










The Delhi High Court recently directed US-based website-hosting platforms Vercel, GitHub and Netlify to take down URLs infringing on the “IndiaMART” trademark. Court documents seen by MediaNama reveal the modus operandi of fraudsters allegedly operating fake websites, WhatsApp accounts and bank accounts using IndiaMART’s copyrighted works, including its website and app content. But what makes the ruling more significant is that it demonstrates how Indian courts are increasingly holding cloud infrastructure providers like Vercel and GitHub directly accountable for infringing content hosted by third parties, with extremely short compliance windows.
1. A clone and phish operation: B2B marketplace IndiaMART — with 219 million registered buyers, 8.6 million suppliers, and 124 million product listings as of March 2026 — has a verified seller base that fraudsters identified as a high-value target.
The perpetrators created 15 “near-identical” clones of the IndiaMART website, mimicking its layout, trade dress, graphic user interface, search structure, and features down to “call now” and “get better price” action buttons.
These fake sites were weaponized through WhatsApp. Here’s how it works.
2. Why Vercel and GitHub are in the dock: According to the suit, these fake IndiaMART websites were hosted on app and website hosting platforms Vercel, GitHub, and Netlify.
While Vercel provides cloud infrastructure for building and scaling websites, GitHub allows developers to create, store, and share code and content. As per the court order, both these platforms enabled continued dissemination and accessibility to infringing IndiaMART URLs by permitting their infrastructure and services to be used for perpetrating fraud.
The court ordered:
3. Why it matters: The ruling signals a shift in how Indian courts view the “safe harbor” protections for cloud infrastructure providers. While intermediaries like internet service providers often claim exemption from liability for user-generated content, the Delhi High Court has drawn a distinction when the infrastructure is knowingly or actively used to commit fraud.
And in doing so, the court treated Vercel, GitHub and Netlify as extensions of the fraudster’s operations, compelling them to act as enforcers.
Further, the order also mandates that the Department of Telecommunications (DoT) and Ministry of Electronics & IT (MeitY) issue notifications to all TSPs and ISPs to block access to the rogue sites, creating a centralised blocking mechanism.
4. Vercel’s legal troubles in the US: This is not the only instance of Vercel landing in a legal soup. Earlier this week, Vercel admitted wrongdoing and agreed to pay the US government a fine after it failed to comply with a federal search warrant issued under the Electronic Communications Privacy Act. The case dates back to August 2025, when U.S. Magistrate Judge Ryan Carson issued a search warrant requiring Vercel to disclose the contents of a specified user account in its possession, custody, and control.
Three days after Vercel received the search warrant, but prior to the company taking any action to execute the warrant, the user deleted the account. Although the deleted information was still located in Vercel’s servers in a deletion queue, it did not recover that information and only provided the government with some records associated with the account. Vercel failed to meet its obligations to produce the entire contents of the account, believing and representing to the court that the records had been deleted.
Also read:
For You
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。