India's cybersecurity framework strengthened after e-rickshaw BMS app misuse

Share:
Audio Loading voice…
India's cybersecurity framework strengthened after e-rickshaw BMS app misuse

Synopsis

India's cyber regulators have removed e-rickshaw Battery Management System apps from stores after they were exploited for unauthorised remote battery control — a rare instance of cyber threat emerging from consumer EV hardware. The incident has prompted MeitY to formally consolidate a multi-agency national cybersecurity framework spanning CERT-In, NCCC, and NCIIPC.

Key Takeaways

The Centre ordered removal of certain Battery Management System (BMS) apps from app stores after reports of unauthorised remote control of e-rickshaw batteries.
MoS IT Jitin Prasada informed Lok Sabha on 22 July that a nationwide integrated cybersecurity framework has been institutionalised.
The framework includes CERT-In , the National Cyber Security Coordinator , NCCC , and NCIIPC under a coordinated architecture.
NCIIPC is established under Section 70A and CERT-In under Section 70B of the IT Act, 2000 .
The ISEA project by MeitY continues to build information security awareness and human resource capacity nationwide.

The Indian government on Wednesday, 22 July ordered the removal of certain Battery Management System (BMS) mobile applications from app stores after taking cognisance of reports that these apps were being misused to enable unauthorised remote control of e-rickshaw batteries. The directive, confirmed through an official statement from the Ministry of Electronics and Information Technology (MeitY), signals a sharper regulatory stance on IoT-linked cybersecurity vulnerabilities.

What Triggered the Action

According to the government's statement, specific BMS applications — designed to monitor and manage electric vehicle battery systems — were found to have been exploited to remotely manipulate e-rickshaw batteries without authorisation. The Centre acted swiftly, directing app stores to delist the offending applications. This is a notable instance of a cyber threat originating not from conventional IT infrastructure but from consumer-facing mobility hardware, reflecting the expanding attack surface of India's growing electric vehicle ecosystem.

The Integrated Cybersecurity Framework

Minister of State for Electronics and Information Technology, Jitin Prasada, informed the Lok Sabha that the government has institutionalised a nationwide, integrated, and coordinated framework to strengthen cybersecurity and digital resilience across the country's digital ecosystems. The framework brings together several key agencies under a unified architecture.

The National Cyber Security Coordinator, operating under the National Security Council Secretariat, ensures inter-agency coordination on cybersecurity matters. The Indian Computer Emergency Response Team (CERT-In), designated under Section 70B of the Information Technology Act, 2000, serves as the national nodal agency for responding to cyber incidents.

The National Cyber Coordination Centre (NCCC), implemented by CERT-In, continuously monitors cyberspace to detect emerging threats and shares actionable intelligence with concerned organisations, state governments, and stakeholder agencies. The National Critical Information Infrastructure Protection Centre (NCIIPC), established under Section 70A of the IT Act, 2000, safeguards the country's critical information infrastructure.

Consumer Protection and Awareness Measures

The Consumer Protection Act, 2019, administered by the Department of Consumer Affairs under the Ministry of Consumer Affairs, Food and Public Distribution, provides a modernised legal framework covering consumer rights in the context of globalisation, emerging technologies, and e-commerce markets.

The government's Information Security Education and Awareness (ISEA) project, implemented by MeitY, focuses on building human resource capacity in information security and promoting cyber hygiene awareness among the general public. Awareness materials on cybersecurity best practices are actively disseminated through multiple government-run digital portals.

Broader Implications for India's EV and Digital Ecosystem

The BMS app misuse case underscores a growing convergence between physical infrastructure and cyber risk in India's rapidly expanding electric mobility sector. E-rickshaws, which number in the hundreds of thousands across Indian cities, rely increasingly on connected battery management systems — making them a potential vector for cyber exploitation if left unregulated. This comes amid the Centre's broader push to secure critical digital infrastructure as India deepens its digital economy ambitions. The integrated framework announced by MeitY is expected to evolve as threats across connected devices continue to multiply.

Point of View

They become hackable. The government's response — delisting apps and reiterating an existing multi-agency framework — is necessary but reactive. What is missing is a proactive IoT security standard mandated at the device certification stage, before vulnerable apps reach the market. India's cybersecurity architecture is increasingly comprehensive on paper; the test is whether CERT-In and NCCC have the bandwidth and legal teeth to act before exploitation, not after.
NationPress
22 Jul 2026

Frequently Asked Questions

Why did the government order removal of e-rickshaw BMS apps?
The government ordered the removal of certain Battery Management System mobile applications from app stores after reports emerged that these apps were being misused to enable unauthorised remote control of e-rickshaw batteries. The directive came from the Ministry of Electronics and Information Technology on 22 July.
What is India's integrated cybersecurity framework?
It is a nationwide, coordinated architecture institutionalised by MeitY that brings together the National Cyber Security Coordinator, CERT-In, the National Cyber Coordination Centre (NCCC), and the National Critical Information Infrastructure Protection Centre (NCIIPC) to detect, respond to, and prevent cyber threats across India's digital ecosystem.
What is CERT-In and what does it do?
The Indian Computer Emergency Response Team (CERT-In) is designated under Section 70B of the IT Act, 2000 as India's national nodal agency for responding to cyber incidents. It also implements the National Cyber Coordination Centre, which monitors cyberspace for emerging threats.
Who is affected by the BMS app misuse?
E-rickshaw operators and owners are most directly affected, as the exploited apps could allow unauthorised parties to remotely control their vehicle batteries. The broader EV ecosystem and consumers relying on connected battery systems face similar risks if IoT security standards are not enforced.
What awareness measures has the government put in place for cybersecurity?
MeitY implements the Information Security Education and Awareness (ISEA) project to strengthen human resources in information security and promote cyber hygiene among the public. Awareness materials are also disseminated through multiple government-run digital portals.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 week ago
  2. 1 week ago
  3. 2 weeks ago
  4. 2 weeks ago
  5. 2 weeks ago
  6. 2 months ago
  7. 2 months ago
  8. 1 year ago
Google Prefer NP
On Google