India's cybersecurity framework strengthened after e-rickshaw BMS app misuse
Synopsis
Key Takeaways
The Indian government on Wednesday, 22 July ordered the removal of certain Battery Management System (BMS) mobile applications from app stores after taking cognisance of reports that these apps were being misused to enable unauthorised remote control of e-rickshaw batteries. The directive, confirmed through an official statement from the Ministry of Electronics and Information Technology (MeitY), signals a sharper regulatory stance on IoT-linked cybersecurity vulnerabilities.
What Triggered the Action
According to the government's statement, specific BMS applications — designed to monitor and manage electric vehicle battery systems — were found to have been exploited to remotely manipulate e-rickshaw batteries without authorisation. The Centre acted swiftly, directing app stores to delist the offending applications. This is a notable instance of a cyber threat originating not from conventional IT infrastructure but from consumer-facing mobility hardware, reflecting the expanding attack surface of India's growing electric vehicle ecosystem.
The Integrated Cybersecurity Framework
Minister of State for Electronics and Information Technology, Jitin Prasada, informed the Lok Sabha that the government has institutionalised a nationwide, integrated, and coordinated framework to strengthen cybersecurity and digital resilience across the country's digital ecosystems. The framework brings together several key agencies under a unified architecture.
The National Cyber Security Coordinator, operating under the National Security Council Secretariat, ensures inter-agency coordination on cybersecurity matters. The Indian Computer Emergency Response Team (CERT-In), designated under Section 70B of the Information Technology Act, 2000, serves as the national nodal agency for responding to cyber incidents.
The National Cyber Coordination Centre (NCCC), implemented by CERT-In, continuously monitors cyberspace to detect emerging threats and shares actionable intelligence with concerned organisations, state governments, and stakeholder agencies. The National Critical Information Infrastructure Protection Centre (NCIIPC), established under Section 70A of the IT Act, 2000, safeguards the country's critical information infrastructure.
Consumer Protection and Awareness Measures
The Consumer Protection Act, 2019, administered by the Department of Consumer Affairs under the Ministry of Consumer Affairs, Food and Public Distribution, provides a modernised legal framework covering consumer rights in the context of globalisation, emerging technologies, and e-commerce markets.
The government's Information Security Education and Awareness (ISEA) project, implemented by MeitY, focuses on building human resource capacity in information security and promoting cyber hygiene awareness among the general public. Awareness materials on cybersecurity best practices are actively disseminated through multiple government-run digital portals.
Broader Implications for India's EV and Digital Ecosystem
The BMS app misuse case underscores a growing convergence between physical infrastructure and cyber risk in India's rapidly expanding electric mobility sector. E-rickshaws, which number in the hundreds of thousands across Indian cities, rely increasingly on connected battery management systems — making them a potential vector for cyber exploitation if left unregulated. This comes amid the Centre's broader push to secure critical digital infrastructure as India deepens its digital economy ambitions. The integrated framework announced by MeitY is expected to evolve as threats across connected devices continue to multiply.