# India's Telegram Ban Reveals Global Internet Fragmentation and BGP Hijacking Risks


India has blocked access to Telegram, one of the world's most popular messaging platforms, through June 22, 2026, following widespread circulation of leaked exam papers on the app. The ban exposed a technical vulnerability extending far beyond India's borders—including disruption in the UAE—and highlights how infrastructure-level attacks can weaponize the internet itself.


Telegram CEO Pavel Durov publicly accused Reliance Jio, India's largest telecom operator, of orchestrating BGP (Border Gateway Protocol) hijacking attacks to disable the service, marking a rare public attribution of such a sophisticated technique and raising questions about who controls internet access in an increasingly fragmented digital landscape.


## The Threat: Exam Security Breach Triggers Nationwide Ban


India's education system faced an unprecedented security crisis when leaked examination papers began circulating on Telegram in June 2026. The leaks potentially compromised national and state-level competitive exams, affecting hundreds of thousands of students preparing for positions in government, engineering, and medical fields—sectors critical to India's workforce.


The incident prompted swift action from India's telecommunications authority and law enforcement:


  • Immediate action: India's Department of Telecommunications ordered all Internet Service Providers (ISPs) to block Telegram's IP addresses and domain names
  • Timeline: The ban was initially set through June 22, with potential extension pending investigation into the exam paper leaks
  • Scope: The blockade affected all access methods within Indian borders, prompting users to seek technical workarounds
  • Stated rationale: Authorities claimed the ban was necessary to prevent further circulation of sensitive examination material and maintain exam integrity

  • However, the government's justification raised concerns among digital rights advocates about whether broad platform bans represent proportionate responses to isolated content violations.


    ## Background and Context: India's Regulatory Approach and Exam Security Crisis


    India has a well-documented history of internet restrictions. The country has implemented platform-specific bans on apps including TikTok, WeChat, and others, often citing national security or data localization concerns. Telegram specifically has been a recurring target due to its encryption-by-default architecture, which prevents government surveillance and content moderation.


    The exam leak's significance:


    Indian competitive exams determine access to prestigious careers and shape the country's professional pipeline. A compromise of exam papers before administration could allow organized cheating rings to achieve unfair advantages, undermining the entire credentialing system. The scale of the leak—affecting multiple exam cycles and thousands of candidates—justified urgent institutional response.


    Previous regulatory tensions:


    Telegram had already faced pressure from Indian authorities over its resistance to content moderation and data disclosure requests. The app's commitment to user privacy meant it could not rapidly comply with government demands to identify or remove leaked documents. This fundamental conflict between Telegram's architecture and India's regulatory expectations created an unresolved tension that the exam leak exacerbated.


    ## Technical Details: BGP Hijacking and Infrastructure-Level Disruption


    Pavel Durov's accusation of BGP hijacking by Reliance Jio represents a technically sophisticated attack vector rarely attributed publicly. BGP is the protocol that directs internet traffic across the globe by announcing which networks control specific IP address ranges.


    How BGP hijacking works:


    | Component | Function | Risk |

    |-----------|----------|------|

    | BGP announcements | Routers advertise which IP addresses they control | False announcements can redirect traffic |

    | Lack of validation | BGP historically relied on trust between operators | Malicious actors can announce routes they don't own |

    | Traffic redirection | Once hijacked, user traffic gets routed to attacker infrastructure | Users can't reach intended services |

    | Regional scope | Hijacking can affect multiple countries depending on which networks amplify the false route | Single ISP can disrupt service globally |


    In the alleged Reliance attack:


    1. Route announcement: Reliance may have announced BGP routes claiming to control Telegram's IP address ranges

    2. Traffic capture: Internet traffic destined for Telegram servers would be redirected toward Reliance infrastructure

    3. Blocking or sinkholing: Telegram traffic could then be dropped (blocked) or redirected to block pages

    4. Upstream propagation: Other networks might have propagated these false routes, extending the disruption beyond India


    The UAE connection: The disruption extending to the UAE suggests either:

  • The false BGP routes were propagated through upstream providers serving both countries
  • Reliance has infrastructure or peering relationships that affected Gulf region routing tables
  • The attack was more widespread than initially contained

  • This level of technical sophistication points toward either state-directed activity or an ISP willing to take unprecedented infrastructure-level action.


    ## Regional Impact and Collateral Damage


    While India was the primary target, the BGP hijacking created unintended consequences across borders:


  • UAE users: Reported intermittent or complete Telegram unavailability, suggesting the hijacked routes affected Gulf-based internet backbone providers
  • Cascade effect: When a major ISP announces false routes, upstream networks may propagate those announcements before discovering the falsity
  • Service quality degradation: Even after Telegram or other operators corrected routing information, verification of legitimate routes takes time
  • Geopolitical infrastructure vulnerability: The incident exposed how a single ISP in one country can disrupt services across multiple nations

  • Telegram worked to mitigate by publishing updated routing information and requesting upstream providers withdraw the false routes, but the damage illustrated the vulnerability of the BGP system globally.


