WhatsApp Pay may put Indian digital banking at risk: Experts

Agencies
November 8, 2019

After WhatsApp accounts of 121 Indians were compromised by the Israeli spyware Pegasus, experts have warned that the payment feature the Facebook-owned platform is planning to launch in India may put the digital banking system at risk.

"WhatsApp payment needs to be seen with microscopic eye, primarily because in payment you will be dealing with sensitive personal data and cyber security is going to be an essential building block component for WhatsApp to demonstrate its due diligence," Pavan Duggal, one of the nation's top cyber law experts, told IANS.

The Ministry of Electronics and Information Technology (Meity) has already expressed dissatisfaction over the manner WhatsApp communicated about the compromised accounts.

The piece of NSO Group software called Pegasus allegedly exploited WhatsApp's video calling system by installing the spyware via missed calls to snoop on 1,400 users globally. The devices were compromised with just a WhatsApp video call.

In May, WhatsApp, which has 400 million users in India, urged its 1.5 billion global users to upgrade the app after discovering the vulnerability.

"WhatsApp's recent operations have shown that it's difficult for the government to get information from it. WhatsApp is an intermediary under the Information Technology Act and is mandated to exercise due diligence under the law. But it has failed to do due diligence," Duggal said.

"You should not be in a hurry to grant new licences or permission to WhatsApp without being satisfied with its adherence to cyber-security norms, international best practices and Indian laws," he said.

The Facebook-owned company is learnt to have countered the government charge that it didn't inform it about a privacy breach on the messaging platform. WhatsApp didn't even comply with the data breach notification law in India, Duggal said.

"It (WhatsApp) didn't follow reasonable security practices as mandated in Section 43A of the IT Act, 2000. In fact, it abetted the crime of un-authorised access too. Granting WhatsApp pay licence should be given a second thought by the Reserve Bank of India," said Prashant Mali, cyber lawyer at Bombay High Court.

In light of the recent hack, the government, the RBI and the National Payments Corporation of India (NPCI) is reportedly evaluating the risk of allowing social media apps into the digital payment ecosystem.

"With the government, the RBI and the NPCI planning to evaluate the risks involved in making payments via social media apps and services, the security of the UPI payment infrastructure on WhatsApp Pay has been rendered under a cloud of vulnerability," said Salman Waris, Managing Partner at TechLegis Advocates & Solicitors, a law firm.

The RBI revealed in an affidavit in the Supreme Court earlier that WhatsApp had not complied with the data localisation norms. In an April 2018 circular, the RBI stated that the data of any payment banking system have to physically located in India.

"The history of WhatsApp has shown that it's not cooperative with the government in sharing of information. If financial information is compromised, it will not only have an impact on users, but it can also have an impact on the sovereignty and security of India," Duggal said.

The government must go slow till the time WhatsApp demonstrates compliance to Indian law and showed that the platform was secure, he said.

"Because almost every phone user in India is on WhatsApp, it's all the more important for the government and the RBI to ensure that WhatsApp not only complies with the parametres of cyber security and data localisation norms, but also the IT Act and the rules and regulations thereunder.

"If WhatsApp doesn't comply with the data localisation norms, rules and regulations of the IT Act, then there is no question of granting new permission," Duggal said.

In a statement, a WhatsApp spokesperson said that safety and security of users remains the platform's highest priority.

"In May, our security team caught and stopped a cyber attack designed to send malware to mobile devices. Unable to break end-to-end encryption, this kind of malware abuses vulnerabilities within the underlying operating systems that power our mobile phones," the WhatsApp spokesperson said.

"Technology companies are constantly working to stay ahead of these kind of challenges through updates and patches. The safety and security of our users remains our highest priority, which is why in May we blocked the attack and have taken action in the courts to hold NSO accountable," the statement added.

Facebook filed a lawsuit against Israel's NSO Group last month. According to Facebook, the NSO Group violated laws, including the US Computer Fraud and Abuse Act.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 2,2025

Puttur: The long-cherished dream of a government medical college in Puttur has moved a decisive step closer to reality, with the Karnataka State Finance Department granting its official approval for the construction of a new 300-bed hospital.

Puttur MLA Ashok Kumar Rai announced the crucial development to reporters on Monday, confirming that the official communication from the finance department was issued on November 27. This 300-bed facility is intended to be the cornerstone for the establishment of the government medical college, a project announced in the state budget.

Fast-Track Implementation

The MLA outlined an aggressive timeline for the project:

•    A Detailed Project Report (DPR) for the hospital is expected to be ready within 45 days.

•    The tender process for the construction will be completed within two months.

Following the completion of the tender process, Chief Minister Siddaramaiah is scheduled to lay the foundation stone for the project.

