The Indian government has introduced new regulations requiring messaging apps such as WhatsApp, Telegram, Signal, and Snapchat to operate only with active SIM cards linked to users’ phone numbers. This move is intended to curb the rising incidents of cyber fraud and misuse, particularly those perpetrated from outside the country using Indian mobile numbers. Under the new rules, web and desktop sessions must automatically log out within six hours, and users will be required to re-verify their accounts frequently. Messaging app providers have 90 days to implement these changes and 120 days to report compliance, as part of an amendment to the 2024 Telecom Cyber Security Rules.
The Department of Telecommunications (DoT) stated that the previous ability to maintain long-lived sessions without an active SIM was being exploited for large-scale, cross-border scams, phishing, and other fraudulent activities. By enforcing SIM-binding and frequent re-verification, authorities aim to close this security loophole and make it more difficult for criminals to operate anonymously or from abroad using Indian identifiers. The new measures are a direct response to the increasing sophistication of cybercriminals targeting Indian users through messaging platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Under the new mandate, messaging providers were given 90 days to implement SIM-device binding and 120 days to report compliance to authorities. The measure extends device-binding practices already used in banking to consumer messaging platforms.
India's Department of Telecommunications introduced new requirements for messaging apps such as WhatsApp, Telegram, Signal, and Snapchat to work only with active, KYC-linked SIM cards. The rules also require web sessions to auto-logout every six hours, as part of an amendment to the 2024 Telecom Cyber Security Rules aimed at reducing cyber fraud and misuse.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.