From 26/11 to Starlink: Why Are India’s Satellite Internet Security Rules So Strict?

The420.in Staff
6 Min Read

Starlink, which is preparing to launch satellite internet services in India, has received several technical and regulatory approvals but still faces important security-related requirements.

A senior company executive has said Starlink is ready to serve India, but the necessary processes must first be completed by the Indian authorities. The company has obtained a Global Mobile Personal Communications by Satellite (GMPCS) licence and approval from the space-sector regulator, but final security clearance, spectrum allocation and some other approvals remain important steps.

Security concerns surrounding satellite communications in India are not new. Following the 26/11 Mumbai terror attacks, the government tightened rules governing satellite phones. Investigations found that the attackers used UAE-based Thuraya satellite phones to communicate with their handlers in Pakistan. Since satellite phones do not rely on conventional mobile networks, monitoring and tracking their communications and location can be more challenging in certain circumstances.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

As a result, the use of satellite phones in India requires permission from the Department of Telecommunications. In practice, their use is closely monitored outside authorised services provided for government agencies, security operations and emergency or rescue work. The use of certain foreign satellite phone services has also been restricted in Indian waters.

Starlink’s technology, however, differs from traditional satellite phone services. Systems such as Inmarsat and Thuraya primarily rely on a relatively small number of large satellites positioned in geostationary orbit, while Starlink uses thousands of small low-Earth-orbit (LEO) satellites to provide high-speed internet connectivity. Starlink satellites operate at an altitude of around 550 kilometres.

India has authorised 4,408 satellites from Starlink’s first-generation network. Globally, the company has around 11,000 satellites in orbit. A small dish terminal installed at a user’s premises connects to a satellite, which then routes the connection through a ground gateway to the wider internet.

These gateways are a crucial part of India’s security framework. The government wants traffic generated by Indian users to pass through gateways located within the country so that lawful interception and monitoring can be carried out when required. Other conditions require key parts of the network, data centres and DNS infrastructure to be located in India, while Indian data cannot be copied or decrypted outside the country.

Security concerns extend beyond technical monitoring. Satellite internet can operate in remote areas where conventional mobile networks or fibre connectivity are unavailable. Its availability in border regions, mountainous areas, forests and offshore locations could create additional challenges for security agencies. The government also wants to ensure that satellite networks cannot be used to bypass India’s telecom infrastructure or establish unauthorised cross-border connectivity.

Security concerns also increased after a Starlink-branded dish and receiver were recovered along with weapons from a suspected militant hideout in Imphal East, Manipur, in December 2024. Officials had suspected that the equipment was being used by a militant group and could have been connected to activities near the porous Myanmar border.

Around the same period, police sought information from Starlink about a device recovered from suspected smugglers at sea. Authorities suspected that the equipment could have been used for navigation. The company later said that Starlink beams had been turned off over India and that the service had never been active in the country.

India’s satellite communication security rules include separate security clearance for each gateway site, lawful interception and monitoring capabilities before commercial operations begin, routing of Indian user traffic through Indian gateways, the ability to block prohibited websites and the capacity to suspend services for users or areas on directions from security agencies. Terminals must also be registered and authenticated, foreign devices verified and live location made available when required.

Special monitoring provisions apply within 50 kilometres of India’s land borders and up to 200 nautical miles from the coastline. The government has also required operators to manufacture at least 20% of ground equipment in India within five years and has encouraged support for the NavIC navigation system.

Starlink received its GMPCS licence in June 2025 and final approval from India’s space-sector regulator in July 2025, with the authorisation valid until July 2030. However, spectrum allocation, final security clearance for gateway sites and foreign investment-related approvals remain important steps before commercial services can begin.

OneWeb and Jio Satellite Communications have also received approvals to operate satellite communication services in India. Both companies were provided spectrum for trials, but final security clearances and other requirements for regular commercial operations remain central to the regulatory process.

The developments underline that, for India, satellite internet is not merely a matter of faster connectivity. Concerns over satellite communication following the 26/11 attacks, the potential misuse of services in border areas and the need to monitor data flows have led the government to seek stringent safeguards before allowing companies such as Starlink to launch services. The regulatory framework therefore focuses on security at three levels—network infrastructure, users and data.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected