Featured Article : Fraud Fears Over New WhatsApp Usernames

WhatsApp’s plan to let people communicate without revealing their phone numbers has run into immediate regulatory opposition in India, turning what began as a new privacy feature into a much wider debate about online anonymity, fraud and how messaging platforms should balance privacy with security.

Give Your Username Instead Of Your Phone Number

WhatsApp has begun allowing users to reserve unique usernames ahead of a wider rollout planned for later this year. The idea is that, under a new system, WhatsApp users will be able to give someone a username instead of their mobile phone number, meaning they can communicate without revealing the number connected to their account.

WhatsApp explained the reason for the feature, saying: “Sometimes you just want to chat without handing over your digits.”

That could be particularly useful, for example, when joining community groups, meeting someone at an event, communicating with a business or speaking to someone online for the first time.

WhatsApp says the reservation process is being opened gradually because the platform has more than three billion users and many people will inevitably want similar names. Once the option becomes available, users can reserve a name through the Account section of the app’s settings.

How Will Usernames Work?

The feature is designed to provide greater privacy without making WhatsApp users publicly searchable.

It’s understood that there will be no directory of usernames and no suggestions showing people they might want to contact, and someone will need to know the exact username before they can start a conversation.

And A Key

Users will also be able to create an optional username key, providing another layer of protection against unwanted contact.

Once the full feature launches, people who have enabled a username will be able to message a new person or business without their phone number being displayed. However, a mobile number will still be required to create a WhatsApp account in the first place.

For creators, businesses and organisations that want a consistent identity, WhatsApp has also created a way to claim an existing Instagram or Facebook username.

Why Has India Intervened?

However, it seems the rollout quickly attracted regulatory attention in India, WhatsApp’s largest national market.

The Indian government has asked WhatsApp to pause the introduction of usernames in the country while consultations take place, amid concerns that the feature could make fraud, phishing and impersonation easier.

The main concern is that criminals could create usernames resembling those of banks, government departments, businesses or well-known individuals and then use them to contact potential victims without displaying a phone number.

This is particularly significant in India, where authorities have been trying to combat a growing problem with cyber fraud, including so-called digital arrest scams in which criminals impersonate police officers or government officials.

The government intervention came shortly after WhatsApp opened username reservations, transforming the launch from a straightforward product announcement into a test of how privacy features should be balanced against fraud prevention and law enforcement concerns.

What Does WhatsApp Say About The Risks?

WhatsApp argues that it has already built several layers of protection into the system.

High-profile usernames associated with public figures, government bodies, celebrities and verified Meta accounts have been reserved so that they can only be claimed by legitimate owners. The company says variations of well-known names are also being protected.

WhatsApp has also said it will limit the number of new people an account can contact, prevent repeated attempts to guess username keys and use its systems to identify common patterns associated with impersonation and abuse.

Recipients of messages from first-time contacts will also be given contextual information, such as whether the sender has a new account, shares mutual groups with them or is based in another country.

The company says: “We’re taking our time and listening to feedback so that when it rolls out later this year we get it right.”

A Genuine Privacy Benefit

Despite the controversy, there does seem to be quite a clear privacy argument for introducing usernames.

For example, phone numbers are increasingly used as identifiers across banking, online accounts, two-factor authentication and other digital services. Giving one to a stranger can therefore reveal more personal information than someone may realise.

Usernames provide a way to separate someone’s WhatsApp identity from their mobile number, making it easier to communicate with new contacts without immediately sharing that information.

This is particularly relevant for business networking, online marketplaces, community groups, customer enquiries and other situations where people may want to communicate without establishing a deeper personal connection.

WhatsApp summarises the thinking behind the feature by saying: “A phone number is personal and it’s tied to so many parts of your life.”

However, the challenge is that privacy features that protect genuine users can also potentially make life easier for criminals. The debate is therefore not simply about whether usernames are good or bad, but whether platforms can introduce stronger privacy without weakening trust and accountability.

What Does This Mean For Your Business?

For businesses, the introduction of WhatsApp usernames could make the platform more useful for customer communication. Employees may be able to speak with customers, suppliers or new contacts without sharing personal mobile numbers, while businesses could create a more consistent identity across WhatsApp, Facebook and Instagram.

However, the fraud concerns raised by the Indian government also highlight the growing importance of digital identity verification.

If usernames become widely used, businesses may need to be more careful about how customers identify genuine accounts. Criminals already impersonate banks, suppliers, senior executives and well-known brands, and convincing username variations could create another opportunity for social engineering.

Organisations using WhatsApp for customer service may therefore need to communicate clearly which accounts are genuine, while employees should be trained not to assume that a familiar-looking username proves someone’s identity.

