The Indian government has withdrawn a directive that would have required all smartphone manufacturers to preinstall the state-run Sanchar Saathi cyber safety app on new devices, following significant pushback from major industry players and privacy advocates. The original order, issued confidentially, mandated that the app be integrated into device firmware and not removable by users, raising concerns about user privacy, device security, and the precedent of government-mandated software on consumer electronics. Apple and Samsung, in particular, led the resistance, arguing that such requirements could introduce vulnerabilities and undermine user trust, with Apple reportedly refusing to comply in any market.
The swift policy reversal was confirmed by India’s telecoms ministry just days after the initial reports surfaced, ending a brief but intense standoff between the government and global handset makers. The episode highlights ongoing tensions between regulatory efforts to enhance cybersecurity and the tech industry’s insistence on user autonomy and secure device ecosystems. The withdrawal of the mandate is seen as a victory for privacy advocates and sets a precedent for future government-technology industry interactions in India.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following industry resistance, the Indian government reversed the plan to make Sanchar Saathi mandatory on smartphones. Adoption of the app was instead made voluntary.
Major device manufacturers including Apple and Samsung, along with privacy advocates, pushed back against the proposed requirement. Critics cited privacy, device security, undeletable software concerns, and lack of industry consultation.
The Indian government moved to require smartphone makers to preinstall the state-run Sanchar Saathi cyber safety app on new devices. The app was intended to help combat mobile phone theft and SIM-related fraud.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcesecurityonline.info
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.