JAIPUR | Expose Now Bureau
A growing number of e-rickshaw drivers across India are reporting sudden vehicle shutdowns that have disrupted their livelihoods and, in several cases, allegedly exposed them to extortion by individuals offering to “repair” the vehicles for money. An investigation by Expose Now has found that the incidents are allegedly linked to the misuse of a mobile application known as BAT-BMS, originally developed for monitoring lithium battery systems rather than controlling vehicles.
The findings have raised concerns over the cybersecurity of Bluetooth-enabled battery management systems (BMS) used in some electric vehicles. While no confirmed cybercrime complaints have yet been registered with the Cyber Crime Department regarding the issue, authorities say any unauthorized access to a user’s device or battery system could amount to data theft and attract criminal liability.

Cyber Crime DIG Responds
In an exclusive interaction with Expose Now, IPS Shantanu Kumar, Deputy Inspector General (Cyber Crime), Rajasthan, clarified that he had not received any formal complaint directly linking BAT-BMS to cybercrime.
Responding to reports that an application could stop moving e-rickshaws, Kumar explained that remote engine shutdown technology has existed for years through GPS-based vehicle tracking systems.
According to him, many GPS devices installed in vehicles include an engine cut-off feature that allows the owner to remotely disable the vehicle in case of theft. However, he emphasized that such systems are intended only for authorized users.

“I have not received any complaint regarding the misuse of such an application for cyber fraud,” Kumar said. “Based on the information currently available to me, I cannot establish a direct connection between these incidents and cybercrime.”
However, he added that if someone’s mobile phone or data were hacked to remotely disable a vehicle, it would constitute data theft and could invite legal action under the Information Technology Act and the Bharatiya Nyaya Sanhita (BNS).
He appealed to affected individuals to submit formal complaints along with technical evidence so that law enforcement agencies could investigate the matter.
Investigation Points to Battery Security Weaknesses
The Expose Now investigation indicates that the issue may not lie with the BAT-BMS application itself but with the weak security configurations found in certain Bluetooth-enabled lithium battery management systems.
BAT-BMS, or Battery Management System, was developed by a Chinese company as a monitoring tool for lithium batteries. Its intended purpose is to display battery information such as charge percentage, voltage, temperature, and battery health. It was not designed as a vehicle hacking application.
However, investigators found that some inexpensive lithium battery management systems are shipped with default or weak Bluetooth passwords. If these passwords are not changed, unauthorized individuals within Bluetooth range may be able to access the battery management system, potentially altering operational settings.
This alleged misuse has reportedly led to cases where e-rickshaws stop functioning unexpectedly, leaving drivers stranded and vulnerable to exploitation.
Not Every E-Rickshaw Is Affected
Experts emphasize that the issue is limited to specific battery configurations.
Only e-rickshaws equipped with Bluetooth-enabled lithium batteries are potentially exposed to such unauthorized access. A significant number of e-rickshaws in India continue to operate on conventional lead-acid batteries, which do not support Bluetooth connectivity.
Furthermore, many established battery manufacturers employ proprietary applications with stronger encryption and authentication systems, making unauthorized access considerably more difficult.
Legal Experts Cite Possible Criminal Offences

Legal experts consulted by Expose Now believe that unauthorized access to battery systems or electronic devices could attract criminal liability under Indian law.


Advocate Yogesh Yadav stated that if an individual unlawfully accesses or manipulates another person’s electronic system using technological means, provisions under Sections 43 and 66 of the Information Technology Act, 2000 may apply. Upon conviction, offenders may face imprisonment of up to three years, a fine of up to ₹5 lakh, or both, depending on the nature of the offence.
Advocate Shubham Katta further observed that certain acts may also invite provisions under the Bharatiya Nyaya Sanhita (BNS) relating to electronic offences. He added that tampering with electronic systems could also attract provisions under the Electricity Act, 2003, depending on the circumstances of the case.
The applicability of these laws would ultimately depend on the facts established during investigation and judicial proceedings.
Safety Measures for Vehicle Owners
Cybersecurity professionals advise e-rickshaw owners using Bluetooth-enabled lithium batteries to adopt several preventive measures:
- Change the default BMS password immediately after installation.
- Use strong, unique passwords instead of factory defaults.
- Disable Bluetooth pairing when not required.
- Regularly inspect battery firmware and security settings.
- Visit authorized service centres if the vehicle experiences unexplained shutdowns.
- Avoid sharing battery credentials with unauthorized individuals.

Government Monitoring the Situation
According to information gathered during the Expose Now investigation, authorities have taken note of concerns regarding the misuse of battery management applications.
Sources indicate that the Government has initiated steps against applications allegedly being misused, including BAT-BMS, Lossigy and Epoch-i-ion, and has reportedly directed their removal from app distribution platforms. Officials are also said to be monitoring similar applications, with further action expected if additional misuse is detected.
However, an official public notification detailing these actions should be referred to for confirmation.
A Growing Cybersecurity Concern
The investigation highlights an emerging challenge at the intersection of electric mobility and cybersecurity. As electric vehicles increasingly depend on connected technologies, weak authentication mechanisms and unsecured Bluetooth access may expose users to new forms of exploitation.
While no conclusive evidence has yet established widespread cybercrime involving BAT-BMS, cybersecurity experts believe the issue underscores the need for stronger security standards, greater awareness among battery manufacturers, and improved digital literacy among vehicle owners.
Authorities have urged anyone experiencing suspicious vehicle shutdowns or unauthorized access to preserve technical evidence and file a formal complaint so that forensic investigations can determine the exact cause.