From August 24, 2026, India's telecom operators must start denying a new SIM connection to anyone who already holds the maximum number allowed: nine nationwide, six in Jammu and Kashmir, Assam and the North-East. A Department of Telecommunications circular dated August 17, 2026 tells operators to use the government's Digital Intelligence Platform to identify any applicant who is already at that limit and refuse the new connection. The platform starts carrying subscriber photographs from August 23 so operators can match a face to a name, with full real-time integration required by November 30, 2026. The stated reason is the one every recent telecom circular gives: stopping the SIM cards that feed India's cyber-fraud economy, from OTP theft to the phone calls that impersonate police officers and freeze a victim's bank account, known as digital-arrest scams.
That economy is not small. Citizens reported losing Rs 2,290.24 crore to cyber fraud in 2022, Rs 7,465.18 crore in 2023 and Rs 22,845.73 crore in 2024, the latest full year the government has given Parliament, a near tenfold rise in two years. On the specific scam the new circular's own messaging leans on, the Ministry of Home Affairs told Parliament that its cyber crime unit, I4C, had proactively blocked more than 1,700 Skype IDs and 59,000 WhatsApp accounts used for digital-arrest calls, as of December 2024. Read the circular against that backdrop and the logic looks simple: fewer SIMs per person, fewer tools for the scam.

Source: Ministry of Home Affairs, Lok Sabha reply, December 2025. Chart: The Signal.
It is worth slowing down on that logic. A cap on how many connections one verified identity can hold only bites if the fraud is concentrated under a single identity that runs past the limit. Nothing about the digital-arrest and OTP-fraud economy requires that. The connections that power a call centre or a mule-account ring do not need to sit in one person's name at all: they are typically spread across many separate identities, often rented, incentivised or fabricated at the point of sale, with each one comfortably under nine. A ring that uses twenty identities to hold five SIMs apiece never shows up on a headcount check built around any single buyer, whatever that buyer's limit is set to.
A per-buyer cap only catches fraud that concentrates. This fraud spreads.
The dealer node the government has already tried to close once
The government has, in fact, already tried to fix this from the supply side rather than the demand side. In 2023, it made biometric and police verification of mobile SIM dealers mandatory and ruled that any point-of-sale dealer caught in illegal activity would be terminated and blacklisted for three years. By the time that initiative was announced, in August 2023, 67,000 SIM card dealers had already been blacklisted and 52 lakh fraudulent connections detected and deactivated. That is the node the new circular's angle sidesteps: it is a dealer count and a connections count, not a buyer count, because dealers, not individual over-limit customers, are where bulk fraudulent issuance actually happens.
The August 2026 circular does not update or extend that dealer tally. It adds a separate, narrower gate: a real-time check, at the moment of a new SIM application, of whether the applicant's own verified identity is already at nine connections. That is a legitimate thing to check, though it is one a ring built on many distinct identities, each application clean on its own, will simply never trigger.
The dealer node has stayed live since 2023, and its own numbers show why a buyer headcount would miss it. A CBI investigation disclosed in May 2025, Operation Chakra-V, found more than 64,000 SIM cards issued by 1,930 point-of-sale agents fit fraud-linked criteria; complaint filtering narrowed the suspect agents to 84, of whom 39 were still active and accused of running a "ghost SIM" scheme. The mechanism the CBI described is exactly the one a per-buyer cap cannot see: an agent would tell a customer their e-KYC had failed and a second SIM was needed, hand the genuine connection to the customer, and sell the second, "ghost" SIM, still registered in that customer's own verified identity, to cybercriminals. Every one of those ghost connections sits under nine per identity. The cap counts buyers; the fraud rides on identities that never see themselves as buyers at all.
What enforcement has actually been catching
The record does show large numbers of connections being found and cut off, but through different mechanisms than a buyer headcount. DoT's AI tool ASTR has disconnected 88 lakh suspicious mobile connections after they failed re-verification, and a further 50.90 lakh connections were disconnected based on 11.18 lakh crowd-sourced fraud reports filed through the Chakshu facility, as of July 15, 2026. Both of those are after-the-fact filters: a connection is issued first, then flagged, either by an automated re-verification failure or by a member of the public. The wider Digital Intelligence Platform behind them has 620 organisations integrated, including banks, state and Union Territory police and telecom operators, and the associated Sanchar Saathi programme has led to more than 1.36 crore fake mobile connections being disconnected in total, Communication Minister Jyotiraditya Scindia told the Lok Sabha in July 2025. Separately, more than 11.14 lakh SIM cards and 2.96 lakh IMEIs have been blocked on police reports of misuse, cumulative as of December 2025, nearly four times as many SIM cards blocked as devices.

Source: Ministry of Home Affairs, Rajya Sabha reply, December 2025. Chart: The Signal.
Every one of those tallies describes catching a connection after it exists, or closing down the dealer that issued it. None of them describes a buyer being turned away at nine because a fraud ring tried to route its identities through his name. That specific pathway, the one the new circular is built to close, has no disconnection number attached to it yet, because it has not taken effect.
The honest objection
The strongest case for the circular is that it is not meant to stand alone. It runs on the same Digital Intelligence Platform that already has 620 organisations feeding it data and a track record of 1.36 crore disconnected fake connections, so a buyer-side check is one more filter layered onto infrastructure that has already found real fraud at scale. And a headcount cap does close one genuine gap: an individual who accumulates connections in their own real name, whether to resell access or to keep a stable of numbers for their own use, now has a hard technical stop they did not have before. Sloppy accumulation under one name is a real failure mode, and this rule targets it directly.
That case holds for exactly the fraud that concentrates. It does not answer the harder case: an operation with the resources to recruit or fabricate several identities has no reason to push any single one of them past nine, and the circular's mechanism, a check run against one applicant's own identity at the moment of issuance, has no way to see the pattern across those separate identities. The 2023 dealer-blacklisting programme was built to catch exactly that pattern, at the point of sale, across many customers at once. The new circular does not extend or update that programme; it adds a check that operates on a different axis entirely.
The Signal
The nine-connection cap will generate a real number soon: how many new applications DoT's platform actually denies once the rule takes effect on August 24. If that number is large, some fraud really was concentrating under single over-limit names, and the circular will have caught it. A small number, though, would more likely mean the cap was never aimed at where the fraud economy actually issues its SIMs, not that it failed to work. A dealer that sells nine connections to nine different mule identities has broken no rule this circular checks. Watch whether the next enforcement announcement is a bigger buyer-denial count, or another round of dealer blacklisting. Only one of those numbers tells you the circular reached the node that matters.
Reporting basis: the SIM-cap circular's terms are per Communications Today's coverage of the Department of Telecommunications circular dated August 17, 2026. Cyber fraud loss figures for 2022 through 2024 and the SIM card and IMEI block counts are from the Ministry of Home Affairs' written replies to the Lok Sabha and Rajya Sabha, both answered in December 2025. The I4C figures on digital-arrest-linked accounts are from a Ministry of Home Affairs Lok Sabha reply carried by the Press Information Bureau. The 2023 dealer verification and blacklisting figures, and the ASTR, Chakshu and Sanchar Saathi disconnection figures, are from Ministry of Communications statements, reported respectively by Prasar Bharati's News on AIR (twice, for the 2023 dealer initiative and the Sanchar Saathi cumulative total) and by Free Press Journal, via IANS. The CBI's Operation Chakra-V ghost-SIM figures are from ThePrint's reporting on CBI officials. The two-year growth rate in cyber fraud losses and the ratio of blocked SIM cards to blocked IMEIs are The Signal's calculations from those figures.



