The Department of Telecommunications (DoT) on December 01, 2025, issued a notification for Mandatory SIM-Binding Rules for Communication Apps to Prevent Cyber Fraud.
The following has been stated:
It has issued new cybersecurity guidelines to prevent the misuse of Indian mobile numbers on app-based communication platforms. It was found that several apps allow users to continue using their services even when the SIM card associated with the registered mobile number is removed, deactivated, or being operated from abroad. This loophole has been frequently exploited by cybercriminals to conduct phishing, digital arrest scams, fake government identity calls, and large-scale investment frauds from outside India.
To address this, DoT held consultations with major communication apps and has now mandated continuous SIM binding, similar to security measures already used in banking and UPI apps. Under the new rules, communication apps must ensure that their services work only when the active SIM linked to the user’s mobile number is present in the device. For apps that offer a web version, DoT has mandated automatic logout every six hours, along with compulsory re-linking through QR code to prevent long, remotely operated sessions that enable account misuse.
The guidelines provide apps 90 days for implementation and 120 days to submit a compliance report. These measures aim to ensure that all active communication accounts are tied to a valid, KYC-verified SIM, improving traceability and reducing cyber fraud risks. DoT emphasizes that the rules do not affect normal roaming, where the SIM remains in the user’s device. With cyber fraud losses crossing ₹22,800 crores in 2024, these uniform security safeguards are expected to significantly strengthen India’s telecom cyber-security environment.
[Release ID: 2197353]