← Resources · July 03, 2026
Polity & Governance GSGS 5 min read

India issues notice to Telegram, Signal on concerns over usernames, source says

What happened
01

India's Ministry of Electronics and Information Technology (MeitY) issued formal notices to Telegram and Signal on July 2, 2026, directing both platforms to explain their username features and fraud mitigation strategies within three days.

02

The government's concern centres on the risk that lookalike handles — usernames closely resembling those of government agencies, public figures, banks, and financial institutions — could be registered by fraudsters to execute phishing, impersonation, and digital arrest scams.

03

This action followed a separate MeitY notice to WhatsApp on July 1, 2026, directing it to halt its planned username rollout in India, citing similar fraud risks affecting its approximately 850 million Indian users.

04

Testing during WhatsApp's brief rollout window found that lookalike usernames referencing senior officials, prominent personalities, and the Reserve Bank of India could be reserved without restriction.

05

Neither Telegram nor Signal had officially responded to the MeitY notices as of July 3, 2026; digital rights organisations have questioned the legal basis for compelling platforms to suspend existing features.

Static topic 1 of 3 · Polity & Governance

Section 69A of the Information Technology Act, 2000

Section 69A empowers the Central Government or an authorised officer to direct any intermediary to block public access to any information on computer resources when satisfied that it is necessary in the interests of sovereignty and integrity of India, national security, public order, or prevention of incitement to cognisable offences. The government used Section 69A most recently to impose a nationwide block on Telegram from June 16–22, 2026, after criminal networks used Telegram channels to conduct exam-paper fraud in the NEET-UG 2026 cycle; the Delhi High Court upheld that block on June 19.

Key Details

  • Section 69A was inserted into the IT Act by the Information Technology (Amendment) Act, 2008.
  • Intermediaries that fail to comply with a valid 69A direction face imprisonment of up to seven years and a fine.
  • The Supreme Court in Shreya Singhal v. Union of India (2015) read down Section 66A (speech criminalisation) but upheld Section 69A as constitutionally valid, subject to procedural safeguards.
  • Between 2018 and 2023 MeitY issued approximately 6,000 blocking orders annually; this rose to ~12,600 in 2024 and ~24,300 in 2025.
Connection to this news

The government's authority to issue notices and potentially compel feature suspension or block access ultimately rests on Section 69A, making the legal scope of this provision central to evaluating whether MeitY can legitimately freeze a platform feature (rather than block a specific URL or piece of content).


Static topic 2 of 3 · Polity & Governance

Section 79 and Intermediary Safe Harbour

Section 79 of the IT Act grants intermediaries immunity (safe harbour) from liability for third-party content hosted on their platforms, provided they exercise due diligence and promptly comply with valid government takedown or blocking orders. Intermediaries lose safe harbour only upon receiving actual knowledge — through a court order or a valid Section 69A notification — of the illegal content, as held by the Supreme Court in Shreya Singhal.

Key Details

  • Section 79 immunity does not extend to intermediaries who initiate or conspire in the unlawful act.
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules 2021), issued under Sections 79(2)(c) and 87(2)(zg) of the IT Act, impose additional due-diligence obligations on social media intermediaries.
  • Significant Social Media Intermediaries (SSMIs) — platforms with more than 50 lakh (five million) registered users in India — must appoint a Chief Compliance Officer, a Nodal Contact Person, and a Grievance Officer, all resident in India.
  • SSMIs providing primarily messaging services must be able to disclose the first originator of information upon a valid court or government order.
Connection to this news

Telegram, Signal, and WhatsApp all qualify as SSMIs. MeitY's notices are framed as due-diligence inquiries — asking how platforms mitigate fraud risks arising from their username features — which is consistent with Rule 3(1)(b) of IT Rules 2021, which requires intermediaries to ensure their computer resources are not used for fraud or impersonation.


Static topic 3 of 3 · Polity & Governance

Cybersecurity and Phishing: The Impersonation Risk Vector

Phishing and impersonation are among the most prevalent cybercrime vectors globally and in India. Username-based platforms amplify this risk when they allow vanity or lookalike handles — short identifiers that closely mimic the name of a government body, bank, or public authority. Unlike phone numbers (which are issued by telecom operators under KYC norms), usernames on messaging apps are self-selected without identity verification, creating an anonymity gap.

Key Details

  • The Indian Computer Emergency Response Team (CERT-In), established under Section 70B of the IT Act, is the national nodal agency for cybersecurity incident response and can issue binding directions to service providers.
  • CERT-In directions of 2022 require reporting of cybersecurity incidents within six hours and mandate certain logging and KYC standards for VPN and cloud providers.
  • Digital arrest scams — fraudsters posing as CBI, ED, Narcotics Bureau, or customs officials via video calls — have emerged as a major fraud category in 2024–26, with username-based channels enabling impersonation at scale.
  • The Internet Freedom Foundation (IFF) has argued that no express provision of the IT Act authorises MeitY to suspend a platform feature (as opposed to blocking specific URLs or content).
Connection to this news

The government's notices rest on this gap: username features lower the technical barrier for launching impersonation attacks at scale. The regulatory debate is about whether MeitY's administrative powers extend to compelling product design changes, or whether such interventions require legislative backing.


Key facts & data
  • MeitY issued notice to WhatsApp on July 1, 2026, and to Telegram and Signal on July 2, 2026.
  • WhatsApp has approximately 850 million registered users in India.
  • Telegram has offered username-based contact since at least 2014; Signal introduced its optional username feature in 2024.
  • MeitY blocked Telegram nationwide under Section 69A from June 16–22, 2026, in connection with NEET-UG 2026 exam-paper fraud.
  • The threshold for classification as a Significant Social Media Intermediary (SSMI) under IT Rules 2021 is 50 lakh (five million) registered users in India.
  • Section 69A non-compliance carries a penalty of up to seven years' imprisonment.
  • MeitY issued approximately 24,300 blocking orders in 2025, up from ~6,000 annually in the 2018–2023 period.
  • CERT-In's 2022 directions require cybersecurity incident reporting within six hours of detection.
Read it? Now lock it in. The quiz for this day’s brief covers this story.
Take the quiz