Cyber Intrusion in Macau: Government Websites Hacked, says Chinese state media
Incident Overview
Earlier this week, the Chinese media reported that several ‘Macau’ government websites were hacked, indicating a significant targeted cyberattack. The hacked website includes those of the office of the Secretary for Security, the public security police, the fire services department and the Security Forces Services Bureau. It was reported that the police have launched a criminal investigation to trace the source of the crime. Furthermore, officials believe the source of the intrusion was likely from overseas, and authorities have carried out an emergency response in conjunction with telecommunication operators to restore affected services on a priority basis. The densely populated Macau is a special administrative region on the south coast of China and the cyber attacks on the essential government website of China raise a serious concern.
Response and Mitigation
Macau's authorities carried out an emergency response in collaboration with telecommunication operators to restore regular services as a distributed denial-of-service attack (DDoS) was reported to be carried out on certain government websites which resulted in the inactivity of those several websites. The country's security forces instructed Macau Telecom to investigate the incident and submit a report and improvement plan to prevent similar attacks in the future.
Context and Implications
The hack on the government websites of Macau is not a single incident; rather, it is a part of an increasing pattern of cyberattacks on the region's vital infrastructure. According to a recent report, the frequency of cybercrimes has tripled since 2020, targeting Macau's critical infrastructure, which is worrying. This pattern draws attention to the growing threats that public sector organisations and governments throughout the world confront.
Final Words
In light of such sophisticated attacks targeting vital infrastructure or critical government operations, it is imperative that the country ensure powerful cybersecurity strategies and measures. Implementing robust cybersecurity measures, developing incident response planning, regular security checks, employee training on cyber hygiene, public awareness and capacity building and international collaboration to jointly develop and plan counteract strategies is a crucial step to build safeguards against such cyber threats.
The incident of a cyberattack on the government websites of Macau serves stark reminder of the evolving threats and cybersecurity challenges, it is a serious concern when critical government websites are compromised by malicious actors. It highlights the necessity for continuous vigilance and cybersecurity measures in place to counter such cyber attacks. A comprehensive approach to cybersecurity, the government can enhance their overall cybersecurity posture, establish resilience against such threats in future, and save the functionality of essential government websites.
References:
- https://macaudailytimes.com.mo/websites-of-office-of-the-secretary-for-security-targeted-in-a-cyber-attack.html
- https://www.reuters.com/world/china/several-macau-government-websites-hacked-says-chinese-state-media-2024-07-11/
- https://4imag.com/several-macau-government-websites-hacked-says-chinese-state-media/
- https://www.aol.com/news/several-macau-government-websites-hacked-001435511.htmlhttps://therecord.media/macau-government-websites-hit-with-cyberattack
- https://macaonews.org/news/city/macau-cyberattacks-cyber-security-attacks-macao/
Related Blogs
.webp)
Introduction
If we look at the concept of scams, they have existed for as long as human societies have. A few decades ago, it was quite common to see scams being carried out in the form of fake landline calls, forged documents or persuasive salesmen. And ‘trust’, being the fundamental aspect of human interaction, has been at the forefront of such interactions. This ‘trust’ factor has been consistently exploited by nefarious individuals all over the world through various acts of deception and a plethora of fraudulent activities.
As the years have gone by, the very same scamming methods have simply shifted mediums. They have transitioned from the geographies of markets and doorsteps to the virtual world of smartphones and digital devices. The senior citizens of today are sitting at a juncture where they come equipped with the ‘habits’ and ‘understanding’ of the offline world. And this is why in today’s technologically driven and fast paced digital environment, they are being targeted via ‘unfamiliar’ digital mediums and tactics, making them highly susceptible to cyber frauds and online scams.
Back in the simpler days, it wasn’t too difficult to catch the whiff of a scammer. One could pick up on their practiced speech patterns, spot their overly polished and formal tone or their sheepish body language and even notice the minute inconsistencies in their statements. This back-and-forth communication would take place in real time, over phone calls and even face to face.
But the scenario today is worse. Since our reliance on digital devices has expanded at an unparalleled pace, it has become all the more difficult to distinguish between what’s fake and what’s genuine. All of a sudden, our entire essential daily activities have become encompassed in the realm of the digital world, ranging from banking, shopping, healthcare to everyday communication. And to further exacerbate the situation, today’s scammers have quietly adapted to this newfound circumstance, as they hide behind screens.
