NEW DELHI: In a sweeping regulatory shift, the Indian government has instructed major messaging and social media platforms—including WhatsApp, Telegram, Signal, Snapchat, ShareChat, JioChat, Arattai, and Josh—to ensure their services cannot be accessed unless users have an active SIM card linked to their device.
The directive has been issued under the newly introduced Telecommunication Cybersecurity Amendment Rules, 2025, which, for the first time, bring communication apps under a framework similar to telecom regulations.
Under these rules, platforms classified as Telecommunication Identifier User Entities (TIUEs) must maintain a continuous connection between the user’s SIM card and the app. This linkage is to be verified within a 90-day cycle.
Stricter Login Rules for Web-Based Access
For users accessing these apps through desktops or browsers, a fresh security requirement has been introduced. Apps will be required to:
- Automatically log users out every six hours
- Force reauthentication via QR code scanning using the active SIM
Officials say this repeated verification makes it harder for bad actors to operate accounts remotely or anonymously.
Why the New Regulation?
According to the DoT, current verification systems are insufficient. Most apps verify a mobile number only once at the time of setup. After that, they continue to function even if the SIM is removed, changed, or deactivated, which creates a window for misuse.
The Cellular Operators Association of India (COAI) reportedly flagged this loophole, noting that criminals—especially those operating from outside India—can continue using app-based communication despite not having an active SIM linked to the number. This makes fraud investigations difficult because call logs, tower locations, and telecom metadata no longer align with the user’s activity on the app.
Mandatory SIM binding, COAI argues, will help maintain a consistent chain linking the user, their mobile number, and the device — reducing spam, scam calls, and financial fraud.
Comparable Security Standards in Other Sectors
The government notes that similar safeguards already exist:
- Banking and UPI apps routinely check SIM presence to prevent unauthorized logins
- SEBI has proposed linking SIM cards to trading accounts and even using facial recognition for added security
Mixed Reactions From Experts
Cybersecurity specialists quoted by MediaNama remain skeptical about the move’s overall impact. They point out that criminals can still obtain SIM cards with fake or borrowed documents, meaning the new rule may only partially deter fraud.
Telecom industry stakeholders, however, see it differently. They argue that mobile numbers continue to be one of India’s most reliable digital identifiers and believe that extending SIM-based verification to messaging apps will enhance cybersecurity and accountability across the board.

