Nine lending apps were named in Indian takedown notices this month, and the body that issued them was a cybercrime agency, not a banking regulator. That distinction is most of the story.
The names, and the two dates
Per the Free Press Journal of 25 August 2026 and MediaNama of 26 August, the Threat Analytics Unit of the Indian Cybercrime Coordination Centre named three apps in a notice dated 19 August: Horizon Cash Service, Money Score Monitor and Zelicredit. Twelve days earlier, a 7 August notice covered six others — LoanOrbit, Hisab, Nexus Loan, One Fund, Credit Factor and Mobile Credit Prairie.
The allegations are I4C’s, as those reports describe them: the apps posed as legitimate lenders advertising fast approvals and low rates, then charged unusually high interest after disbursal, and reached Aadhaar details, financial information, contacts, photographs and camera access. Both reports say Google has complied.
The provision is the interesting part
The notice was issued under Section 79(3)(b) of the Information Technology Act, 2000 and Rule 3(1)(d) of the IT Rules, 2021, according to MediaNama.
That pairing is not a ban on anyone’s lending. It is the safe-harbour machinery, and not the version of it most people last read. In the text the Ministry of Electronics and Information Technology publishes, updated to 10 February 2026, Rule 3(1)(d) was substituted whole by G.S.R. 775(E) of 22 October 2025, then had its removal window cut from thirty-six hours to three by G.S.R. 120(E) of 10 February 2026. Actual knowledge now arises only by court order, or by a reasoned intimation in writing from an officer specifically authorised for the purpose. Ignoring it costs the intermediary its immunity.
So the three hours I4C is reported to have demanded is no agency flourish. It is the outer limit the amended rule now sets — a fact about Google’s exposure, not a finding about anyone’s lending.
This is also not the Reserve Bank: across its August press releases to 28 August it published nothing on loan apps or digital lending, and a Rule 3(1)(d) notice alters no firm’s registration position.
What a takedown does not settle
Neither report establishes who owned these nine apps, where those owners are incorporated, or which entity — if any — was to hold the loans. A delisting does not answer that; it removes a listing. The permissions in the allegations are the same permissions whatever the listing claims, and an app taken off a store can be sideloaded the same afternoon.
Nine names in one month is worth keeping, though, as a list to check an installed app against — but not as the running total: MediaNama reports a further notice on 21 July naming five more.
None of this is guidance on where to borrow. A delisting tells you an app is gone, not which company was on the hook for the loan. Find that name and check it against the regulator’s own records before any money moves.