Predatory Sparrow Meteor Malware

India Mandates ‘Undeletable’ Sanchar Saathi App on All New Smartphones

India's Department of Telecommunications has issued a sweeping directive requiring all smartphone manufacturers to preload a government-backed cybersecurity application called "Sanchar Saathi" on every new device sold in the country. The order, issued November 28, 2025, mandates that the app be installed as a permanent, non-removable feature with 90 days for full compliance. The unprecedented requirement affects major manufacturers including Apple, Samsung, Xiaomi, Vivo, and Oppo, and represents a significant expansion of state control over consumer electronics in the world's second-largest telecom market with over 1.2 billion subscribers.

The Sanchar Saathi Platform: From Web Portal to Mandatory App

Sanchar Saathi for "Communication Companion"—began this year as a voluntary web portal designed to empower mobile subscribers with cybersecurity and fraud prevention tools. The government's decision to mandate smartphone preloading represents a dramatic escalation, transforming the platform from optional to universally enforceable.

The app integrates several critical safety features directly into device interfaces:

Chakshu: A reporting tool enabling users to flag suspected fraud communications, including malicious calls, SMS messages, and WhatsApp contacts through a centralized platform.

Lost/Stolen Mobile Blocking: Leverages the Central Equipment Identity Register (CEIR) to permanently block stolen devices across all networks, rendering them unusable to thieves.

Connection Management: Enables users to verify "Know Mobile Connections in Your Name," identifying unauthorized SIM cards registered against their identity and preventing identity theft.

Genuineness Checks: Verifies device hardware authenticity and validates IMEI numbers to prevent counterfeit device circulation.

The government points to substantial results justifying the mandate: over 700,000 lost phones recovered since January 2025, 30 million fraudulent connections terminated, and 3.7 million stolen devices blocked from network access. These metrics demonstrate measurable success in combating telecommunications fraud across India's massive subscriber base.

The Apple Problem: Philosophy vs. Mandate

The directive creates fundamental conflict with Apple's stringent corporate policies, which historically prohibit preinstallation of government or third-party applications on iPhones. Apple has consistently declined such requests globally, viewing mandatory app preloading as compromising user experience, device performance, and brand autonomy.

Industry executives, speaking anonymously, expressed frustration over the lack of prior consultation. Manufacturers fear that forced application installation could undermine user trust, complicate device performance, and establish precedent for future government mandates affecting device functionality.

Apple may pursue negotiated compromise, potentially offering users prominent installation prompts rather than permanent preloading. However, the government's firm language regarding "undeletable" installation suggests limited flexibility.

Privacy Concerns and Surveillance Risks

Digital rights advocates have raised legitimate privacy concerns. A government-controlled app with deep system access theoretically enables surveillance capabilities. Privacy advocates warn that permanently installed government applications with extensive permissions could be repurposed for monitoring without transparent oversight mechanisms.

However, Indian government officials have consistently denied surveillance intentions, characterizing the directive as purely consumer protection against telecommunication fraud, device theft, and IMEI spoofing—criminal tactics exploited by scam networks to conceal device identities.

The Broader Context: Digital Sovereignty vs. Consumer Privacy

This mandate reflects India's broader strategy asserting regulatory control over digital infrastructure and consumer electronics. As India's telecom sector faces increasing fraud, device theft, and organized crime exploiting telecommunications networks, the government views technological mandates as necessary defensive measures.

Yet the "undeletable" requirement represents an unprecedented intrusion into device autonomy, establishing institutional precedent for future mandatory software requirements.

Manufacturers must also distribute the app to existing devices through software updates, ensuring coverage across the active smartphone base—potentially affecting hundreds of millions of devices already in use.