← Resources · July 03, 2026
Internal Security GS 6 min read

Govt lens on e-rickshaw remote shutdown issue; two apps including BAT-BMS removed from app stores

What happened
01

The Ministry of Electronics and Information Technology (MeitY) directed the removal of two battery management applications — BAT-BMS and Lossigy — from the Google Play Store and Apple App Store, following viral social media videos showing e-rickshaws being stalled remotely by unknown individuals.

02

A third app, Epoch-i-ion, was also removed from app stores as part of the same enforcement action.

03

The videos showed e-rickshaw drivers stranded mid-route, with some alleging that unknown persons had connected remotely to their vehicles' battery systems via the BAT-BMS app and activated a discharge function, cutting off power instantly; some drivers also reported extortion demands in exchange for restoring access.

04

The vulnerability stems from Bluetooth-enabled Battery Management Systems (BMS) in low-cost aftermarket lithium battery packs that lack authentication or password protection, allowing any nearby device with the app installed to pair and issue commands.

05

BAT-BMS was developed by the Chinese company Shenzhen Grenergy Technology and was used by manufacturers, dealers, and service technicians to monitor charging status, diagnose faults, and configure battery parameters; its open Bluetooth access model created the security gap.

06

The government has directed app stores to apply stricter scrutiny before approving similar applications and is assessing broader cybersecurity risks across connected electric vehicles.

Static topic 1 of 4 · Internal Security

Battery Management Systems (BMS) and IoT Security

A Battery Management System is an electronic system that monitors and protects rechargeable battery packs, managing parameters such as voltage, current, temperature, state of charge, and state of health. In electric vehicles, the BMS is the critical safety layer preventing overcharging, over-discharging, and thermal runaway. In many low-cost e-rickshaws, the BMS communicates wirelessly with smartphones via Bluetooth Low Energy (BLE) for remote diagnostics — but when authentication mechanisms are absent or disabled by default, the BLE interface becomes an unauthenticated attack surface exploitable within Bluetooth range (~10–30 metres).

Key Details

  • The attack model observed in these incidents is a Denial of Service (DoS) via the BMS "discharge" function — a legitimate service tool repurposed to halt a vehicle.
  • Bluetooth-enabled BMS vulnerabilities are categorised under IoT security threats, where embedded systems lack adequate access controls.
  • India's Bureau of Indian Standards (BIS) certification under IS 17017 is mandatory for EV subsidy eligibility; however, cybersecurity specifications for embedded BMS remain under development.
  • AIS-189 (Cybersecurity Management System standard, modelled on UNECE Regulation R155) is effective for new vehicle types from October 1, 2025, and for all vehicle types from October 1, 2028.
Connection to this news

The e-rickshaw incidents illustrate the security gap between EV hardware proliferation and regulatory standards — AIS-189 focuses on four-wheelers and two-wheelers; low-cost three-wheelers and e-rickshaws are often outside the immediate compliance perimeter, leaving their BMS units vulnerable.


Static topic 2 of 4 · Internal Security

FAME Scheme and India's EV Policy Framework

The Faster Adoption and Manufacturing of Electric Vehicles (FAME) scheme is India's flagship central policy for accelerating EV adoption by providing demand-side subsidies and supporting charging infrastructure. FAME-I ran from 2015 to 2019; FAME-II (₹10,000 crore outlay) ran from 2019 to 2024, with e-rickshaws and e-buses as primary beneficiaries. After FAME-II, the government launched the PM E-DRIVE scheme with a ₹10,900 crore outlay, valid through March 2026, continuing demand incentives across vehicle segments.

Key Details

  • E-rickshaws are three-wheeled electric vehicles classified under L5M (three-wheeled goods carriers) or equivalent; they are a dominant last-mile and intra-city transport mode in north and central India.
  • FAME-II subsidised e-rickshaws and e-carts with up to ₹25,000 per vehicle, driving rapid adoption of low-cost models, many using aftermarket lithium battery packs without integrated cybersecurity.
  • The rapid subsidy-driven growth of the e-rickshaw fleet outpaced standardisation of the battery and BMS components used in these vehicles.
  • The government's EV target is 30% electric vehicle sales by 2030.
Connection to this news

The BAT-BMS incident is a direct consequence of rapid EV adoption incentivised by FAME without parallel enforcement of component-level cybersecurity standards for three-wheelers. It highlights a policy gap: demand subsidies scaled the fleet faster than supply-side quality and security standards could be enforced.


