India ordered a temporary nationwide block of Telegram and directed the platform to disable message editing in the country as authorities moved to protect the NEET-UG 2026 medical entrance re-examination from cheating and fraud. The restriction, issued under Section 69A of the Information Technology Act, is set to remain in place until June 22, while message editing is to stay disabled until June 30. Officials said scammers used Telegram channels, groups, and bots to sell fake exam papers, solicit payments from candidates and families, and exploit edited posts and PDFs with preserved timestamps to falsely claim they had leaked questions before the exam.
The action follows the cancellation of the original May exam after allegations of question paper leaks, forcing a June 21 rerun for more than 2 million candidates. Indian cyber authorities said they removed numerous Telegram-based fraud operations, while police in Ahmedabad arrested suspects linked to an inter-state scam ring that allegedly operated eight Telegram channels and moved about ₹1.5 crore. The Bihar Police Economic Offenses Unit, I4C, state police, the CBI, and the National Testing Agency said claims of pre-exam access were fraudulent, while digital rights advocates criticized the platform-wide restriction as disproportionate and argued that any real leak would more likely originate from insiders than from the messaging app itself.

Get the infrastructure and lures behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Authorities scheduled the NEET-UG 2026 re-examination for June 21, 2026, for more than 2 million candidates after the original exam was canceled amid leak allegations.
On June 19, 2026, the Delhi High Court upheld India's temporary Telegram restriction imposed ahead of the NEET-UG 2026 re-exam. The ruling sustained the emergency measure despite Telegram's legal challenge.
In a June 18 affidavit to the Delhi High Court, the Indian government said Telegram had been warned roughly two weeks before the block and had acknowledged it could not proactively detect exam-leak channels, groups, and bots at scale. The filing was part of the ongoing court fight over India's temporary Telegram restrictions tied to NEET-UG 2026 fraud.
Pavel Durov alleged that Indian telecom operator Reliance interfered with Telegram access beyond India through unauthorized BGP announcements, describing the incident as BGP hijacking. He later said the routing problems had stopped.
Telegram challenged the Indian government’s temporary nationwide restriction and message-editing disablement order in a New Delhi court, arguing the measures were unlawful, disproportionate, and less effective than targeted removals. The company said it had already cooperated by removing hundreds of channels and more than 900 links tied to illegal NEET-related content.
Authorities directed Telegram to disable editing of previously published messages in India through June 30, 2026, to prevent scammers from altering old posts and PDFs to fake proof of advance access to exam papers.
India ordered a temporary nationwide restriction on Telegram under Section 69A to disrupt cheating and fraud tied to the NEET-UG 2026 re-examination. Authorities said the block would remain in place until June 22, 2026.
Indian cyber authorities and law enforcement agencies took down Telegram channels, groups, and bots advertising fake leaked papers and issued warnings that claims of pre-exam access were fraudulent.
Police in Ahmedabad arrested suspects linked to an inter-state cyber-fraud gang that allegedly operated eight Telegram channels and handled about 15 million rupees in fraudulent transactions tied to fake exam paper scams.
Authorities canceled the original May NEET-UG 2026 medical entrance exam after allegations that question papers had leaked, triggering public protests and heightened scrutiny of exam security.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
12 references tracked. Mallory keeps watching after this page renders.
stealthmole-intelligence-hub.blogspot.com
Open sourcecysecurity.news
Open sourcebleepingcomputer.com
Open sourcexakep.ru
Open sourcetherecord.media
Open sourcetherecord.media
Open sourcenta.ac.in
Open sourcecore.telegram.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.