+91 98186 32779
πŸŽ–οΈ 500+ Officers SelectedSince 2001Retired SSB Officer FacultyOwn 5-Acre GTO GroundSee Results β†’
CDS / OTA Current Affairs · Polity/Bodies · 23 Sep 2026

Fifteen Digits That Decide Whether a Phone Can Be Found

A SIM card identifies a subscriber. An IMEI identifies a handset. Change the first and the phone is still traceable; change the second and it effectively becomes a different device β€” which is the entire reason the second is unlawful to alter.

A PIB backgrounder of 23 September 2026, titled IMEI Tampering: Threat to Digital Sovereignty, set out the framework India has built around device identity. It opens with the scale that makes the problem worth solving: India's active wireless mobile subscriber base reached 1,204.01 million in July 2026, and those devices increasingly carry digital payments, government services and identity credentials.

What the number is

The International Mobile Equipment Identity is a 15-digit number that identifies a mobile device on a telecom network. Users can display it by dialling *#06#.

The first eight digits form the Type Allocation Code (TAC), which identifies the model or type of device. The TAC is allocated by the GSMA β€” the Global System for Mobile Communications Association, the industry body for mobile operators β€” to manufacturers and brand owners. The manufacturer then assigns a unique IMEI to each individual device it produces. A dual-SIM phone generally has two IMEI numbers, one for each SIM slot.

The structure matters because of what it enables. Because the TAC identifies the model, a network can tell what kind of device is connecting before it knows anything else about it. Because the remaining digits are unique per device, a specific handset can be identified across networks and across SIM changes. A phone whose IMEI is intact can be located, blocked or traced no matter which SIM is inserted into it.

That property is precisely what tampering destroys. The backgrounder defines unlawful tampering as intentionally removing, obliterating, changing or altering the identification number β€” or intentionally using, producing, trafficking in, controlling or possessing hardware or software knowing it has been configured to do so. Note that the offence extends to the tools, not merely the act. A framework that punished only the alteration would leave the equipment trade untouched.

Why an altered IMEI matters beyond the stolen phone

The obvious harm is theft. A stolen handset with an intact IMEI can be blocked and becomes worthless; the same handset with a rewritten IMEI can be resold and used normally. Tampering is what makes handset theft a viable business rather than an opportunistic one.

The less obvious harm is larger. A device with a cloned or configurable IMEI is, from the network's perspective, not reliably identifiable. That breaks the assumption underlying most telecom-enabled investigation: that a device used in a crime can be traced afterwards. The backgrounder's specific warnings against SIM boxes β€” equipment that terminates international calls as if they were local, using banks of SIMs β€” and against modifying Calling Line Identity point at the same thing. Each technique severs the link between an action on the network and an identifiable device or number.

That is why the backgrounder frames this as digital sovereignty rather than consumer protection. When identity credentials, payments and government services run over mobile devices, the reliability of device identity becomes a question about the integrity of the whole system.

Duties across the supply chain

The framework's most distinctive feature is that it places obligations at every stage rather than only on the end user.

Manufacturers must register the IMEI numbers of applicable telecom devices made in India with the Government before their first sale, testing, research or other use, through the Device Setu – Indian Counterfeited Device Restriction (ICDR) portal, and must ensure devices carry valid, unique and untampered numbers.

Importers must register IMEI numbers with the Central Government before importing applicable equipment, through the same portal, and must ensure imported devices carry valid and authorised numbers.

Resellers and retailers must ensure devices offered for sale carry valid and untampered IMEIs. Those dealing in used devices are expected to verify the IMEI against the Government's central database of tampered and blacklisted devices before completing a transaction, against a fee per verification. Dealing in devices with tampered or configurable IMEIs can attract stringent legal action.

Brand owners must ensure devices sold under their brands comply with registration and cybersecurity requirements, with their brands registered on the Device Setu–ICDR portal and linked to the relevant GSMA TAC.

The logic is worth naming, because it recurs across regulation. Enforcement at the point of use is expensive and unreliable β€” there are 1.2 billion connections and no practical way to inspect them. Enforcement at the chokepoints, where devices enter the country or the market, is far cheaper, because the number of manufacturers, importers and brand owners is small and each is identifiable and licensable. Registering identity before first sale also means the legitimate baseline exists before any device reaches a consumer, so an unregistered device is detectable by its absence from the database rather than by any positive evidence of wrongdoing.

Sanchar Saathi, CEIR, and blocking a stolen handset

For citizens the operative system is Sanchar Saathi, the Department of Telecommunications' platform, available as a portal and an app. It allows a user to verify a device's IMEI details β€” brand, model and manufacturer β€” before buying. Verification is also available by SMS: send KYM <15-digit IMEI number> to 14422.

