In Focus: Convenience vs Security in UPI
How often does the average person use UPI apps in a single day? The answer varies widely. For some, it may involve just one major transaction, such as paying rent or settling a bill. For others, it is woven into nearly every routine activity, enabling a steady stream of small payments: buying groceries, paying for transport, splitting meals, or ordering food. This wide variation reflects how deeply digital payments have embedded themselves into everyday life in India. The scale of this transformation is remarkable. In 2025, UPI transactions reached approximately 228.4 billion, and the number continues to rise rapidly. What began as a convenient payment option has evolved into the backbone of India’s retail payment ecosystem. From metropolitan cities to small towns and rural markets, UPI has improved accessibility and made financial transactions faster, simpler, and more inclusive.
However, this rapid expansion has also exposed underlying vulnerabilities. Nearly a decade after digital payments became mainstream, concerns around security are becoming increasingly difficult to ignore. The Reserve Bank of India (RBI) has flagged several recurring issues, particularly in the domain of cybersecurity. The data highlights the scale of the problem. In 2025 alone, close to 28 lakh cases of cyber fraud were reported through the National Cyber Crime Reporting Portal. Even more concerning is the cumulative impact: between 2021 and 2025, Indians collectively lost nearly ₹22,900 crore to cyber fraud. These figures reveal a stark reality that while digital payments have brought unprecedented convenience, they have also created new avenues for exploitation.
A closer look at UPI-specific figures further reinforces this concern. In FY24, around 1.34 million cases of UPI-related fraud were reported, leading to losses of approximately ₹1,087 crore. These are not isolated incidents but part of a broader pattern, suggesting systemic gaps that need to be addressed. As adoption grows, so too does the incentive for fraudsters, making stronger safeguards increasingly necessary.
Understanding the Nature of UPI Fraud and Vulnerable Groups
UPI-related fraud is not limited to a single demographic; it cuts across age groups, income levels, and regions. However, certain groups appear to be more vulnerable. Digitally inexperienced individuals, lower-income households, and rural users are often targeted due to limited awareness or access to reliable information. At the same time, younger users aged 18–25 and middle-aged individuals between 41–60 have also emerged as frequent targets, highlighting that familiarity with technology does not always translate into caution.
The methods used by scammers are varied and constantly evolving. One common tactic is the fake “collect request” scam, where users are tricked into approving a payment request under the impression that they are receiving money. In reality, they end up transferring funds to the fraudster. Similarly, fake QR code scams involve replacing legitimate QR codes with fraudulent ones, redirecting payments without the user realizing it. Phishing scams continue to be a major concern. These often appear as fake SMS messages, WhatsApp texts, emails, or links that prompt users to share sensitive information such as UPI credentials or OTPs. Once this information is compromised, fraudsters can quickly gain access to accounts. Fake customer care scams add another layer of deception, with perpetrators posing as bank or app representatives and convincing users to disclose confidential details. More sophisticated techniques, such as SIM swap fraud, further complicate the issue. In such cases, scammers take control of a user’s mobile number by transferring it to another SIM card, allowing them to intercept OTPs and bypass authentication systems.
What makes these scams particularly effective is their reliance on psychological manipulation. Fraudsters frequently create a sense of urgency, claiming that an account will be blocked or a payment will fail to push users into making quick decisions without verification. They may also impersonate authority figures or exploit emotional triggers to gain trust. This combination of technical and psychological tactics makes UPI fraud both pervasive and difficult to combat. Given the diversity and sophistication of these methods, addressing the issue requires more than just technical fixes. It calls for a combination of user awareness, institutional safeguards, and proactive regulatory measures.
A Layered Approach to UPI Security
In response to the growing risks, the RBI has proposed a set of safeguards aimed at strengthening the security of digital payments. One of the most notable measures is the introduction of a time lag for transactions exceeding ₹10,000. Under this system, such payments would not be processed instantly. Instead, the bank would provisionally debit the amount, giving users a window of time to cancel the transaction if they suspect fraud. This measure is intended to counter urgency-based scams, where victims are pressured into making immediate payments. By introducing a delay, users are given an opportunity to reconsider and verify the legitimacy of the transaction.
Another proposal involves an additional authentication layer that includes a third trusted person. This is designed to protect individuals who may be more susceptible to manipulation, providing an extra checkpoint before completing certain transactions. Alongside this, the RBI has suggested introducing a digital payment control mechanism, including an on/off “kill switch” and customizable transaction limits at the account level. These features would allow users to quickly disable payments if their device is compromised and to better manage their financial exposure. The RBI has also focused on tackling mule accounts which are bank accounts used by fraudsters to move and launder stolen funds. To address this, it has proposed capping incoming credits into certain accounts unless a legitimate business relationship is verified. This would help identify suspicious activity early and reduce the ability of scammers to layer transactions and obscure money trails.