The wider story here is really about the difficult balance between privacy and trust. Hiding phone numbers can protect users from unwanted exposure, but every new layer of anonymity can also create opportunities for abuse.

WhatsApp’s challenge is to prove that usernames can provide meaningful privacy without making impersonation and fraud easier. How that balance is achieved could influence not only the future of WhatsApp, but also how messaging platforms around the world design privacy features in the years ahead.

Featured Article : Historic Global Leak : 16 Billion Logins Exposed

A massive trove of stolen usernames and passwords totalling 16 billion records has been discovered across 30 newly uncovered databases, revealing one of the largest and most dangerous credential breaches ever recorded.

Two Login Credentials for Every Person on Earth

Security researchers at Cybernews have uncovered an unprecedented cache of login data scattered across unsecured web databases. These exposed collections, some open to the internet only briefly, were mostly hosted on misconfigured Elasticsearch instances or cloud object storage services, making them accessible without authentication.

All but one of the 30 datasets involved in the breach had not been reported previously. Combined, they include roughly two login credentials for every person on Earth!

A Blueprint For Mass Exploitation

“This is not just a leak – it’s a blueprint for mass exploitation,” said the Cybernews team, who have been tracking the breach since early 2024. “The structure and recency of these datasets make them particularly dangerous.”

From Apple, Google, Facebook, and More

While large-scale data breaches have become disturbingly common, this incident stands out for the freshness of the data and the scope of what’s included. For example, Cybernews has reported that the breach includes login credentials drawn from a huge range of services including Apple, Google, Facebook, GitHub, Telegram, VPNs, and even government portals.

More Than Just Usernames and Passwords

The datasets primarily consist of credentials stolen by infostealers, i.e. a type of malicious software designed to extract sensitive information from infected computers. Once installed (often via phishing emails, fake software updates, or pirated software), infostealers scan the victim’s device for stored logins, cookies, authentication tokens, and autofill data. These details are then quietly sent back to attackers’ servers.

In most cases, Cybernews reports that the stolen data is structured in a familiar format, i.e. the website URL, the username or email address, and the associated password. Some records are reported to include extra metadata, such as session cookies or two-factor authentication tokens, which can significantly aid attackers in bypassing security protections.

Cybernews estimates that some overlap exists between datasets, but even conservative estimates suggest billions of distinct login records are involved. The largest single collection, linked to a Portuguese-speaking population, holds over 3.5 billion records. Others are named generically (such as “logins” or “credentials”) while some reference specific services like Telegram or locations such as the Russian Federation.

Who’s Behind It and Who’s Affected?

It appears that the origin of these leaked datasets remains murky. Although some may have been compiled by cybercriminals intent on launching mass-scale phishing or credential stuffing attacks, others could belong to grey-hat researchers, aggregating leaked data for academic or threat intelligence purposes. However, it should be noted that the absence of clear attribution makes them no less dangerous.

Cybersecurity experts have warned that even if only a fraction of the 16 billion records are actively exploited, the consequences could be severe. Identity theft, business email compromise (BEC), unauthorised access to cloud services, ransomware attacks, and financial fraud are all plausible next steps.

A significant concern is that many users still reuse the same password across multiple sites (known as ‘password sharing’). Attackers often employ credential stuffing, a tactic that involves testing stolen username/password pairs against a wide range of sites, hoping users have reused credentials elsewhere.

The impact is not likely to be just limited to individual consumers. Businesses, particularly those lacking multi-factor authentication (MFA) or modern password management protocols, are at risk of full-scale account takeovers. These in turn could lead to data theft, service disruption, or reputational damage.

What Tech Companies and Security Experts Are Saying

So far, most affected companies have not issued individual statements, probably because the breach is not tied to a specific platform or service – the leak is an aggregation of credentials siphoned off via malware over time.

However, the Cybernews team and other researchers have voiced serious concern. “Credential leaks at this scale are fuel for phishing campaigns, ransomware intrusions, and business email compromise,” the team said in its public briefing. “The inclusion of both old and recent infostealer logs – often with tokens, cookies, and metadata – makes this data particularly dangerous for organisations lacking multi-factor authentication or credential hygiene practices.”

Security vendor Malwarebytes described the incident as “a wake-up call” for both users and companies. “This is a stark reminder that infostealer malware remains an enormous threat and that misconfigured cloud services continue to expose sensitive data at scale.”

More of a ‘Combolist’

Some experts have cautioned against treating the breach as a single event, noting that it is better understood as a massive combolist, i.e., a curated aggregation of multiple smaller leaks. Even so, the potential for harm remains high.

Why This Breach Is Different and What Comes Next

Unlike older breaches which often contain outdated or previously exposed data, these records are mostly new. Only one of the 30 datasets had been reported before (a 184 million-entry trove covered by Wired in May). The rest have emerged only recently, some in the last few weeks, suggesting that infostealer activity is ongoing and highly active.

