Context: UPI and digital payments have become deeply integrated into everyday economic activity in India, but their growing adoption has also expanded the potential target base for cybercriminals.
- The Status of Policing in India Report (SPIR) 2026 highlights a paradox: people who use digital payments more frequently and have greater confidence in online banking were also more likely to report having experienced cybercrime.
Rapid Expansion of Digital Payments
- UPI processed over 24,000 crore transactions in FY 2025–26, with transaction value exceeding ₹314 lakh crore, reflecting its central role in India's digital economy.
- Around 70% of India's population is connected to the internet, creating a vast user base for digital platforms as well as a large potential target pool for cybercriminals.
- Around 49% of respondents reported using UPI apps daily, while another 24% used them once or twice a week.
- UPI was the most frequently used online payment method, with around 48% reporting that they used it “many times”, ahead of cards, wallets and NEFT/RTGS.
Growing Trust in Digital Payments
- UPI was the most trusted digital payment method in the survey: 34% considered it “very safe” and 41% “somewhat safe”, meaning around three-fourths perceived it as safe.
- Card payments ranked next, with around 65% considering them safe.
- Across online banking modes, about 23% considered them “very safe” and 40% “somewhat safe”, indicating broad public confidence in digital financial systems.
- This trust is broadly positive because widespread confidence encourages financial digitisation, convenience and adoption of formal payment systems.
The “Trust Paradox”
- The report found that high trust did not necessarily correspond to safer digital behaviour.
- Among respondents categorised as highly vulnerable to unsafe online practices, 49% considered online banking “very safe” and another 39% considered it “somewhat safe”.
- By contrast, only around one-fifth of respondents with moderate or no vulnerability considered online banking “very safe”.
- Thus, confidence in the security of digital payments can sometimes coexist with risky user behaviour, such as opening links from unknown sources, downloading files from strangers or sharing OTPs.
Trust and Cybercrime Victimisation
- Respondents who considered online banking modes “very safe” were more likely to report being victims of cybercrime during the previous 2–3 years.
- Among cybercrime victims, 28% considered online banking “very safe”, compared with 14% who considered it “very unsafe”.
- A similar pattern was observed with UPI usage: people using UPI many times were more likely to report cybercrime victimisation than those who never used it.
- This does not necessarily mean that UPI usage itself causes cybercrime; frequent users simply have greater exposure to digital transactions and may become more attractive targets for sophisticated fraud networks.
How Cybercriminals Exploit Digital Trust
- Cybercrime has increasingly developed into an organised ecosystem, rather than consisting only of isolated individual fraudsters.
- According to an expert cited in SPIR, fraudsters can obtain pre-arranged SIM cards, bank accounts and mobile phones through “fraud kits” for around ₹10,000–20,000, enabling large-scale fraud while making tracing more difficult.
- Criminal networks use fake investment and betting applications, impersonation and other deceptive interfaces to create an appearance of legitimacy.
- “Digital arrest” scams exploit fear and authority by falsely claiming that victims are under investigation and coercing them into transferring money or sharing sensitive information.
- Fraudsters also manipulate victims psychologically, gradually building trust, urgency or fear before extracting money or personal information.
Exploitation of the Financial System’s Users
- Cybercriminal networks sometimes recruit ordinary individuals by persuading them to lend or provide their bank accounts, turning them into intermediaries for fraudulent transactions.
- Some such account holders may themselves be deceived and only later discover that their accounts have been used for criminal activity.
- This creates a layered fraud chain, where replaceable intermediaries face investigation while the principal organisers remain difficult to identify.
Important Concept: Social Engineering
- Social engineering refers to manipulating people into voluntarily revealing information or performing actions that compromise their security.
- Unlike purely technical hacking, such fraud exploits human psychology—trust, fear, urgency, greed or authority.
- Common examples include phishing, impersonation, OTP fraud, fake investment schemes and digital-arrest scams.
- The growing sophistication of social engineering means that technological security alone cannot eliminate cyber fraud.
Implications for India
- The expansion of digital payments increases financial inclusion and transaction efficiency, but simultaneously expands the potential surface for cyber fraud.
- Greater trust in digital systems can create overconfidence, causing users to lower their guard against suspicious communications.
- Organised fraud networks can exploit weaknesses across the banking, telecommunications and digital-platform ecosystems.
- Cybercrime therefore requires a coordinated response involving banks, payment platforms, telecom operators, law-enforcement agencies and users, rather than relying solely on individual vigilance.
Way Forward
- Strengthen financial cyber-security: Banks and payment platforms should improve real-time fraud detection, transaction monitoring and rapid freezing of suspicious accounts.
- Target organised networks: Law enforcement should focus on identifying the masterminds, mule-account networks and infrastructure supporting cybercrime rather than only apprehending account holders.
- Improve digital literacy: Public awareness must emphasise that trust in a payment system does not mean trusting every message, link, caller or request received through it.
- Strengthen inter-agency coordination: Financial institutions, telecom companies, technology platforms and police need faster information-sharing mechanisms for detecting and disrupting fraud.
- Promote responsible digital behaviour: Users should never share OTP, PIN, passwords or banking credentials, click suspicious links or transfer money under pressure from unknown callers.