< Back to situation

[REVISION HISTORY]

India telecom security and fraud prevention measures

Updated 5 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-31 19:07 UTC → 2026-09-08 09:44 UTC · added removed

In July 2026, India’s Department of Telecommunications (DoT) introduced new security regulations to protect critical digital infrastructure. These rules prohibit telecom infrastructure providers from storing or transmitting telecom-related data outside of India and establish a new regulatory category for Cloud-Hosted Telecommunication Network Providers (CHTNPs) subject to continuous monitoring. Simultaneously, the DoT utilized an artificial intelligence and big-data platform called ASTR to identify and disconnect approximately 8.8 million mobile connections flagged as suspicious or failing reverification. By August 2026, the DoT expanded its efforts to curb cyber fraud and identity misuse by mandating limits on the number of SIM cards an individual can hold. Effective August 24, 2026, individuals are prohibited from obtaining new connections if they already hold nine active SIM cards across all operators. In sensitive regions such as Jammu and Kashmir, Assam, and the North-East, this limit is restricted to six connections. Following a circular issued on August 17, telecom service providers are now required to implement technical and organizational measures to strictly enforce these quotas. To combat rising cyber fraud and “digital arrests,” the DoT is phasing out paper-based KYC in favor of mandatory digital and biometric authentication, including live facial recognition, fingerprinting, or iris scans. To prevent the use of fraudulent photos, live captures must include geo-tagging and time-stamping. Furthermore, all All telecom service providers must ensure mandatory police verification for POS agents and SIM dealers; unauthorized vendors face penalties of up to ₹10 lakh, blacklisting, and criminal prosecution. Bulk SIM card purchases are also restricted to corporate connections only. Operators have until November 30, 2026, to fully implement real-time verification systems. In late August 2026, the DoT issued additional warnings regarding the misuse of telecommunication identifiers. Under dealers. Furthermore, under the Telecommunications Act, 2023, the DoT has warned that tampering with International Mobile Equipment Identity (IMEI) numbers or obtaining SIM cards through fraud, cheating, or impersonation are cognizable and non-bailable offenses, punishable by up to three years of imprisonment and fines of up to Rs 50 lakh.

Versions

  1. 2026-09-08 09:44 UTC India telecom security and fraud prevention measures
  2. 2026-08-31 19:07 UTC India telecom security and fraud prevention measures
  3. 2026-08-24 18:27 UTC India telecom security and fraud prevention measures
  4. 2026-08-22 08:42 UTC India telecom security and fraud prevention measures
  5. 2026-08-21 05:29 UTC India telecom security and fraud prevention measures
  6. 2026-08-20 07:34 UTC India telecom security and fraud prevention measures

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.