Static topic 3 of 4 · Internal Security

Consumer Protection Act, 2019 and Product Liability

The Consumer Protection Act, 2019 (CPA 2019) replaced the 1986 Act and introduced for the first time a comprehensive product liability chapter in India, shifting the framework from "buyer beware" to "seller beware." Under this chapter, manufacturers, product service providers, and product sellers can be held liable for harm caused by defective products. Defects covered include manufacturing defects, design defects, deviation from express product specifications, and failure to provide adequate warnings or usage instructions.

Key Details

  • Section 2(34) of CPA 2019 defines a "product" broadly to include any article or goods, covering hardware products like battery packs and BMS units.
  • A "product liability action" can be brought by a consumer in the District Consumer Disputes Redressal Commission (claims up to ₹50 lakh), State Commission (₹50 lakh to ₹2 crore), or National Commission (above ₹2 crore).
  • The Central Consumer Protection Authority (CCPA), established under Section 10 of CPA 2019, can issue safety notices, order product recalls, and impose penalties for unfair trade practices.
  • The CPA 2019 extended jurisdiction explicitly to e-commerce transactions, covering apps and digital services as part of the consumer ecosystem.
Connection to this news

E-rickshaw owners harmed by the remote shutdown — with vehicles stalled mid-route, loss of livelihood, and in some cases extortion — may have recourse against battery manufacturers and importers under the product liability provisions of CPA 2019 if the BMS is found to be defectively designed or inadequately secured. The CCPA also has standing to investigate and order corrective action.


Static topic 4 of 4 · Internal Security

Cybersecurity Law and CERT-In's Role

The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for cybersecurity, established under Section 70B of the Information Technology Act, 2000. It has the authority to issue binding directions to service providers, intermediaries, data centres, and body corporate on cybersecurity practices. CERT-In's 2022 directions mandated six-hour incident reporting for a specified list of cybersecurity incidents and required VPN providers, cloud service providers, and cryptocurrency exchanges to maintain user logs.

Key Details

  • CERT-In coordinates with law enforcement on cybercrime involving critical information infrastructure (CII).
  • The National Critical Information Infrastructure Protection Centre (NCIIPC), established under Section 70A of the IT Act, protects critical sectors including energy, transport, and telecom.
  • Bluetooth-based vehicle attacks, if used systematically to disrupt public transport, could fall within the ambit of attacks on transport CII.
  • The IT Act Section 66 provides for imprisonment up to three years for unauthorised access to a computer system, which could apply to BMS exploitation.
Connection to this news

The deliberate remote shutdown of e-rickshaws via an unauthenticated Bluetooth interface constitutes unauthorised computer access under the IT Act. If the incidents escalate to organised disruption of transport networks, CERT-In and NCIIPC's remit becomes directly relevant.


Key facts & data
  • Three apps removed from Play Store and App Store: BAT-BMS, Lossigy, and Epoch-i-ion.
  • BAT-BMS was developed by Shenzhen Grenergy Technology (China).
  • Bluetooth Low Energy (BLE) operates at a typical range of 10–30 metres; exploitation requires physical proximity to the e-rickshaw.
  • AIS-189 (vehicle cybersecurity management standard) is mandatory for new vehicle types from October 1, 2025.
  • FAME-II outlay: ₹10,000 crore (2019–2024); PM E-DRIVE outlay: ₹10,900 crore (through March 2026).
  • India's EV target: 30% of vehicle sales to be electric by 2030.
  • Consumer Protection Act 2019 introduced product liability provisions for the first time in India; the CCPA can order product recalls and impose penalties.
  • Section 66 of the IT Act provides imprisonment up to three years for unauthorised access to computer systems.
  • CERT-In's 2022 directions require cybersecurity incident reporting within six hours of detection.
Read it? Now lock it in. The quiz for this day’s brief covers this story.
Take the quiz