IMEI Tampering: Why Device Identity Is Central to India's Telecom Security
India's telecom rules treat IMEI tampering as a cognizable, non-bailable offence, with manufacturers, importers, sellers and citizens sharing responsibility.
India's telecommunications network now underpins daily life, commerce and governance, with the active wireless subscriber base touching 1,204.01 million in July 2026. As more citizens rely on mobile devices for payments, services and governance, the integrity of the equipment connecting to these networks has become a security priority.
A key element of that integrity is the International Mobile Equipment Identity (IMEI), a unique 15-digit number that identifies a handset on a telecom network. The first eight digits form the Type Allocation Code (TAC), which denotes the device model. The Global System for Mobile Communications Association (GSMA) allocates TACs to manufacturers and brand owners, who then assign unique IMEIs to individual devices. A dual-SIM phone typically carries two IMEIs, one per SIM slot.
Tampering with or misusing these numbers allows devices to operate under altered identities, complicating identification on networks and creating hurdles for law enforcement, consumer protection and network security.
What counts as unlawful tampering
Under the rules, it is unlawful to intentionally remove, obliterate, change or alter a device's unique identification number. It is equally unlawful to intentionally use, produce, traffic in, or possess hardware or software configured to do so.
Legal safeguards
The Telecommunications Act, 2023 provides the framework against such offences. Section 42(3)(c) prohibits tampering with telecommunication identifiers, while Section 42(3)(e) bars obtaining SIMs or identifiers through fraud, cheating or impersonation. Violations can attract imprisonment of up to three years, a fine of up to ₹50 lakh, or both, and are cognizable and non-bailable under Section 42(7). Section 42(6) extends the same liability to those who abet or promote such offences.
Responsibilities across the device lifecycle
Manufacturers must register IMEIs of applicable devices made in India with the government before first sale, testing, research or other use, through the Device Setu–Indian Counterfeited Device Restriction (ICDR) portal, and ensure valid, unique and untampered numbers. Importers must register IMEIs before bringing applicable equipment into India through the same portal. Resellers and retailers must ensure devices on sale carry valid, untampered IMEIs, and those dealing in used devices should verify numbers against the government's central database of tampered and blacklisted devices, paying a fee per verification. Brand owners must ensure their brands are registered on the portal, linked to the relevant GSMA TAC, and that devices carry authentic IMEIs.
What citizens should do
The Department of Telecommunications advises against using or assembling modems, modules, SIM boxes or other equipment with configurable or tampered IMEIs; procuring SIM cards through fake documents or impersonation; transferring SIMs to others who may misuse them; and using apps or websites to alter Calling Line Identity or other identifiers.
Users can check their IMEI by dialling *#06# and verify device details through the Sanchar Saathi portal or app, or by sending KYM followed by the 15-digit IMEI to 14422. Consumers are advised to buy only from authorised sellers, secure handsets with strong passwords or biometrics, and use authorised service centres for repairs.
In case of loss or theft, the prescribed process involves filing a police complaint, obtaining a duplicate SIM, and registering a blocking request on the Sanchar Saathi (CEIR) portal with the police report and ID proof to receive a Request ID. Because SMS services are restricted for the first 24 hours of a re-issued SIM's activation under TRAI regulations, the OTP-based request must wait until that window ends. If a device is recovered, it should first be reported to police, after which the Request ID can be used to unblock it.
Maintaining device security is a shared responsibility across the telecom ecosystem, with awareness and compliance helping prevent fraud and strengthen India's digital infrastructure.