India’s vibrant digital economy, increasingly reliant on instantaneous communication for critical financial transactions, faces a growing threat as telecommunication operators raise alarms over the diversion of essential banking SMS traffic through unregulated channels. This practice, allegedly spearheaded by third-party telemarketers seeking to cut costs, not only erodes the revenue streams of licensed telecom providers but, more critically, exposes millions of consumers to significant security vulnerabilities and poses a systemic risk to the integrity of the nation’s financial digital infrastructure. The observed decline in verifiable SMS volumes, reported to be as high as 50-80% for major public sector banks, signals a potential parallel communication ecosystem operating beyond the established regulatory oversight, prompting urgent intervention from bodies like the Telecom Regulatory Authority of India (Trai), the Reserve Bank of India (RBI), and the Securities and Exchange Board of India (Sebi).
The traditional architecture for Application-to-Person (A2P) SMS, particularly for sensitive communications such as banking alerts, requires principal entities like banks to route messages through registered telemarketers who then utilize the licensed telecom networks for delivery to end-users. This regulated pathway ensures traceability, security protocols, and compliance with national communication standards. However, telecom operators have presented compelling evidence to the Joint Committee of Regulators (JCoR) suggesting a widespread circumvention of this system. They contend that after securing contracts from banks, some telemarketers are illicitly diverting a substantial portion of these critical messages—estimated at 60-70% across several public sector banks—away from regulated telecom networks. These messages are instead being routed through untracked, internet-based channels, effectively creating a "shadow" communication network.
The motivation behind this alleged rerouting is primarily economic. Principal entities, such as financial institutions, are typically charged approximately 7 paise per SMS, a cost that includes network termination fees. By bypassing the regulated telecom infrastructure, telemarketers can significantly reduce their operational expenses, potentially pocketing the difference while delivering messages through cheaper, often unmonitored, alternative platforms. This practice not only creates an unfair competitive advantage but also directly impacts the revenue of telecom operators, who invest heavily in maintaining secure and robust network infrastructure. The A2P SMS market globally is a multi-billion dollar industry, with India being one of its fastest-growing segments due to rapid digitalization. A significant portion of this market is tied to financial services, making the reported diversion a substantial blow to telco profitability and their ability to further invest in network security and expansion.
The implications for consumer security are profound and far-reaching. Critical financial communications, including one-time passwords (OTPs), transaction alerts, account balance updates, and fraud notifications, are designed to be delivered through secure, verifiable channels. The regulated telecom networks operate under strict licensing conditions that mandate features like Distributed Ledger Technology (DLT) scrubbing, which helps prevent spam and fraudulent messages by verifying sender identities. Furthermore, these networks are subject to lawful interception capabilities, essential for national security and law enforcement investigations. When sensitive financial information is transmitted via unregulated internet-based applications, these crucial safeguards are entirely absent.
Operators have highlighted that certain internet-based apps, generic phone-based SMS applications, Rich Communication Services (RCS), and Over-the-Top (OTT) platforms—some even mimicking traditional SMS functionality—are processing and displaying financial transaction details completely outside the Trai-regulated ecosystem. This creates a critical regulatory blind spot. Unlike licensed telecom providers, many of these internet-based platforms are not subject to the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR), which govern consent management, sender ID registration, and grievance redressal mechanisms for commercial communications. Consequently, highly sensitive data, including account numbers, transaction amounts, and beneficiary details, could be traversing unencrypted internet infrastructure, potentially routed through servers located in foreign jurisdictions, completely beyond the reach of Indian regulatory authorities and data protection laws.
The risks associated with this unregulated communication pathway are manifold. Without DLT scrubbing and verifiable customer consent, users become more susceptible to phishing attempts, identity theft, and financial fraud. A malicious actor could exploit these loopholes to spoof legitimate bank messages, tricking customers into divulging personal information or authorizing fraudulent transactions. The absence of lawful interception capabilities also presents a national security concern, making it harder for authorities to track and prevent cybercrimes or other illicit activities facilitated through these shadow channels. Moreover, if banks are paying telemarketers for messages that are ultimately undelivered or routed through unsecure channels, it creates a systemic inefficiency and a potential liability for the financial institutions themselves, despite their initial intent to communicate securely with customers.
The gravity of this situation has prompted telcos to present a series of recommendations to the JCoR. They propose a mandatory system where all delivery reports for A2P messages, irrespective of the routing method, are published on the DLT platform. This would provide principal entities with transparent, verifiable proof of message delivery and the channel used. Crucially, they have urged the RBI to issue explicit guidelines requiring banks to leverage these telco-verified reports when remunerating telemarketers. This measure would incentivize telemarketers to adhere to regulated channels, as payments would be tied to verifiable delivery through approved infrastructure. It would also empower banks to identify discrepancies in communication systems and hold their partners accountable.
This challenge is not unique to India, though its scale in a rapidly digitizing economy like India makes it particularly pressing. Globally, regulators grapple with the convergence of traditional telecom services and internet-based OTT platforms. The European Union, for instance, has been working on strengthening its ePrivacy Directive to ensure that communication services, regardless of their underlying technology, offer equivalent levels of security and privacy. The issue underscores the need for a harmonized regulatory framework that can adapt to technological advancements while safeguarding consumer interests and national security. Telecom consultant Rakesh Mehrotra emphasizes that critical communications must be routed through licensed networks due to their inherent security architecture. "Bank communication through third-party apps could impose risks, as the built-in security is usually not present in those apps," he warns, highlighting the potential for significant breaches and loss of trust.
The ongoing discussions within the JCoR represent a critical juncture for India’s digital ecosystem. A robust, secure, and transparent communication framework is foundational for fostering trust in digital financial services, which are vital for economic inclusion and growth. Addressing the alleged diversion of banking SMS traffic requires a concerted effort from all stakeholders: telecommunication companies, financial institutions, telemarketers, and regulators. By closing the existing regulatory blind spots, enforcing stringent compliance, and promoting transparent reporting mechanisms, India can ensure that its digital communication pathways remain secure, reliable, and capable of supporting the aspirations of a modern, digitally-empowered nation, while also protecting the legitimate revenues of its crucial telecom sector. The imperative is clear: to reconcile technological innovation with regulatory oversight, ensuring that the pursuit of cost-efficiency does not come at the expense of financial security and consumer confidence.