Not Indexed Yet

At the moment (it’s still early days since the discovery), compounding the risk is the lack of visibility. Many of the exposed credentials have not yet been indexed by breach monitoring services or browser alert systems, meaning users aren’t being automatically notified if their details are among those leaked.

Also, because the databases were reportedly only briefly exposed, researchers say they could not determine who held or uploaded the data, nor whether it has already been downloaded or traded on criminal forums.

What Should Users and Businesses Do Now?

For individual users, the recommendations are fairly straightforward but urgent and they probably echo most of the points of security good practice around breaches. For example:

– Immediately change passwords on any accounts using duplicated or weak credentials.

– Use a password manager to generate and store complex, unique passwords for every service.

– Enable multi-factor authentication (MFA) wherever possible.

– Monitor for phishing emails or unusual account activity, especially logins from unfamiliar locations or devices.

– Run antivirus and anti-malware tools to scan for potential infostealers on your system.

For businesses, the stakes are higher. Implementing stronger access controls, requiring MFA across all services, and deploying endpoint detection tools are worthwhile steps. Regular audits of privileged access accounts, secure cloud configurations, and employee training on phishing threats are also essential.

Experts also recommend checking employee and corporate credentials against breach monitoring services such as Have I Been Pwned or Cybernews’ Leaked Database Checker.

Could Big Tech Be Doing More?

Looking at where many of these stolen credentials came from, it’s perhaps not surprising that there is growing pressure on tech platforms to go beyond offering MFA as an optional feature. Some experts are calling for default-on MFA policies, improved session token management, and better user alerts for credential misuse. Others suggest that browser makers could more aggressively warn users about unsafe passwords, even when stored locally.

Cloud service providers also face scrutiny. For example, misconfigured storage services remain a recurring source of data exposure and security researchers have long warned that businesses often fail to understand the shared responsibility model of cloud hosting, which places the burden of securing customer data squarely on the organisation using the service, not the cloud provider itself.

Combined for Weaponisation

This breach essentially demonstrates how aggregated, seemingly disparate data leaks can combine to form a vast, weaponisable archive of credentials. Also, without rapid, coordinated responses from users, businesses, and tech providers alike, the consequences may stretch far beyond compromised passwords.

What Does This Mean For Your Business?

The sheer scale and structure of this breach underline how fragile the global system of digital identity has become. With 16 billion credentials exposed, many of them recent, unrecycled, and complete with cookies and tokens, the barrier to entry for cybercriminals appears to have been lowered dramatically. This isn’t just an escalation in volume, it’s a shift in the quality and usability of stolen data. For attackers, this is a ready-made toolkit for highly convincing phishing, large-scale account takeover attempts, and social engineering operations that could target everyone from individual users to senior staff within high-profile organisations.

For UK businesses, the risks are not theoretical. Any organisation with staff using shared or recycled passwords, without enforced multi-factor authentication, could find themselves an easy target. For example, compromised employee accounts can quickly open doors to sensitive systems, intellectual property, financial accounts or customer data. The consequences are likely to include financial loss, regulatory penalties, and long-term reputational damage. This is especially pressing for sectors handling critical infrastructure or customer data, such as healthcare, education, local government and law firms.

The fact that so many of the datasets were discovered in misconfigured online storage shows how easily even vast amounts of sensitive information can be left vulnerable. This again raises questions about internal security practices, not just among cybercriminals, but among businesses and developers failing to properly secure cloud environments. As more breaches emerge from poor cloud hygiene, regulators may well move to demand greater accountability and oversight from cloud service providers and their clients.

For security professionals and digital privacy advocates, this breach reinforces the need to accelerate the move away from passwords altogether. Passkey adoption, hardware-based authentication, and biometric alternatives are already gaining traction, but the pace remains slow. Meanwhile, tools such as credential stuffing bots and AI-enhanced phishing make password-only systems increasingly outdated and risky.

The discovery also points to a deeper issue around breach notification and public awareness. Because these credentials were collected silently through infostealers and surfaced only when aggregated by researchers, the victims (both users and the platforms their data was stolen from) may have no idea they were compromised. With no clear breach event to attribute, many companies are, therefore, unlikely to report or even detect the loss. This leaves users exposed and unprepared, and it puts the onus on breach checkers and independent researchers to close the gap.

This incident serves as a stark reminder that security needs to be proactive, not reactive. Businesses should no longer view breaches as isolated events but as part of an ongoing data extraction economy that thrives on delay, misconfiguration and user complacency. Whether you’re a multinational tech firm, a regional employer, or an individual internet user, the threat landscape has shifted again and this time, the scale is difficult to ignore.