Fake messages or emails can be easily mistaken for being ‘real’ in the current modern digital age. Especially for senior citizens, this shift is presenting a serious challenge. They are being forced to evaluate authenticity and legitimacy through links, messages and apps that basically all look familiar. For example, the logo in an online correspondence might seem to be genuine or its language might look official and credible. At first glance, even the format or the layout of an email or a message may seem familiar enough to not raise any suspicion. This is the point where the danger lies. When there are no warning signs, no rude tones, no spelling errors and no weird behaviour. It becomes very difficult for people to tell what’s real and what’s a trap, especially for the seniors. And in that brief period of confusion, scammers manage to fool people into divulging personal information, clicking dangerous links or even parting with their hard-earned money.
What makes the senior population so vulnerable?
Trapped in the Convenience of Digital Dependence
As the senior population embraces the new and sophisticated digital tools of today, alongside they are also risking their exposure to the online world of cyber security risks and cyber criminals. New devices such as smartphones and tablets do offer unprecedented convenience but they also come with various underlying dangers. Modern technology has made everyday tasks quite easy. Smartphone based UPI applications, bank applications and even online healthcare platforms have simplified life not just for the elderly, but for everyone across society. But many senior citizens may not be as well versed with the usage of these technologies and the digital risks they carry. They may get influenced easily or they may not exercise the same level of caution as the younger generations (who have literally grown up being surrounded by the dynamics of technology). This ‘familiarity gap’ adds up to the vulnerability of seniors. Without any prior visible warning signs they can easily end up getting exposed to online scams, fraudulent transactions and data misuse.
Cybercriminals’ Goldmine: Cash-rich Seniors
Although a person’s vulnerability towards becoming a target or a victim of a cyber crime is mostly shaped by their circumstance and not by age alone. But still, from the point of view of a cyber criminal, senior citizens do seem to be the perfect victims. Most of them are retired and financially sound with lifetime savings, consistent pensions, accumulated assets and anticipated income streams. As they enjoy their solid financial footing, they may not keep a regular check on their online banking accounts and financial records. This ‘financial ease’ can inadvertently make them more prone to cyber crimes, especially when they are simultaneously getting increasingly dependent on digital tools. This lack of oversight may allow suspicious activities or fraudulent transactions to go unnoticed and sometimes even lead to huge losses of money. This is where digital literacy comes in. Keeping the seniors well informed on the safe usage of the internet can significantly lower their chance of getting intertwined in an online scam. It has therefore become crucial to promote and encourage regular account checks, setting up of alerts and foster awareness regarding common online threats that can help seniors safeguard their hard-earned resources.
India itself witnessed an increase of 86% from the years 2020 to 2022 in cyber crime cases related to senior citizens.
Targeting the Psychological Aspects: Panic, Overwhelm, Manipulation and Isolation
Senior citizens are often at an age and stage in life where their routines slow down and the general pace of life shifts towards a gentler rhythm. Thought processes may not be as swift as they used to be, some may even experience mild cognitive decline and many live alone or away from their children or immediate support systems. Research also shows that aging can lead to low memory function which in turn can increase an individual’s susceptibility to digital traps such as phishing emails and financial abuse. According to a comprehensive analysis of senior fraud victims, it has been noted that victimisation increases with advancing age. There are significant associations between fraud victimisation and human cognitive factors, such as: diminished executive functioning, reduced ability of the brain to process information and even impairments in comprehending complex everyday information.
Cybercriminals, who are aware of these soft spots, deliberately exploit the seniors’ psychological and mental space. They strategically deploy methods that create confusion and cognitive overload. They may create a fictitious scenario depicting some kind of ‘urgency’ and use the elderly’s ‘panic response’ to their advantage. They may create false warnings of a blocked bank account, a missed or delayed medical update or inform them of a sudden (but fake) legal issue. They aim at creating a situation of ‘overwhelm, anxiety and severe distress’. And it is common knowledge that when fear encapsulates an individual, the process of rational decision making deeply gets affected. In this scenario elderly victims often fall for the cyber criminals’ malicious antics and end up complying with them without actually verifying their intent and authenticity.
The senior population of the current times was raised in an era where they were rarely taught to question authoritative figures. This is where ‘manipulation’ steps in. The concept of manipulation thrives on the sense of ‘authority, power, position and trust’. Cyber fraudsters use this mechanism and convincingly impersonate government representatives, senior bank officials, healthcare providers, etc. They may project credibility and legitimacy by using authoritative sounding language, creating a sense of power over the victim and manipulating them.
