The images in this article were generated with artificial intelligence. How we publish
WhatsApp has opened this week the possibility of booking user names on a global scale, a novelty that aims to allow more than three billion users to connect without sharing their phone number publicly. The company explains that the function is optional and that the names should be reserved from the app (Settings > Account > User Name) before their general deployment, and that there will be no public directory or suggestions to look for them: only someone who knows exactly your name will be able to contact you for the first time.
In practical terms, this represents a paradigm shift in the way people and organizations identify themselves in WhatsApp: no longer need to give the phone number to start a conversation, which reduces direct exposure risks and facilitates the management of privacy in relationships with clients, followers or occasional contacts. For creators and small businesses there is also the option to claim the same identifier they use on Instagram or Facebook, which promotes brand coherence.

The platform adds an additional measure called "username key," which acts as a second key to accept initial contacts: Whoever wants to write you needs to know your exact name and that key the first time. WhatsApp will also allow a name generator to help choose available and unique identifiers, and will offer the possibility to reset the key to cut new incoming contacts at any time.
From a cybersecurity perspective, the initiative has real advantages, but also new vectors to monitor. The reduction of direct number exposure makes it difficult to doxxing and some types of call-based fraud or SMS, but it opens the door to username identity supplanting, phishing or squatting campaigns - a preventive record of valuable names - if not accompanied by verification and good practices by WhatsApp and users.
In order to minimize personal and professional risks, several precautions should be taken: reserve the name you use publicly as soon as possible, activate the username key if you want to control who writes and enable verification in two steps in your account. In addition, it avoids public publication of the key, reviews privacy permits in Adjustments and maintains an internal policy in organizations to coordinate who and how it shares official identifiers.
The creators and brands should take advantage of the possibility to claim the same hands on different platforms, but to do so in a safe way: to associate the name to official channels verified on websites and networks, to monitor impersonation attempts and, in case of abuse, to document and report quickly to WhatsApp and alternative platforms. Preventive registration of essential names can save reputation and digital extortion problems.

It is relevant to place this novelty in a larger context: Signal has long introduced a similar functionality with the aim of protecting phone numbers, and now WhatsApp incorporates a comparable solution within its massive ecosystem. The change does not eliminate the technical link between number and account on WhatsApp's servers, but it does promise to reduce public exposure of the number to unknown.
If you want to read the official WhatsApp ad and check technical and availability details in your country, see the official WhatsApp blog page at https: / / blog.Whatsapp.com. For journalistic monitoring and security analysis of this and other messaging functions, specialized media such as The Hacker News keep up-to-date coverage in https: / / thehackernews.com, and organizations dedicated to privacy offer practical guides that can help you set up your account safely, for example the Electronic Frontier Foundation at https: / / www.ef.org.
In short, the user name functionality of WhatsApp can improve privacy and facilitate communication without exposing the phone, but its effectiveness will depend on both platform design decisions and user behavior: book and protect your name, use the key if you need strict contact control and strengthen your account security to avoid surprises.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...