    ## Circumvention Methods: MTProto Proxies and User Responses


    Despite the ban, Indian users quickly adopted technical workarounds:


    MTProto proxies:

  • Telegram's native proxy protocol that disguises encrypted traffic as non-Telegram data
  • Proxy servers act as intermediaries, forwarding requests from users to Telegram servers
  • Can evade simple IP-blocking and DPI (Deep Packet Inspection) filtering
  • Technically challenging for governments to block without causing collateral damage to legitimate traffic

  • Additional workarounds:

  • VPN services (though many face their own regulatory pressure in India)
  • Tor network access to Telegram
  • DNS-over-HTTPS to bypass DNS-level blocking
  • Alternative apps with similar functionality (Signal, WhatsApp, though they lack feature parity)

  • The rapid adoption of circumvention methods highlighted that broad bans, while disruptive, rarely achieve complete prevention of access when users are motivated.


    ## Implications: Privacy, Regulatory Overreach, and Internet Fragmentation


    The incident reveals several critical implications:


    For users and platforms:

  • Telegram's encryption prevents rapid cooperation with government demands, creating regulatory conflict
  • Encrypted platforms face increasing pressure and bans in countries prioritizing surveillance capability
  • Users in restricted regions will continue adopting workarounds, driving underground adoption

  • For internet infrastructure:

  • BGP security remains a critical vulnerability despite decades of awareness
  • No validation mechanism prevents operators from announcing false routes
  • Single ISPs can disrupt global services if motivated or directed
  • RPKI (Resource Public Key Infrastructure) adoption could prevent hijacking but remains incomplete globally

  • For geopolitics:

  • Internet fragmentation is no longer theoretical—individual nations and ISPs now weaponize infrastructure
  • Democracies and authoritarian states increasingly resort to blocking rather than regulation
  • Cross-border impacts complicate international coordination

  • ## HackWire Analysis


    The India-UAE Telegram disruption represents a watershed moment in internet governance: the first publicly attributed use of BGP hijacking as a regulatory weapon. While exam security justified urgent action, the proportionality of a nationwide platform ban—especially one executed through infrastructure-level attacks affecting neighboring countries—raises fundamental questions about power distribution in the digital era.


    Why this matters now: Internet infrastructure was designed with utopian assumptions about cooperation and trust. BGP, the protocol directing global traffic, has no built-in validation mechanism. For 30 years, the internet community has debated fixes like RPKI but failed to achieve global adoption. Reliance's alleged attack proves that motivated actors—whether state-directed or simply ambitious ISPs—can exploit this gap at scale. If one telecommunications company in India can disrupt the UAE, what prevents larger operators from targeting critical infrastructure across continents?


    The pattern: This follows a clear trajectory of internet fragmentation. We've seen China's Great Firewall, Russia's sovereign internet, and India's rotating platform bans. Now we're seeing the technical sophistication increase. What was once simple IP blocking has evolved to infrastructure-level disruption. The next incident may target banking systems, health infrastructure, or emergency services using identical techniques.


    The hidden risk: Platforms like Telegram that resist government surveillance face existential regulatory pressure. Exam security was the stated trigger, but the underlying conflict is architectural—Telegram's encryption prevents the rapid compliance that Indian authorities demand. Organizations worldwide should expect similar conflicts to escalate as governments insist on surveillance-ready design, and encrypted platforms face choice: capitulate or ban.


    For defenders: Organizations relying on Telegram or similar platforms need redundant communication channels. Internet service providers need to implement RPKI validation to prevent BGP hijacking. And governments need proportionality frameworks—exam leaks should trigger investigation and accountability, not whole-platform destruction. The cost of India's ban extends to legitimate users, medical emergency coordination, and civil society organizing.


    A concrete step: This incident should accelerate RPKI adoption worldwide. Internet operators should cryptographically sign their BGP announcements, making hijacking exponentially harder. Every country's telecom regulator should mandate RPKI implementation on critical infrastructure. This single technical standard could prevent the next cross-border disruption.


    — HackWire Editorial


    ## Recommendations


    For internet users in India and affected regions:

  • Understand that VPNs and MTProto proxies carry their own risks; evaluate trade-offs carefully
  • Maintain alternative communication channels with contacts
  • Document any censorship attempts for advocacy purposes

  • For telecommunications operators:

  • Implement RPKI (Resource Public Key Infrastructure) to cryptographically sign route announcements
  • Establish incident response protocols for routing security events
  • Coordinate with upstream providers to detect and halt false route propagation

  • For platform developers:

  • Design with geopolitical resilience in mind—anticipate regulatory bans and regional disruptions
  • Implement proxy mechanisms as standard features, not afterthoughts
  • Support user-operated infrastructure to reduce single points of failure

  • For policymakers and regulators:

  • Distinguish between content moderation (responsible) and infrastructure-level blocking (disproportionate)
  • Establish proportionality frameworks for platform restrictions
  • Coordinate internationally to prevent cross-border collateral damage

  • For civil society and advocacy organizations:

  • Document internet disruptions and their real-world impacts on users
  • Push for government transparency on filtering and blocking infrastructure
  • Support digital rights education and circumvention literacy

  • ---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)