New Delhi: Amid the Government of India's move to halt the rollout of WhatsApp's username feature over fraud concerns, Meta has dismissed rumours that popular or well-known usernames are being reserved by random users.

WhatsApp has asserted that usernames related to well-known public figures can only be reserved by their legitimate account owners.

The clarification came as part of a set of FAQs released by the Meta-owned messaging platform regarding its proposed username feature, which has come under scrutiny over concerns of impersonation and fraud.

"A few more things to keep in mind… People are making false claims about reserving popular or well-known usernames — this isn't true. Only the legitimate account owners are able to reserve well-known public-figure names," WhatsApp said in the FAQs.

On Wednesday, the Centre issued a notice to Meta over the planned feature, citing concerns that it could materially increase online fraud, phishing, digital arrest scams and impersonation attacks. It directed the platform to pause the rollout until consultations on the issue are completed "to the satisfaction of the Government."

AAP leader says variations of his name already reserved

India is a key market for WhatsApp, with the messaging platform having more than 500 million users in the country.

Several prominent personalities recently took to X to express concerns after discovering that many variations of their names had already been reserved during the ongoing username reservation phase.

Former Delhi Deputy Chief Minister Manish Sisodia said in a post on X that he was surprised to find that "almost every variation" of his name, along with that of his party, the Aam Aadmi Party (AAP), appeared to have already been reserved.

Similarly, MobiKwik Co-founder and CEO Bipin Preet Singh said close variations of his name had also been taken during the early reservation window.

WhatsApp's proposed username feature has raised concerns among cybersecurity experts and users, who believe it could trigger a surge in impersonation, spoofing and financial fraud.

In its notice, the government said the feature may "materially increase" cases of online fraud, phishing, digital arrest scams and impersonation attacks by enabling bad actors to contact and deceive users. It has asked Meta to explain why action should not be initiated under the Information Technology Act and the relevant rules over the proposed feature, which could potentially increase cybercrime.

The Centre also reminded Meta that WhatsApp, as a Significant Social Media Intermediary (SSMI), is bound by due diligence obligations under the Information Technology Act and its rules.

WhatsApp claims built-in safeguards prevent scams and impersonation

Responding to the concerns, WhatsApp defended the feature, saying it has built-in safeguards to prevent scams, impersonation and other forms of abuse.

A WhatsApp spokesperson said the username feature is not yet live and will be be rolled out gradually later this year.

"To protect against impersonation, we've held the highest-profile names — including those of public figures, government entities, celebrities and verified Meta accounts — so they can only ever be claimed by their legitimate owners. Lookalike derivatives of known names are also reserved," the spokesperson said.

Users will still need a phone number to use WhatsApp, Meta said, adding that multiple layers of protection have been built into the username system.

"Other users need to know your exact username to message you. We will limit how many new people an account can contact, block repeated attempts to guess someone's username key, and have systems to detect and remove activity showing common impersonation and abuse patterns," the company said.

WhatsApp also said users will be shown whether a first-time sender is using a new account, is an existing contact, shares a mutual group or is messaging from another country before they choose to respond.

"When the feature becomes available and someone sends you a message for the first time using your username, we will show you whether they're using a new account, whether they're your contact, whether you have groups in common and whether they're based in another country, so you can decide whether to respond," the company added.

Meanwhile, the Internet Freedom Foundation (IFF) criticised the Centre's notice, arguing that it has no clear legal basis.

"It is an attempt by the executive to decide what a company may build and ship, which no statute permits," the digital rights advocacy group said.

In a social media post, the IFF added: "The notice treats the launch of a lawful feature as a wrong the company must justify. That reverses the ordinary position, especially given the absence of any clear legal power. MeitY does not name any provision that allows it to approve a product feature before release or order it to be withdrawn because no such provision exists."