Behind the blocking function sits the CEIR β€” the Central Equipment Identity Register β€” the database against which devices are checked and in which blocked handsets are listed. A blocked IMEI is rejected by networks, which is what makes the handset unusable rather than merely reported.

The procedure after a theft is specified, and the sequence has a reason at each step:

  1. File a police report and keep a copy. The complaint is the evidentiary basis for the block; without it, the system would let anyone disable anyone else's phone.
  2. Obtain a duplicate SIM for the lost number from the operator. The block request is authenticated by an OTP to that number, so the number must be recovered first. Note the wrinkle the backgrounder flags: under TRAI regulations, SMS services are restricted for the first 24 hours after a re-issued SIM is activated β€” an anti-fraud measure against SIM-swap attacks β€” so the request cannot be submitted until that window has passed.
  3. Register the blocking request on the Sanchar Saathi (CEIR) portal or app, uploading the police report and a valid ID proof, and receive a unique Request ID.
  4. If the device is recovered, report it to the police first, then use the Request ID to unblock the handset.

The 24-hour SMS restriction is a good example of two security measures interacting. It exists to defeat SIM-swap fraud, in which an attacker obtains a duplicate SIM to intercept one-time passwords. It has the side effect of delaying a legitimate theft victim's block request by a day. Both effects are real, and the design accepts the second to prevent the first.

The backgrounder's advice to citizens follows from the architecture: buy only from authorised sellers and verify the IMEI; secure the handset with a strong password, PIN or biometric; and get devices repaired only at authorised service centres, since an unauthorised repair is one of the commonest opportunities for tampering.

It also warns against three things people do without regarding them as offences: procuring SIM cards through fake documents or impersonation; transferring or selling a SIM obtained in one's own name to someone else; and using apps or websites to modify Calling Line Identity. The second is the one worth stressing, because it is casually common and because the consequences of what the recipient does with that connection attach to the person whose documents obtained it.

Where it sits among the telecom rules

This is the third distinct strand of telecom regulation to surface this month, and they are worth keeping apart because examinations test the boundaries between regulators.

TRAI regulates tariffs and quality of service and makes regulations on commercial communication β€” the anti-spam framework we covered in our explainer on the new rules against spam calls. DoT is the licensor and the administrative department, and it is DoT that runs Sanchar Saathi, the CEIR and the Device Setu–ICDR registration system. The wider digital-governance stack these sit within is described in our piece on Digital India at eleven.

The simplest way to hold the distinction: TRAI regulates the service; DoT administers the network and the devices on it. Spam and tariffs are TRAI. Licensing, spectrum administration and device identity are DoT.

πŸ”‘ Revision block

  • The document: PIB backgrounder, 23 September 2026 β€” IMEI Tampering: Threat to Digital Sovereignty
  • Scale: India's active wireless mobile subscriber base reached 1,204.01 million in July 2026
  • IMEI: International Mobile Equipment Identity, a 15-digit number identifying a device (not a subscriber)
  • TAC: the first 8 digits form the Type Allocation Code, identifying the device model or type
  • Allocation: the GSMA allocates TACs to manufacturers and brand owners, who assign unique IMEIs to devices
  • Dual-SIM phone: generally has two IMEI numbers
  • Check your own: dial *#06#
  • Verify: Sanchar Saathi portal or app, or SMS KYM <15-digit IMEI> to 14422
  • Unlawful tampering: intentionally removing, obliterating, changing or altering the number; or using, producing, trafficking in, controlling or possessing hardware or software configured to do so
  • Registration portal: Device Setu – Indian Counterfeited Device Restriction (ICDR)
  • Manufacturers: register IMEIs before first sale, testing, research or other use
  • Importers: register IMEIs before importing applicable equipment
  • Resellers and retailers: ensure valid, untampered IMEIs; verify used devices against the central database of tampered and blacklisted devices, against a fee
  • Brand owners: register brands on Device Setu–ICDR, linked to the relevant GSMA TAC
  • CEIR: Central Equipment Identity Register β€” the database used to check and block devices
  • Blocking sequence: police report β†’ duplicate SIM (SMS restricted for the first 24 hours under TRAI regulations) β†’ register on Sanchar Saathi (CEIR) with police report and ID β†’ receive Request ID β†’ report recovery to police, then unblock with the Request ID
  • DoT warns against: SIM boxes and devices with configurable or tampered IMEIs; SIMs obtained by fake documents or impersonation; transferring one's SIM to another person; modifying Calling Line Identity
  • Regulator split: TRAI regulates the service (tariffs, quality, commercial communication); DoT administers the network, licensing and device identity

🎯 Practice MCQs

Q1. An IMEI number consists of: (a) 10 digits (b) 12 digits (c) 15 digits (d) 16 digits

β†’ (c) β€” dialling *#06# displays it.

