The Ministry of Corporate Affairs (MCA) has cautioned stakeholders that SMS messages referring to “MCA Signals” and directing recipients to mcasignals.com/app/ for viewing company reports are not issued by MCA. The Ministry has strongly advised stakeholders to verify the source before accessing any link and to avoid sharing confidential or sensitive company and personal information through unverified links. The alert was issued on MCA's official X account, @MCA21India, on 10 September 2026.
“📢 Stakeholder Alert 📢
The Ministry of Corporate Affairs (MCA) has come to notice that stakeholders are receiving SMS messages referring to ‘MCA Signals’ and directing them to access mcasignals.com/app/ for viewing company reports.
Please note that such messages are NOT issued by MCA. Stakeholders are advised to verify the source before accessing any link and avoid sharing confidential/sensitive information through unverified links.”
What Does the Alert Say?
MCA's advisory clarifies that reports have emerged regarding stakeholders receiving unsolicited SMS communications stating that company compliance reports or signals are available for review, with clickable links redirecting recipients to mcasignals.com/app/.
The Ministry has clarified on record that such messages are entirely unassociated with the MCA and has instructed recipients to:
- Independently verify the authenticity and source of any message before clicking links.
- Refrain from sharing confidential, sensitive, or regulatory information (such as MCA portal credentials, OTPs, DIN numbers, or financial data) via unverified links.
The alert must be understood primarily as a warning regarding the origin, channel, and authenticity of the SMS communication. It cautions against unsolicited communications masquerading as regulatory notices.
An Important Nuance: “MCA Signals” Is a Third-Party Company-Intelligence Platform
A crucial point that corporate stakeholders and practitioners should understand is the distinction between government infrastructure and private intelligence portals:
MCA Signals is an independently operated third-party company-intelligence platform accessible via web and mobile applications. The platform aggregates public-record information across Indian companies and LLPs, including MCA master data, financial filings, directorship records, charge registers, GST information, and legal litigation history.
Public registries and application store listings associate the platform with Corwhite Solutions Private Limited. The platform itself operates commercially as a private corporate information aggregation tool rather than a sovereign government portal.
Accordingly, compliance officers and directors should distinguish between two separate questions:
- Authenticity of Communication: Did the Ministry of Corporate Affairs dispatch the SMS? — No, MCA has explicitly disowned these messages.
- Nature of the Underlying Service: Is the service a private business-intelligence tool? — Yes, it is an independent commercial intelligence product.
Who Should Pay Attention?
- Company Directors, KMPs, and Authorised Signatories: Are frequent targets of unsolicited messages claiming changes or reports are pending on their companies.
- Practicing Company Secretaries (PCS) & Chartered Accountants (CA): Frequently receive urgent inquiries from clients seeking confirmation whether such SMS alerts signify impending MCA notices or non-compliance penalties.
- MSME Promoters & Startups: Often unfamiliar with specific MCA SMS protocols (e.g., standard government sender headers such as AX-MCAIND or VD-MCAIND) and more vulnerable to social engineering.
- Insolvency Professionals & Legal Advisers: Dealing with statutory due diligence who require clear delineation between official sovereign notices and commercial data aggregators.
How to Verify Genuine MCA Communications
The Ministry and information-security standards recommend adhering to the following verification checklist:
- Check the Sender ID: Official transactional SMS from the Ministry of Corporate Affairs are dispatched through registered government DLT headers (typically ending in
-MCAINDor-GOVMCA), never from standard 10-digit mobile numbers or unverified promotional headers. - Verify on the Official Portal: Cross-check all company statuses, master data, and filing notifications directly on the official MCA21 portal at www.mca.gov.in.
- Review Verified Announcements: Review public advisories published under the “Latest News” section on
mca.gov.inor verified social accounts such as @MCA21India on X. - Strict Credential Hygiene: Never input MCA portal passwords, digital signature token credentials (DSC), OTPs, Director Identification Numbers (DIN), or corporate bank details into third-party web forms delivered via unsolicited text messages.
CorpLawUpdates Strategic Analysis
The broader importance of this stakeholder advisory lies in reinforcing institutional compliance hygiene and cyber vigilance:
As corporate compliance workflows digitize, the boundary between official regulatory portals and third-party SaaS tools or analytics platforms can easily blur for non-specialist executives. When private platforms or unauthorized promoters use government acronyms in unsolicited broadcast campaigns, it creates acute confusion regarding statutory filing requirements.
For corporate legal departments and secretarial firms, the recommended standard operating procedure (SOP) is straightforward:
- Treat all unsolicited communications as unverified by default.
- Establish clear client guidelines clarifying that statutory MCA communications arrive via registered email addresses and the official MCA21 portal.
- Ensure that engagement with legitimate third-party intelligence platforms occurs through authenticated, direct institutional subscriptions rather than unsolicited SMS links.