Together, these measures aim to address some of the most common forms of fraud. The time lag targets urgency-driven scams, additional authentication disrupts impersonation tactics, and the kill switch empowers users with greater control. Meanwhile, stricter monitoring of account activity seeks to weaken the infrastructure that supports large-scale fraud.
Balancing Protection and Convenience: The Road Ahead
However, these proposals have also raised concerns about their practical effectiveness. One of the primary criticisms is the potential impact of the time lag on user experience. UPI’s success has largely been built on its speed and convenience, and introducing delays even for high-value transactions could undermine this advantage. For many users, especially in fast-paced environments, instant payments are not just a convenience but a necessity. There is also concern that such friction could push users back toward cash transactions, particularly for larger payments. Similarly, the requirement for third-party authentication may be seen as intrusive, especially by older individuals who value their independence in managing finances.
Another major criticism is that the framework appears too generalized. Digital fraud is highly nuanced, with different scams requiring different countermeasures. A uniform approach may not be flexible enough to address the full range of threats effectively. Additionally, there are concerns that existing mechanisms to detect and prevent mule accounts are already insufficient, raising questions about how effectively new measures would be implemented.
Despite these challenges, the need for stronger safeguards is clear. As digital payments continue to expand, a larger share of everyday transactions will move online. Without adequate protections in place, the scale of potential fraud could increase significantly. Ultimately, the RBI’s proposals should be viewed as a starting point rather than a final solution. They create an opportunity for dialogue between regulators, banks, and users to refine and improve the framework. The goal is not just to introduce safeguards but to ensure they are both effective and user-friendly.
The central challenge lies in balancing security with convenience. Too much friction could discourage adoption, while too little could leave users vulnerable. Striking this balance will be critical to sustaining trust in India’s digital payment ecosystem. If done right, these measures could help ensure that as digital transactions continue to grow, they do so within a framework that prioritizes both innovation and safety.
Top Stories of the Week
Government Notifies ₹ 10,000 Crore Startup India Find of Funds 2.0
On April 13, 2026, the Ministry of Commerce and Industry notified the Startup India Fund of Funds 2.0 (Startup India FoF 2.0) with a corpus of ₹10,000 crore to boost the country’s startup ecosystem. The scheme builds on the earlier Fund of Funds for Startups (FFS 1.0), launched in 2016 under the Startup India Action Plan. With an allocation of Rs. 10,000 crore, FFS 1.0 addressed critical funding gaps and supported over 140 Alternative Investment Funds (AIFs), which have collectively invested more than ₹25,500 crore in 1,370 startups.
FoF 2.0 will continue to operate through AIFs, with a sharper focus on priority segments such as deep tech and early-growth-stage startups. AIFs will be selected by a Venture Capital Investment Committee (VCIC), governed by the Department for Promotion of Industry and Internal Trade (DPIIT) with oversight from an Empowered Committee, while the Small Industries Development Bank of India (SIDBI) will serve as the implementing agency. The scheme aims to address funding gaps and support innovation in line with the government’s vision of Viksit Bharat @ 2047.
Delhi-Dehradun Economic Corridor Signals Push for Faster Regional Connectivity
Prime Minister Narendra Modi inaugurated the Delhi-Dehradun Economic Corridor on April 14, 2026, marking a significant step in India’s ongoing efforts to modernise road infrastructure and improve regional connectivity. Spanning over 210 km, the access-controlled corridor is set to reduce travel time between Delhi and Dehradun from over 6 hours to around 2.5 hours, significantly improving regional mobility.
Developed by the National Highways Authority of India (NHAI), the six-lane expressway passes through Delhi, western Uttar Pradesh, and Uttarakhand, easing congestion on existing routes while strengthening connectivity to key districts. Beyond faster travel, the corridor is expected to enhance logistics efficiency and unlock economic activity across the region, particularly in tourism and local enterprise.
The project also reflects a more balanced approach to infrastructure planning, incorporating sustainability measures such as an 11-km elevated wildlife corridor through Rajaji National Park and dedicated animal crossings. With modern features including interchanges, wayside amenities, and intelligent traffic systems, the expressway aligns with India’s broader push towards high-quality transport networks.
A Few Good Reads
Naushad Forbes argues that in a world too dependent on other countries, India should move beyond self-reliance and pursue interdependence by building domestic strength and ensuring others are as dependent on it.
Shyam Saran writes that a post-Iran war West Asia order can open strategic space for India as a US-led security architecture in the region, including Israel as a key pillar, has diminishing prospects.
Rajiv Memani frames the Jan Vishwas reforms as a move towards a trust-based regulatory framework by decriminalising actions that should never have been punishable, while calling for a comprehensive audit and deeper clean-up of remaining laws.
Sreelakshmi Hariharan and Mukund Govind Rajan emphasise that MSMEs sit at the centre of the country’s economic development but receive only a small fraction of green finance flows, making new financing structures critical.
Dani Rodrik notes that for AI to work for us, it must not think for us, warning of the displacement of human thought and the erosion of the knowledge base it depends on.


