Tuesday , September 29 2026
Telegram

India Drops Bombshell Rule
India’s New Login Rules for WhatsApp, Telegram & Other Messaging Apps

The Indian government now requires messaging apps such as WhatsApp, Telegram, and Signal to work only when linked to an active SIM card. This regulation, issued by the Department of Telecommunications on November 28, aims to combat increasing cyber fraud and secure digital communication.

Telecommunication Cybersecurity Amendment Rules, 2025, take effect immediately but allow 90 days for compliance. The rules classify certain apps as Telecommunication Identifier User Entities (TIUEs) and require them to undergo verification like telecom companies to combat fraud, spam, and cybercrime.

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

According to the notice, these communication apps must ensure within 90 days that their services remain “continuously” linked to the SIM card used during registration. They must block access if the SIM is not present in the device – a technical requirement known as SIM binding. Additionally, web- based versions of these apps, such as WhatsApp Web, must log out users periodically, with sessions not exceeding six hours.

“It has come to the notice of Central Government that some of the app based communication services that are utilizing mobile number for identification of its customers… allow users to consume their services without availability of the underlying SIM within the device posing challenge to telecom cyber security as it is being misused from outside the country to commit cyber-frauds,” DoT stated in its notice.

What does the mandate require?

Continuous SIM Binding: Applications must verify the link between the customer’s registered phone number, SIM card, and device. If the SIM is removed, inactive, or deactivated, the application should be disabled until it is re-validated.

Restrictions on Web Versions: Users will be automatically logged out of web access/desktop every 6 hours; they must then verify their SIM presence by re-scanning the QR code through the mobile app.

Timeline: Platforms must implement changes within 90 days and report compliance to DoT within 120 days. Non-compliance may lead to service restrictions.

Affected Apps: WhatsApp, Telegram, Signal, Snapchat, ShareChat, JioChat, Arattai, and Josh are the most popular communication apps in India. Currently, these apps continue to work indefinitely after initial verification, even without an active SIM.

Why This Change? Official Rationale and Context?

Fraud Prevention: Cybercriminals exploit SIM-independent access to commit scams with spoofed numbers, financial fraud, and spamming. COAI notes that this causes traceability issues as fraudsters use apps even after swapping their SIM cards.

Telecom Cybersecurity: Aligned OTT applications with banking standards, for example; therefore, treating mobile numbers as the digital ID of India to make them more accountable.

Check Also

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. …