Another important factor that scammers leverage to their advantage is ‘isolation’. A lot of seniors live alone or just with their spouse, with no immediate support systems nearby. They navigate and tread their daily routines on their own, trying hard to adapt to the dynamic digital world. This life of solitude or isolation leaves them in a vulnerable state. They may not even have someone to talk to, or get a second opinion, or even guidance regarding some suspicious online activity that they may be experiencing. This state of isolation combined with their limited digital competence creates the perfect stance for a cybercriminal to manipulate these individuals.
Understanding this psychological dimension has become critical to prevent cyber crimes amongst the elderly. Proper awareness campaigns, reassurance, encouragement of think-and-verify habits can reduce the occurrence of such scams and protect our senior citizens.
Clickbait Cures, Bogus Health Remedies and Expensive False Hopes
It is a known fact that for most senior citizens, their health ranks highest in the list of their priorities. They are always on the lookout for information regarding treatments, medications, dietary supplements and even wellness programs. In an effort to live a healthy and fuller life in this digital age, unknowingly, senior citizens can become easy targets for cybercriminals.
The internet is flooded with eye-catching headlines, ads and clickbaits that promise quick relief and miracle cures. Their wordings may appear like: ‘miracle joint and arthritis relief’, ‘reverse diabetes in seven days’, ‘secret anti-ageing formulas that doctors won’t divulge’, etc. These promises seem all flashy and shiny, but the reality is generally painful. Elderly people can easily get attracted to such ads. Scammers use reassuring language that instantly appeals to the seniors’ attention and their emotions. They create fake doctor profiles or publish fabricated patient reviews with overly dramatised testimonials and false research. In order to seem authentic, some scammers may even use the names and logos of respectable health institutions and organisations such as the ‘World Health Organisation’. They claim to sell products like miracle pills, teas, devices, virtual health services, etc., all at extremely high prices along with pressure inducing statements such as: ‘offer ends tonight’ or ‘only 20 spots left’.
When the elderly fall for this scam and end up paying the amount, either the promised product doesn’t turn up or it proves to be completely ineffective. In worst case scenarios, it may even harm the user’s health. These bogus health products are not regulated by any health association or authority. They may contain unsafe ingredients, incorrect dosages and other toxic substances that can severely impact the elderly’s health. An adverse reaction can take place or an existing medical condition may worsen. What begins as a hopeful step towards better health can eventually lead to loss of finances, physical harm and a deep sense of disappointment and hurt.
Sharing of card details, Adhaar numbers, insurance and medical reports on fake websites can further lead to identity theft and other dangerous cyber crimes.
Protection starts with simple habits. And here families have a big role to play. Making our senior citizens aware of this scenario is the first step. Education brings along ‘awareness’, and with awareness comes ‘caution and confidence’. Teaching the seniors to be wary of any warning signs, to not share any personal or financial details online and to make sure to consult a doctor first before starting any new treatments, are a few ways that can definitely help in reducing the risk of such scams.
Risky Digital Routines: Overexposure and Oversharing
The senior citizens of today are heavily invested in their daily digital routines. They stay virtually connected through various messaging apps (such as WhatsApp), they eagerly curate and maintain their digital identities on online platforms (such as Instagram and Facebook) and they regularly use emails to share messages, articles and forwards within their social circles. Many of us have seen it in our own family groups, that the seniors are the most enthusiastic lot. They are the first to send in their morning salutation messages, photos and other daily updates. This eagerness reflects both their genuine commitment towards staying in touch and also the pure joy that they derive from being active members of these online communities. It is important to understand that these platforms don’t just serve as mere communication tools for them. Beyond messaging and sharing of updates, these online spaces offer a sense of community, belongingness and self-expression to the elderly.
But these everyday digital routines can cause an overexposure to the virtual world which further creates opportunities for scammers. Clicking on unfamiliar links, downloading unknown softwares and giving quick responses to alerts and notifications (without first identifying the source), are a few examples of how seniors end up getting embroiled in risky situations. At the same time, online oversharing of personal details such as addresses, birthdays, travel plans, family updates, phone numbers, even investment plans, etc., can seem to be quite harmless on the face of it. But all of this information builds a goldmine for the scammers. They may be able to piece it together and use it to send highly convincing phishing emails, create fake online offers or even impersonate a loved one.
Senior citizens also tend to take online messages at face value. AI generated videos, images, false news, etc., are all generally shared under the garb of sensational claims or urgent warnings and are therefore easily assumed to be true, especially by the elderly. They may not even take a minute to factcheck the information and instead may forward it to ten other people in their circle.