Q2. The first eight digits of an IMEI constitute the: (a) Subscriber Identity Module code (b) Type Allocation Code, identifying the device model (c) Network operator code (d) Country of manufacture code

β†’ (b)

Q3. Type Allocation Codes are allocated by: (a) The Department of Telecommunications (b) TRAI (c) The International Telecommunication Union (d) The GSMA

β†’ (d) β€” to manufacturers and brand owners, who then assign unique IMEIs.

Q4. An IMEI identifies: (a) The subscriber (b) The device (c) The network operator (d) The location of the call

β†’ (b) β€” the SIM identifies the subscriber, which is why a dual-SIM phone has two IMEIs.

Q5. Manufacturers and importers must register IMEI numbers through which portal? (a) Device Setu – Indian Counterfeited Device Restriction (ICDR) (b) Sanchar Saathi (c) DigiLocker (d) National Single Window System

β†’ (a) β€” Sanchar Saathi is the citizen-facing verification and blocking platform.

Q6. To verify a device's IMEI details by SMS, a user sends: (a) IMEI <number> to 1909 (b) VERIFY <number> to 155260 (c) CHECK <number> to 1930 (d) KYM <15-digit IMEI number> to 14422

β†’ (d)

Q7. The database in which blocked handsets are listed and against which devices are checked is the: (a) Central Equipment Identity Register (b) National Telecom Registry (c) Unified Device Database (d) National Cybercrime Reporting Portal

β†’ (a)

Q8. Under TRAI regulations, SMS services on a re-issued SIM are restricted for the first 24 hours in order to: (a) Allow the network to update its records (b) Reduce network congestion (c) Guard against SIM-swap fraud, in which an attacker obtains a duplicate SIM to intercept one-time passwords (d) Complete the KYC process

β†’ (c) β€” with the side effect of delaying a genuine theft victim's blocking request.

Q9. Placing registration duties on manufacturers, importers and brand owners rather than only on users reflects: (a) A preference for penalising businesses over individuals (b) The absence of any duty on consumers (c) A requirement of international law (d) Enforcement at chokepoints, where the number of regulated entities is small and identifiable

β†’ (d)

Q10. Consider the following statements: 1. Tampering with an IMEI can make a stolen handset usable again despite being reported. 2. TRAI, rather than the Department of Telecommunications, operates the Sanchar Saathi platform. Which is/are correct? (a) 1 only (b) 2 only (c) Both 1 and 2 (d) Neither 1 nor 2

β†’ (a) β€” Sanchar Saathi is a DoT platform; TRAI regulates tariffs, quality of service and commercial communication.

πŸ“‹ How this gets asked (PYQ pattern)

Telecom and cyber governance has become a steady presence in the CDS and OTA general knowledge section, and it is an area where precision about bodies and acronyms pays directly.

The acronym question is the commonest form. IMEI, TAC, CEIR, GSMA, DoT, TRAI, TDSAT. Expanding each correctly is often the whole question, and the ones candidates fumble are CEIR and TAC.

The body question asks who does what. The split to hold is that TRAI regulates tariffs, quality of service and commercial communication, while DoT licenses, administers spectrum and runs the device-identity systems β€” Sanchar Saathi, CEIR and Device Setu–ICDR. A question that asks who operates Sanchar Saathi is testing exactly this, and TRAI is the attractive wrong answer.

The number question covers the 15 digits of an IMEI, the 8 digits of a TAC, *#06#, and the 14422 short code. These are pure recall and cost nothing to hold. Keep 14422 separate from 1909 (the TRAI spam complaint number) and 1930 (the cyber-fraud helpline), because short codes are asked as a matched set.

The procedure question asks the sequence for blocking a stolen phone. Police report, duplicate SIM, portal request, Request ID. Candidates who know the steps but not the order lose the mark.

For an interview, the useful framing is the chokepoint argument: that regulating 1.2 billion devices at the point of use is impossible, while regulating the few hundred entities that manufacture, import or brand them is straightforward. That is a general principle about enforcement design, and it applies well beyond telecom β€” which is exactly why it makes a good answer.

Preparing for CDS or OTA? Technology governance questions are won on the boundaries between bodies β€” who regulates, who administers, who enforces. Build the base with our CDS/OTA general studies notes, follow the daily CDS/OTA current affairs, and prepare with our faculty in the upcoming Cavalier courses in Delhi.


✍️ Written by Aditya Tiwari β€” Economy & polity faculty at The Cavalier. Reviewed by the Cavalier Faculty Desk.