"Setting up a medical college in Puttur is a historical decision by the Congress government in Karnataka," Rai stated. The project has an estimated budget allocation of Rs 1,000 crore for the medical college.

Focus on Medical Education Department

The MLA highlighted a key strategic move: requesting the government to implement the hospital construction through the Medical Education Department instead of the Health and Family Welfare Department. This is intended to streamline the entire process of establishing the full medical college, ensuring the facilities—including labs, operation theatres, and other necessary infrastructure—adhere to the strict guidelines set by the Medical Council of India (MCI). The proposed site for the project is in Bannur.

Rai also took the opportunity to address political criticism, stating that the government has fulfilled its promise despite "apprehensions" and "mocking and criticising" from opposition parties who had failed to take similar initiatives when they were in power. "Chief Minister Siddaramaiah has kept his word," he added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 5,2025

Mangaluru: In a significant step to curb online hate and intimidation, Mangaluru City Police have registered a suo motu case against multiple Instagram accounts accused of circulating alleged provocative and threatening content.

While monitoring social media activity on Tuesday, Kankanady Town PSI Anitha Nikkam identified the Instagram handle ‘team_targetttt_900’ for posting a hate message alongside images of lethal weapons. Another account, ‘team_nagara_900’, allegedly shared a threatening post targeting activist Bharath Kumdelu, tagging additional pages such as KARAVALI-OFFICIAL.

Several other accounts — including ‘immu_bhai.fan’, ‘target_boy_900’, ‘kings_of_manglore’, ‘team_target_boys.900’, ‘arshad_mangalore’, ‘target_ka19_ullal’, ‘team_target__’, ‘troll_tigersz_900’, ‘tr_group_900’, and ‘team_target_900’ — are also under scrutiny for spreading similar inflammatory material, police said.

Authorities have urged citizens, especially young social media users, to report suspicious pages and avoid engaging with groups that glorify violence or threaten individuals. Online hate can quickly escalate into real-world harm, and police stress that sharing or promoting such content can attract legal consequences.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 4,2025

indigoflight.jpg

Domestic carrier IndiGo has cancelled over 180 flights from three major airports — Mumbai, Delhi and Bengaluru — on Thursday, December 4, as the airline struggles to secure the required crew to operate its flights in the wake of new flight-duty and rest-period norms for pilots.

While the number of cancellations at Mumbai airport stands at 86 (41 arrivals and 45 departures) for the day, at Bengaluru, 73 flights have been cancelled, including 41 arrivals, according to a PTI report that quoted sources.

"IndiGo cancelled over 180 flights on Thursday at three airports-Mumbai, Delhi and Bengaluru," the source told the news agency.

Besides, it had cancelled as many as 33 flights at Delhi airport for Thursday, the source said, adding, "The number of cancellations is expected to be higher by the end of the day."

The Gurugram-based airline's On-Time Performance (OTP) nosedived to 19.7 per cent at six key airports — Delhi, Mumbai, Chennai, Kolkata, Bengaluru and Hyderabad — on December 3, as it struggled to get the required crew to operate its services, down from almost half of December 2, when it was 35 per cent.

"IndiGo has been facing acute crew shortage since the implementation of the second phase of the FDTL (Flight Duty Time Limitations) norms, leading to cancellations and huge delays in its operations across the airports," a source had told PTI on Wednesday.

Chaos continued at several major airports for the third day on Thursday because of the cancellations.

A spokesperson for the Kempegowda International Airport (KIA) in Bengaluru said that 73 IndiGo flights had been cancelled on Thursday.

At least 150 flights were cancelled and dozens of others delayed on Wednesday, airport sources said, leaving thousands of travellers stranded, according to news agency Reuters.

The Directorate General of Civil Aviation (DGCA) has said it is investigating IndiGo flight disruptions and has asked the airline to submit the reasons for the current situation, as well as its plans to reduce flight cancellations and delays.

It may be mentioned here that the pilots' body, Federation of Indian Pilots (FIP), has alleged that IndiGo, despite getting a two-year preparatory window before the full implementation of new flight duty and rest period norms for cockpit crew, "inexplicably" adopted a "hiring freeze".

The FIP said it has urged the safety regulator, the DGCA, not to approve airlines' seasonal flight schedules unless they have adequate staff to operate their services "safely and reliably" in accordance with the New Flight Duty Time Limitations (FDTL) norms.

In a letter to the DGCA late on Wednesday, the FIP urged the DGCA to consider re-evaluating and reallocating slots to other airlines, which have the capacity to operate them without disruption during the peak holiday and fog season if IndiGo continues to "fail in delivering on its commitments to passengers due to its own avoidable staffing shortages."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.