India mandates SIM-linked messaging apps to fight rising fraud
嗯,用户让我用中文总结这篇文章,控制在100字以内,而且不需要用“文章内容总结”之类的开头。好的,我先仔细读一下文章。 文章讲的是印度政府要求消息应用必须与用户的活跃SIM卡绑定,以防止欺诈和滥用。他们修改了2024年的电信网络安全规则,要求像WhatsApp、Telegram这样的应用在90天内实施这一政策,并在120天内报告执行情况。此外,网页版应用的会话必须在6小时内自动登出,以防止长期会话被滥用。 用户的需求是得到一个简洁的总结,重点突出政策内容和目的。所以我要抓住几个关键点:印度政府强制消息应用与SIM卡绑定、防止欺诈、修改规则的时间、实施期限以及网页版的自动登出机制。 接下来,我需要把这些信息浓缩到100字以内。要注意用词简洁明了,避免冗余。例如,“强制”比“要求”更直接,“防范”比“防止”更正式一些。 最后检查一下是否符合用户的所有要求:中文、100字以内、不使用特定开头。看起来没问题了。 </think> 印度政府要求消息应用与活跃SIM卡绑定以防范欺诈和滥用,修改2024年电信网络安全规则,规定90天内实施并120天内报告。网页版会话需6小时自动登出,遏制长期会话被滥用。 2025-12-3 09:20:36 Author: securityaffairs.com(查看原文) 阅读量:8 收藏

India mandates SIM-linked messaging apps to fight rising fraud

Pierluigi Paganini December 03, 2025

India ordered messaging apps to work only with active SIM cards linked to users’ phone numbers to curb fraud and misuse.

India’s Department of Telecommunications (DoT) now requires providers of messaging apps to work only with active SIM cards linked to users’ numbers to prevent fraud and misuse.

“The Department of Telecommunications (DoT) has observed that some of the App Based Communication Services that are utilizing Indian Mobile Number for identification of its customers/users or for provisioning or delivery of services, allows users to consume their services without availability of the underlying Subscriber Identity Module (SIM) within the device in which App Based Communication Services is running. This feature is being misused to commit cyber-frauds especially from operating outside the country.” reads the announcement published by the DoT.

Indian Government now requires messaging apps such as WhatsApp, Telegram, Signal, Snapchat, and others that rely on Indian mobile numbers as user identifiers to comply with new SIM-binding rules within 90 days. The amendment to the 2024 Telecom Cyber Security Rules aims to curb fraudulent activities such as phishing, scams, and cyber fraud by preventing the misuse of telecom identifiers.

Web sessions must auto-logout within six hours. Apps have 90 days to implement and 120 days to report. The measure aims to close a security gap exploited for large-scale, cross-border fraud, where accounts stay active even after a SIM is removed, deactivated, or taken abroad.

“Long‑lived web/desktop sessions let fraudsters control victims’ accounts from distant locations without needing the original device or SIM, which complicates tracing and takedown. A session can currently be authenticated once on a device in India and then continue to operate from abroad, letting criminals run scams using Indian numbers without any fresh verification.” continues the statement. “Auto‑logout every 6 hours (its only for web version and not for App version) shuts down such long web-sessions and forces periodic re‑authentication with control of the device/SIM, sharply reducing scope for account takeover, remote‑access misuse and mule‑account operations. Frequent re‑authentication forces criminals to repeatedly prove control of the device/SIM, raising friction and detectability.”

Mandatory SIM–device binding and periodic logouts tie every account and web session to a live, KYC-verified SIM, improving traceability in phishing, digital arrest, loan and investment scams. The rule doesn’t affect users roaming with their SIMs. With cyber-fraud losses topping ₹22,800 crore in 2024, these Telecom Cyber Security measures aim to curb identifier misuse and restore trust. Similar device-binding practices used in banking are now extended to communication apps heavily abused in cyber fraud.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, messaging apps)




文章来源: https://securityaffairs.com/185265/laws-and-regulations/india-mandates-sim-linked-messaging-apps-to-fight-rising-fraud.html
如有侵权请联系:admin#unsafe.sh