The above risks can significantly be reduced by practicing safer digital habits. Seniors should be mindful in their digital usage. Pausing and thinking before clicking on a link, fact checking a piece of news, using strong privacy settings and trusted apps, etc., can help protect both their personal data as well as their digital wellbeing.
Silent Suffering: Shame, Underreporting and Systemic Gaps
Research suggests that senior citizens do not always report a cybercrime. This can be due to shame, self blame, ridicule, fear of being judged as incompetent and a general opinion that even if they report it, nothing will come out of it. They may feel embarrassed about getting deceived, believing that they should have known better. This may create an emotional burden which further amplifies underreporting. Informing their family members or just reaching out for some help can seem like a mammoth task for them.
Existing institutional gaps in our systems compounds this silent suffering. While there are law enforcement and consumer protection agencies in place, but the first step, which is the ‘reporting mechanism’, can seem to be inaccessible or too overbearing for the seniors. These systems may not have a very proactive outreach and can fail to tackle the distinct set of challenges faced by the seniors (such as clear guidance on scams or support for recovering lost funds).
This combination of ‘shame, underreporting and weak system support’ creates a dangerous cycle. Senior citizens are left as open prey, exploited and repeatedly targeted without sufficient help or any recognition for their plight.
The Way Forward
Society has to first acknowledge and identify the inimitable vulnerabilities of the seniors. This cycle can be broken by developing information drives that are specially tailored for the seniors. Moreover, along with family involvement, user friendly reporting channels and stronger protections from fraudulent online practices, seniors can see a ray of hope.
Targeted training programs, senior friendly cybersecurity workshops and courses can be a starting point. Teaching them about password creations, safe browsing tactics, phishing recognition and specific mentor-led sessions can empower them with the basic understanding of the online world.
Being able to navigate the digital world with adequate competence and confidence, and without the fear of exploitation, is ultimately what every senior citizen needs.
References
- https://www.staysafeonline.org/articles/why-do-scammers-target-older-adults
- https://pmc.ncbi.nlm.nih.gov/articles/PMC12074955/
- https://cybersecurityasia.net/rise-cyber-crime-targeting-older-adults/
- https://news.ufl.edu/2024/06/older-adults-vulnerable-to-scams/
- https://oklaw.org/resource/why-are-older-people-vulnerable-to-scams
- https://www.crimrxiv.com/pub/g7u4rb9v
- https://www.norc.org/research/library/majority-of-older-adults-experience-cyber-abuse-in-their-lifetim.html
- https://www.sbigeneral.in/blog/cyber-insurance/cyber-tips-and-tricks/how-senior-citizens-can-avoid-internet-scams

Digital vulnerabilities like cyber-attacks and data breaches proliferate rapidly in the hyper-connected world that is created today. These vulnerabilities can compromise sensitive data like personal information, financial data, and intellectual property and can potentially threaten businesses of all sizes and in all sectors. Hence, it has become important to inform all stakeholders about any breach or attack to ensure they can be well-prepared for the consequences of such an incident.
The non-reporting of reporting can result in heavy fines in many parts of the world. Data breaches caused by malicious acts are crimes and need proper investigation. Organisations may face significant penalties for failing to report the event. Failing to report data breach incidents can result in huge financial setbacks and legal complications. To understand why transparency is vital and understanding the regulatory framework that governs data breaches is the first step.
The Current Indian Regulatory Framework on Data Breach Disclosure
A data breach essentially, is the unauthorised processing or accidental disclosure of personal data, which may occur through its acquisition, sharing, use, alteration, destruction, or loss of access. Such incidents can compromise the affected data’s confidentiality, integrity, or availability. In India, the Information Technology Act of 2000 and the Digital Personal Data Protection Act of 2023 are the primary legislation that tackles cybercrimes like data breaches.
- Under the DPDP Act, neither materiality thresholds nor express timelines have been prescribed for the reporting requirement. Data Fiduciaries are required to report incidents of personal data breach, regardless of their sensitivity or impact on the Data Principal.
- The IT (Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, along with the Cyber Security Directions, under section 70B(6) of the IT Act, 2000, relating to information security practices, procedure, prevention, response and reporting of cyber incidents for Safe & Trusted Internet prescribed in 2022 impose mandatory notification requirements on service providers, intermediaries, data centres and corporate entities, upon the occurrence of certain cybersecurity incidents.
