Centre for

Corporate Laws and Governance

Dharmashastra National Law University, Jabalpur.

Blog

Cybersecurity Challenges in Digital Banking and UPI Transactions

Contents
  1. IIntroduction
  2. IIGrowth of Digital Banking and UPI
  3. IIIMajor Cybersecurity Threats in Online Banking
  4. IVCybersecurity Challenges Specific to UPI
  5. VRegulatory and Security Measures
  6. VIGaps Between Law and Practice
  7. VIISolutions and Best Practices
  8. VIIIConclusion

I. Introduction

The banking system of India has gathered remarkable pace, driven by the rapid growth in the use of the Unified Payments Interface. In 2025, transactions through UPI crossed 20.01 billion, with an accumulated value of about ₹24.85 lakh crore, marking the highest record to date. The bulk of retail online payment is now done through UPI, and it is a substantial move towards an economy that is cashless in nature. Users experience matchless ease while transacting through UPI, joined with instant peer-to-peer payments. There is a sense of comfort when merchants collect payment through UPI, and it can be done from a mobile phone alone.

As with anything that flourishes, people find ways to misuse it, and the same is happening here. The danger of misusing digital banking is cyber threats. In 2024, cybercrime jumped four-fold with cumulative losses of about $20 million. There were a total of 1.13 million banking-related crimes in 2023. This alone tells us how and why cyberattacks are hampering the development of the digital economy. In 2024 alone, ₹22,800 crore in losses were suffered by Indians through the digital payment system. With the rise in online payment — and it will definitely grow — there will always be the threat of cyberattack, leading to vulnerabilities.

This blog highlights the key cybersecurity difficulties that persist in the online banking payment system, including UPI, and focuses on the challenges that are new and specific to Unified Payments Interface systems.

II. Growth of Digital Banking and UPI

The rise of UPI changed the dynamics of the payment structure. The Unified Payments Interface was ushered in in 2016 to make the banking system of India efficient and fast. In its early days the transactions were only a few million, but by August 2025 the monthly count reached 20,008.31 million, worth around ₹24.85 lakh crore.

This kind of growth tells us how online banking has changed in recent years. There are now minimal bank visits by customers and an increase in mobile banking transactions, immediate fund transfers, and on-demand financial services. These transformations bring new challenges of their own. As digital banking brings more convenience, it also increases people’s vulnerability to cyberattacks.

III. Major Cybersecurity Threats in the Online Banking System

Cybercriminals target the digital banking and UPI system, and this trend has increased in recent years, carried out through various methods. Below are the major threats that users and corporations must be aware of.

  • Phishing and vishing attacks. Phishing is done through fraudulent emails, SMS or links that seem legitimate but trick users into entering their information or PINs. Vishing, or voice phishing, is where attackers call users impersonating bank officials and ask them to disclose bank details and sensitive credentials. For example, a fraudster made a user believe he was a bank official and asked the user to share his PIN to authorise ₹1 lakh.
  • Malware, ransomware and fake apps. Malicious applications pretend to be official bank apps. Once installed, they collect important credentials, monitor SMS and intercept OTPs. For example, an Android banking malware impersonates an official banking app, steals login credentials and runs background crypto mining. Microsoft has repeatedly flagged trojans propagated through social media that lure users into downloading fake apps.
  • SIM swap and OTP hijacking. Fraudsters transfer the victim’s mobile number to a SIM under their control. This results in interception of OTPs and password resets, and severely weakens SMS-based two-factor authentication. In one case, a woman in Ghaziabad lost ₹18.5 lakh after her SIM was hijacked through fake upgrade calls, which enabled multiple fraudulent transactions.
  • Social engineering. Fraudsters inflict damage on the psychology of people, leveraging their fear of losing something. They often claim there is an account problem, or persuade people to install remote-access apps. These methods often succeed even with people who have knowledge about them.

IV. Cybersecurity Challenges That Are UPI-Specific

UPI has made a transformative contribution to the landscape of digital payment in India, but it has also opened up vulnerabilities that cybercriminals exploit. Below are some of the challenges specific to UPI.

A. Fake QR Codes and Fraudulent Apps

Attackers may generate counterfeit QR codes — a method often called quishing — and paste them over a merchant’s real QR code. When a customer scans it, the payment is routed to the scammer’s bank account. These fake QR codes sometimes direct the user to a different website where their credentials are phished. Attackers also create clone UPI apps, which trick users into entering their login credentials, OTP or UPI PIN. Some fake apps even display a transaction-completed screen while the actual transfer of money never happened.

