An important directive has been issued by the Indian government that could potentially alter the way millions of users interact with popular messaging applications like WhatsApp, Telegram, Signal, Snapchat, ShareChat, JioChat, Arattai, and Josh. The Department of Telecommunications (DoT) has mandated these platforms to require users to have an active SIM card in their device to access their services. This directive is part of India’s newly introduced Telecommunication Cybersecurity Amendment Rules of 2025, which subject app-based communication services to telecom-style regulations for the first time.
As per the new regulation, these apps, officially referred to as Telecommunication Identifier User Entities (TIUEs), must ensure that SIM cards are continuously linked to their services within a 90-day timeframe. For users accessing these platforms via a web browser, the DoT has introduced another significant change: platforms will be required to log users out every six hours and prompt reauthentication through a QR code. The government asserts that this measure will enhance security by mandating that every session is associated with an active and verified SIM, making it more challenging for criminals to exploit these apps remotely.
Reasons for the Directive
The DoT states that the directive aims to address a significant loophole in the user verification process of communication apps. Currently, most services authenticate a user’s mobile number only during installation, after which the app remains functional even if the SIM is removed or deactivated. The Cellular Operators Association of India (COAI) highlighted that the binding between a subscriber’s app-based communication services and their SIM card occurs only once at installation, allowing the application to operate independently thereafter, as reported by MediaNama.
This loophole creates opportunities for misuse. Cybercriminals, often based outside India, can continue using these apps even after changing or deactivating SIM cards, making it challenging to trace fraudulent activities through call records, location logs, or carrier data. The COAI emphasized that persistent SIM binding would establish critical traceability between the user, the number, and the device, potentially reducing spam, fraud communications, and financial scams via messaging platforms.
Similar security measures are already in place in sectors like digital payments. Banking and UPI apps enforce stringent SIM verification to prevent unauthorized access, while the Securities and Exchange Board of India (SEBI) has suggested linking trading accounts to SIM cards and utilizing facial recognition for added security.
Expert Opinions
While some experts believe that SIM binding could aid in combating fraud by ensuring traceability between users and their devices, others are skeptical. Cybersecurity experts informed MediaNama that scammers could circumvent such measures by using counterfeit or borrowed IDs to acquire new SIM cards, providing only limited benefits. Conversely, representatives from the telecom industry argue that mobile numbers are India’s most dependable digital identifiers and believe that this directive will enhance cybersecurity and accountability by leveraging the existing verification system more effectively.