- These laws and regulations obligate companies to report any breach and any incident to regulators such as the CERT-In and the Data Protection Board.
The Consequences of Non-Disclosure
A non-disclosure of a data breach has a manifold of consequences. They are as follows:
- Legal and financial penalties are the immediate consequence of a data breach in India. The DPDP Act prescribes a fine of up to Rs 250 Crore from the affected parties, along with suits of a civil nature and regulatory scrutiny. Non-compliance can also attract action from CERT-In, leading to more reputational damage.
- In the long term, failure to disclose data breaches can erode customer trust as they are less likely to engage with a brand that is deemed unreliable. Investor confidence may potentially waver due to concerns about governance and security, leading to stock price drops or reduced funding opportunities. Brand reputation can be significantly tarnished, and companies may struggle with retaining and attracting customers and employees. This can affect long-term profitability and growth.
- Companies such as BigBasket and Jio in 2020 and Haldiram in 2022 have suffered from data breaches recently. Poor transparency and delay in disclosures led to significant reputational damage, legal scrutiny, and regulatory actions for the companies.
Measures for Improvement: Building Corporate Reputation via Transparency
Transparency is critical when disclosing data breaches. It enhances trust and loyalty for a company when the priority is data privacy for stakeholders. Ensuring transparency mitigates backlash. It demonstrates a company’s willingness to cooperate with authorities. A farsighted approach instils confidence in all stakeholders in showcasing a company's resilience and commitment to governance. These measures can be further improved upon by:
- Offering actionable steps for companies to establish robust data breach policies, including regular audits, prompt notifications, and clear communication strategies.
- Highlighting the importance of cooperation with regulatory bodies and how to ensure compliance with the DPDP Act and other relevant laws.
- Sharing best public communications practices post-breach to manage reputational and legal risks.
Conclusion
Maintaining transparency when a data breach happens is more than a legal obligation. It is a good strategy to retain a corporate reputation. Companies can mitigate the potential risks (legal, financial and reputational) by informing stakeholders and cooperating with regulatory bodies proactively. In an era where digital vulnerabilities are ever-present, clear communication and compliance with data protection laws such as the DPDP Act build trust, enhance corporate governance, and secure long-term business success. Proactive measures, including audits, breach policies, and effective public communication, are critical in reinforcing resilience and fostering stakeholder confidence in the face of cyber threats.
References
- https://www.meity.gov.in/writereaddata/files/Digital%20Personal%20Data%20Protection%20Act%202023.pdf
- https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- https://chawdamrunal.medium.com/the-dark-side-of-covering-up-data-breaches-why-transparency-is-crucial-fe9ed10aac27
- https://www.dlapiperdataprotection.com/index.html?t=breach-notification&c=IN

Introduction
For more than 10 years, WhatsApp has been designed around one seemingly trivial but impactful idea: your phone number is your digital identity. This concept offered simplicity in terms of contact discovery and onboard- ing but inevitably exposed users to fraud, spam and the everyday necessity of sharing personal phone numbers with complete strangers in group chats and conversations. On June 29th Meta finally revealed a major move: you’ll now be able to choose and reservate a WhatsApp username and communicate without sharing your phone number.
This shift to a username based identity marks the company catching up to platforms like Telegram and Signal, which have utilized this functionality for years.
However, while presented as a push towards greater privacy for the millions using its platform, this new change has already created some alarm around impersonation, cybersquatting, and identity theft. The issues became amplified when, according to reports, the Indian Ministry of Electronics and Information Technology advised WhatsApp to halt the implementation of the new features while it clarifies details, shifting a mundane app update into a high-stakes discussion on digital privacy, platform responsibility, and government regulation.
How does the mechanism work?
“WhatsApp’s username is an added pseudonym layer on its current phone number architecture, not a replacement,” Meta said in a statement on Thursday, as reported by TechCrunch. A WhatsApp username is a three to 35-character name containing lower case letters, numbers, periods and underscores that must contain at least one letter and “should not look like a website address.” The feature will allow you to “reserve a unique identifier that you can share as an alternative to your phone number in WhatsApp Settings - Accounts - Username.”
It said the usernames will work in parallel with a username key which can serve as a passphrase to initiate conversation “with a recipient before sending a message for the first time.”
“The change - which will have some additional, protective measures like reserving usernames for people of public interest or those that would cause impersonation, and rate limits on claiming names - can help maintain phone number protection, while offering people more choices,” Meta said. WhatsApp said usernames will replace phone numbers as the primary way to initiate new chats, but will not be publicly searchable: “Anyone you message would need your exact username, and would still need you to respond.”
