Back Hindustantimes 26/11 attack and strict satellite rules: Why Starlink's security clearance is taking so long
India has authorised Starlink’s first-generation network of 4,408 satellites, out of roughly 11,000 in orbit worldwide
A senior SpaceX executive said on Wednesday that Starlink is "ready to serve in India, once India is ready." The company has its licence and its space regulator approval, but it is still waiting for security clearance and other regulatory approvals. To see why security is the sticking point, one needs to go back to Mumbai in 2008.
The 26/11 attackers carried a satellite phone (UAE-based Thuraya) and used it to talk to their handlers in Pakistan. Reports say India's regulation of satellite phones was set up for national security, particularly after the Pakistan-based terrorists used this technology to talk to their handlers during the 2008 attacks. The worry was that a satellite phone does not use any Indian mobile network, so Indian agencies cannot easily intercept or track it.
Also Read: Elon Musk blames Starlink hurdles in India on ‘monopolistic chokeholds’
That is why one needs a DoT licence for a sat phone today, with only specific types of Inmarsat terminals permitted. In practice, DoT permits are restricted to Inmarsat phones. BSNL has provided satellite service to the government, security and rescue agencies. Foreigners have been stopped at airports for carrying Thuraya and similar phones. At sea, a 2012 shipping circular reportedly bans Thuraya, Iridium and similar phones in Indian waters.
Similar security concerns
Starlink looks very different on the technology side. Inmarsat and Thuraya use a few big satellites parked 36,000 km up. They mainly carry calls and light data. Starlink uses thousands of small satellites flying low, at 550 km. That gives fast broadband, not just calls.
India has authorised Starlink’s first-generation network of 4,408 satellites, out of roughly 11,000 in orbit worldwide. The user needs only a small dish, which can connect a phone or laptop through Wi-Fi. The dish talks to a satellite overhead, the satellite sends the signal down to a ground station called a gateway, and the gateway connects to the internet. That is why India insists the gateway must be on Indian soil. It is the one place where agencies can watch and intercept traffic. In case of Starlink, Dreyer said they have set up 20 gateway sites comprising hundreds of antennas.
Even so, the security concerns are almost the same as for sat phones. In both cases the user sits outside the normal phone and internet system. If the signal goes from dish to satellite to a gateway abroad, Indian agencies have no local network to tap. The device can be carried anywhere and used without a local SIM or normal KYC checks. It works where there is no mobile coverage, such as border hills, forests and the open sea. It can also beat internet shutdowns.
The Myanmar border shows the same fear playing out. In December 2024, the Indian Army recovered weapons and a dish and receiver with a Starlink logo on it from a militant hideout in Manipur’s Imphal East district. Military officers said a militant group was using the device and that it was likely smuggled across the porous border with Myanmar, where rebel groups' use of Starlink has been documented.
Earlier that month, police sent Starlink a legal demand for purchase details of a device found on smugglers caught at sea with $4.2 billion worth of methamphetamine. Police suspect the smugglers used it to navigate. Elon Musk replied on X that Starlink beams were "turned off over India" and "never on in the first place."
Security conditions for Satcom
This is why the government has written so many security conditions in 2025. The DoT added new security rules to the Unified Licence for satellite internet firms. Each gateway site needs separate security clearance, and lawful interception and monitoring must work there before launch. The core network, data centres and DNS must be in India, all user traffic must pass through Indian gateways, and Indian data cannot be copied or decrypted abroad. Terminals cannot link to each other through satellites and bypass Indian infrastructure. Companies must block banned websites, metadata with the Telecom Security Operation Centre, and deny or suspend service to users or areas when security agencies order it.
Every terminal must be registered and authenticated, and foreign devices must be verified first. Operators must give authorities the live location of terminals on request. Geo-fencing must stop signals spilling across borders, and security agencies get special monitoring access within 50 km of land borders and up to 200 nautical miles off the coast. Companies must also make at least 20% of their ground equipment in India within five years of launch, and are encouraged to support NavIC in terminals by 2029.
Also Read: Starlink built India setup to meet security norms, says SpaceX executive; awaits nod
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
