From identifier to secret
What WhatsApp usernames and M-Pesa's masked numbers have in common.
On July 1, India's IT ministry ordered WhatsApp not to roll out its new username feature until consultations are complete, and gave the company three days to explain itself. The ministry's concern is impersonation: usernames, it argues, could be used to spoof individuals, financial institutions and government agencies, and Indian law requires messaging accounts to be bound to a verified phone number. Meta responded that it has impersonation protections in place and has reserved the names of public figures and institutions. The dispute is developing.
Behind the standoff is a quieter shift. The phone number, the thing that has identified us to each other for decades, is being pushed out of view. And not everyone agrees it is safe.
This is happening on two layers at once. In March, Safaricom began masking the sender's phone number in M-Pesa transaction messages, showing names but hiding the digits, a CBK-approved change made under Kenya's Data Protection Act to stop fraudsters harvesting numbers from alerts and posing as agents to extract PINs. In June, WhatsApp opened reservations for usernames, with the full feature arriving later this year: no public directory, contact by exact match only, an optional username key, and high-profile names held back against impersonation.
The money layer and the messaging layer are moving the same direction. The phone number is being demoted from a public identifier that announces who you are, to a private credential that sits in the background and verifies you. It is not going away. It is going out of view.
The privacy gain is real, and it may matter more here than anywhere. On M-Pesa the phone number is bound to your national ID and the phone is your wallet, so a harvested number is not just a nuisance, it is a door into your money. Hiding it closes a working fraud channel.
But India has named the catch. Its rules bind accounts to verified numbers precisely because a number tied to an ID is hard to fake, and a name you choose is not. Security researchers are already warning users not to reuse their Instagram or X handles on WhatsApp, because doing so rebuilds the very exposure the feature was meant to remove. The same decoupling that protects you is what makes impersonation easier.
If the phone number is quietly retired as the thing that identifies us, what becomes the anchor of trust in its place, and is a name we choose harder to steal than a number we were assigned?
India directive: Reuters, read via Yahoo Finance and U.S. News republications, corroborated by The Tribune/ANI and WION; independently confirmed by CNBC, with AFP coverage read via republications (July 2, 2026). The situation is developing. M-Pesa masking: Capital FM/Capital Business and TechCabal (March 2026). WhatsApp usernames: AP and Al Jazeera. M-Pesa KYC: Safaricom and World Bank documentation. Handle-reuse warnings: Bitdefender, as reported by RTÉ.