leading to a page imitating Facebook. The site guided her through the legal process of pairing WhatsApp with a new device, so the victim was unknowingly authorizing the attacker’s access (Gen Digital, Avast).

False voting in the competition as bait in a global campaign

Whalebone Threat Intelligence recorded the same pattern as GhostPairing, based on fake voting in the competition, in over 15 countries around the world – mainly in Central and Southern Europe (Czech Republic, Slovakia, Slovenia, Serbia, Romania, Bulgaria, Poland, Croatia), but also in Spain, Italy, Brazil and Mexico – with language variants tailored to local audiences and an extensive phishing infrastructure of over 200 blocked domains (source).

Impersonating loved ones from a hijacked account

A joint bulletin from Sussex Police and Surrey Police described the case of a person from Sussex who received a WhatsApp message from her sister’s compromised account asking for money and lost almost £500 before realizing she was talking to a fraudster (source). The telephone number and the resulting trust in contacts from the friends’ list are crucial here – the victim did not verify the interlocutor because the message came from an account he had known for years.

Malicious files and device infection

Microsoft described a campaign running since the end of February 2026 in which malicious VBS files were sent via WhatsApp, triggering a multi-stage chain of infections and installing MSI backdoors providing remote access to the system (source).

Fake “WhatsApp Security Center”

HKCERT warned in June 2026 against fake “WhatsApp Security Center” websites, which, under the pretext of unblocking an allegedly suspended account, encouraged people to scan a QR code or enter a pairing code (source).

What is WhatsApp phishing

Phishing via WhatsApp is an attack method in which the criminal uses a message, a voice call or a link shared in the messenger to impersonate a well-known brand, institution or person from the victim’s contacts in order to extort personal data, money or access to the account.

It differs from email phishing by several features that work to the advantage of the attacker on WhatsApp:

  1. End-to-end encryption protects the content of conversations from eavesdropping, but at the same time means that WhatsApp cannot automatically scan chats for malicious links or fraudulent text – detecting an attack depends entirely on the recipient.
  2. The messenger is also a space built on trust in close contacts, so a message from a “friend” or “group administrator” arouses less suspicion than an analogous email from an unknown sender.
  3. Additionally, the message is sent to the phone with a real-time notification, which prompts a faster, less thoughtful response than in the case of email.

Phishing via WhatsApp takes many specific forms – from false verification codes and pages imitating a security center, through malicious links and files, to impersonating loved ones from a compromised account. The common denominator of all variants is the use of trust and time pressure to bypass the victim’s common sense, without breaking the technical security of the application itself.

How usernames can reduce phishing on WhatsApp

Username really hinders one specific stage of the attack: the first, unsolicited contact based on knowledge of the phone number itself.

However, it does not protect against account takeover when the attacker already knows the number, has access to the registration code or operates from the account of a person the victim knows and trusts.

What does username actually block?

Auto-dialer bots that massively scan number ranges for active WhatsApp accounts are losing their basic advantage. The number itself is no longer sufficient to establish first contact – an exact username is needed, and if the username key is enabled, an additional code is also needed.

The lack of a directory and contact suggestions also means that you can’t “browse” WhatsApp users like you can browse profiles on other social networking sites.

For victims of mass spam campaigns and first-contact scams, such as fake lotteries or job offers sent to a number from a leaked database, this is a real, measurable barrier.

What username does not block

None of the account takeover cases described earlier would have disappeared based on the username alone.

  • The verification code will still need to be provided if someone falls for it, regardless of whether the sender knows the number or just the username.
  • The pairing code and QR scanning in GhostPairing or the fake “WhatsApp Security Center” work on the victim’s device, not on their phone number.
  • A message from a compromised friend’s account, as in the case described by Surrey Police, reaches the victim regardless of whether he or she sees the number or name – what matters here is the identity of the interlocutor, not the form of his identifier.

In other words, username shifts the threshold for attacks based on anonymous, mass reaching out to numbers, but leaves open a whole category of attacks based on taking over an existing account, which in the source material from 2025-2026 outnumbers classic cold phishing to an unknown number.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579