B. Unauthorised Access: Weak Authentication and SIM Swap

Though UPI makes two-factor authentication compulsory, its reliance on SMS/OTP becomes vulnerable when the SIM is hijacked. A scammer who gains full control of the mobile number may reset the UPI PIN and authorise transactions. Additionally, if device binding and biometric authentication are poorly designed, attackers may also bypass them.

C. Data Privacy and Third-Party App Risk

Many users run third-party UPI apps; these apps may ask for excessive permissions and potentially gather important data. If such apps are compromised or poorly designed, there is a high chance of data leakage.

D. Social Engineering via WhatsApp and SMS

Attackers use messaging apps to pretend to be friends, merchants or officials. They might send a QR code framed as a request for money, prompting the user to scan the link and authorise a payment.

These UPI-specific problems highlight how rapidly evolving fraud tactics continuously target both the technology and its users.

V. Regulatory and Security Measures

India has adopted a multi-pronged regulatory approach to protect the digital banking and UPI system. Below are the major measures adopted to protect users and to close the gap between law and actual practice.

A. RBI and NPCI Regulation

The RBI Cybersecurity Framework mandates all banks and financial institutions to implement board-approved cybersecurity measures, conduct continuous risk assessment, make contingency plans, encrypt data, and implement vendor risk management. In parallel, NPCI issues guidelines related to UPI and has made two-factor authentication, device binding and limits on transaction volumes compulsory to prevent fraud.

B. The IT Act and the Data Protection Regime

The Information Technology Act makes certain cybercrimes punishable, such as hacking and unauthorised access. But there is a lack of comprehensive protection for financial data. The goal of the data protection legislation is to close those gaps by imposing obligations on how personal and financial data is used, stored and transferred. Data localisation is also mandated in India, requiring that payment system data be stored within the country; this reinforces control over sensitive information.

C. Inbuilt Security Features in UPI Apps

UPI introduced two-factor authentication through mobile number validation and entry of the UPI PIN, often combined with device binding and biometric authentication. There is also a transaction limit on UPI of ₹1 lakh, with certain categories allowing a higher threshold. Recently, UPI has allowed transactions of up to ₹10 lakh for person-to-merchant (P2M) payments in selected categories, while strict controls remain on P2P transactions.

VI. Gaps Between the Law and Practice

Despite various strict guidelines, enforcement lags behind. Some smaller banks and third-party apps lack cybersecurity maturity. Additionally, there has been delay in passing robust data protection law. Dependence on SMS/OTP for two-factor authentication remains weak because of SIM swap. Moreover, after a fraud, victims often face a slow grievance process and do not recover full damages even when claimed under the regulations.

VII. Solutions and Best Practices

To fight evolving threats in digital banking and UPI transactions, stakeholders should implement a layered, practical security approach. Below are the important solutions and best practices.

A. Multifactor Authentication and Biometrics

The SMS/OTP system has become obsolete. There should be use of dynamically generated authentication factors along with device binding or verification through biometrics such as fingerprint and face ID, to create strong identity assurance. The RBI has advised the introduction of Additional Factor Authentication (AFA) to make transaction validation more robust.

B. Encryption and Secure Channels

Data in transit and at rest should use strong encryption such as TLS and AES-256. Sensitive keys and tokens must be stored in isolated, secure modules. APIs, SDKs and backends should adhere to secure coding practices and undergo continuous penetration testing.

C. Fraud Detection through AI and Machine Learning

With the help of artificial intelligence and machine learning models, there should be continuous supervision of transaction patterns to identify anomalies and flag suspicious behaviour in real time. NPCI is leading a federated AI model with banks to detect fraud. The Department of Financial Services has urged banks to adopt AI/ML models to identify and restrict suspicious accounts and other fraud arrangements. The RBI’s MuleHunter.AI also identifies mule accounts by analysing transaction patterns.

D. User Awareness and Financial Literacy Campaigns

A technical solution is not sufficient without a well-informed user base. Continuous reminders through messages, emails, SMS and app notifications can keep users updated on new methods of fraud. Google’s DigiKavach is a strong example of a public–private awareness effort.

VIII. Conclusion

At a time when digital payment has become the backbone of India’s economic and social life, robust cybersecurity is not optional; it is compulsory. It is fundamental to maintaining trust, protecting users, and guaranteeing the integrity of the financial system. As digital banking and UPI transactions grow further, every stakeholder — banks, regulators, fintechs and users — carries a responsibility, and those responsibilities are shared. Institutions need to build resilient systems and apply security standards, while regulators must supervise strictly and provide the right incentives. The battle against fraud cannot be won by technology alone; collaboration and human vigilance matter just as much.

Scroll to Top