The Genuine Privacy Case
The upside is real. Phone numbers double as keys to two-factor authentication, banking apps and SIM-swap fraud, so handing one to a new acquaintance, a group chat of strangers or a customer-support bot has always carried quiet risk. Numbers harvested from public groups already fuel spam and scam campaigns, and a username-first model narrows that exposure considerably.
For journalists, small business owners and anyone who fields messages from people they've never met, decoupling identity from a number that also unlocks their bank account is a meaningful, overdue shift – and one that WhatsApp's closest competitors adopted years ago without major incident.
The Scammer's Paradise Scenario
The trouble lies in what a username removes. A phone number was never just an identifier; it was also a rough verification signal and, for law enforcement, a traceable data point. Security reporters testing the reservation system found that lookalike handles mimicking prominent Indian politicians, film stars and the Reserve Bank of India remained available to claim. Crypto executive Changpeng Zhao's own failed bid to capture his desired handle highlighted the first-come, first-served danger of the rollout and led researchers to advise people to manually activate the optional username key that Meta leaves disabled by default.
The Mozilla Foundation was unvarnished about the tradeoff, noting that impersonation from fake accounts and scams are an “inevitable consequence” of a design that abandons the “implicit signal of authenticity” that comes from owning a phone number.
Indian entrepreneur Ankur Warikoo called the rollout a potential “disaster” if robust enforcement against fraud isn’t immediately applied because scammers could register handles a few characters removed from a popular brand or public figure to launch investment and payment schemes, a concern mirrored by cyber security researchers who observed that many users neglect to check verification badges before trusting an account.
India's Regulatory Scrutiny of WhatsApp's Username Feature
So far the strongest reaction comes from New Delhi. The Ministry of Electronics and Information Technology (MeitY) issued an official notice to Meta's compliance office that it should “temporarily suspend the feature” in the country pending further consultations and “provided an explanation in three days”. The cited concerns involve “digital arrest” fraud, a rapid boom category that involves crooks impersonating investigators like those with India's CBI, judges or customs agents to extort victims, in addition to standard concerns around phishing and bank or government impersonation.
A subtler concern, for India’s government anyway, is “traceability.”
At present, say officials, an Indian mobile number is a launching pad to determine whether a given suspect is a domestic or international actor, while a username and foreign SIM would leave authorities nowhere to begin. The Department of Telecommunications independently voiced concerns over how the change intersects with its SIM-binding regulations and over WhatsApp's lag time for such requests. The MeitY notice, the legal basis for which, incidentally, is in contention with some digital rights groups, specifically invokes Section 79 of the IT Act and various IT Rules from 2021 and provisions on identity theft and impersonation that target individual criminals rather than the tech tools. Not everyone, however, shares MeitY’s reading of the legal ground: the Internet Freedom Foundation says that Section 79 “deal with liability of intermediary” and “does not confer on the government power to license the features of a product,” while arguing the relevant criminal statutes were designed to criminalize impersonators, not tech platforms whose services are misused, echoing concerns that killed a similar government advisement about AI models last spring.
In the meantime, Meta says usernames are unavailable in the country for now and the multilayered safeguards it designed were always intended for exactly this level of risk.
Conclusion
WhatsApp's username feature is neither a total privacy upgrade nor a major security problem; instead, it reallocates risk, reducing phone number exposure while adding a risk of identity spoofing and misuse. Whether it pays off will hinge on the strength of Meta's crackdown on fraudulent usernames, the uptake of extra security features like the username key and whether the company can adequately satisfy regulatory concerns about traceability and user safety. Until all those questions are fully settled, users may want to use the feature tentatively, secure a desired username, enable any other protections and be watchful about new contacts.
References
- https://blog.whatsapp.com/its-time-to-reserve-your-whatsapp-username
- https://www.businesstoday.in/technology/news/story/whatsapp-usernames-why-indias-top-creators-fear-scams-impersonation-and-identity-theft-540359-2026-07-02
- https://www.outlookindia.com/national/outlook-explains-why-is-the-indian-government-worried-about-whatsapp-usernames
- https://techcrunch.com/2026/06/29/whatsapp-now-lets-you-reserve-usernames/
- https://bestmediainfo.com/mediainfo/mediainfo-digital/whatsapp-says-username-feature-not-live-yet-after-meity-asks-meta-to-pause-rollout-12124813