News · Science & Technology

Why growing trust in digital payments may be leaving Indians more exposed to cybercrime

Why growing trust in digital payments may be leaving Indians more exposed to cybercrime

Trust can become a blind spot. Digital payments feel reliable because they are fast, familiar, and widely accepted. But confidence may make users less likely to question unexpected requests, links, calls, or payment instructions. That matters because fraud often targets behaviour, not the payment technology itself. The report found that 28% of cybercrime victims considered online banking “very safe,” compared with 14% who considered it “very unsafe.” Highly vulnerable users were also especially confident: 49% called online banking very safe, while another 39% called it somewhat safe. Frequent UPI users were more likely to have been victims than people who never used it. This does not prove that using UPI causes victimisation. It shows a troubling association between heavy use, high confidence, and exposure. As digital payments expand, users need habits that match their trust: checking senders, refusing unknown requests, and never sharing OTPs or personal details.

Based on reporting by The Hindu

How can growing trust in digital payments leave people more exposed to cybercrime?

Trust can become a blind spot. Digital payments feel reliable because they are fast, familiar, and widely accepted. But confidence may make users less likely to question unexpected requests, links, calls, or payment instructions. That matters because fraud often targets behaviour, not the payment technology itself.

The report found that 28% of cybercrime victims considered online banking “very safe,” compared with 14% who considered it “very unsafe.” Highly vulnerable users were also especially confident: 49% called online banking very safe, while another 39% called it somewhat safe. Frequent UPI users were more likely to have been victims than people who never used it.

This does not prove that using UPI causes victimisation. It shows a troubling association between heavy use, high confidence, and exposure. As digital payments expand, users need habits that match their trust: checking senders, refusing unknown requests, and never sharing OTPs or personal details.

How widespread are UPI and other digital payments in India?

Digital payments are no longer limited to large shops or online purchases. In India, UPI is used by everyday customers, vegetable vendors, auto drivers, doctors, and roadside stalls. Its scale matters because a huge user base creates both economic convenience and an attractive target for cybercriminals.

UPI processed more than 24,000 crore transactions in FY 2025-26, with total value crossing ₹314 lakh crore. About 49% of respondents used UPI apps every day, and another 24% used them once or twice weekly. UPI was also the most frequently used online payment method, with 48% using it many times.

The wider digital environment is similarly large. About 70% of India’s population is connected to the internet. As more people rely on digital payments, safety awareness must grow alongside access, usage, and trust.

What is UPI, and how does a QR-code payment work?

UPI, or Unified Payments Interface, lets people move money directly between bank accounts using a mobile application. It matters because users can pay without handling cash, counting change, or entering lengthy bank details. The same system works for small roadside purchases and larger digital transactions.

At a tea stall, a customer opens a UPI app and scans the seller’s QR code. The code contains payment information identifying the recipient. The customer enters or confirms the amount, checks the recipient, and authorises the transaction with a UPI PIN. A confirmation message or beep then indicates that the transfer has been processed.

The article describes this routine as a daily habit across India. Its convenience has helped make UPI the most frequently used online payment method in the survey. However, users must still verify payment requests, because a QR code or convincing instruction can be used in a scam.

What does the report reveal about the relationship between payment habits, confidence in online banking, and cybercrime victimisation?

The report compares three linked patterns: how often people use digital payments, how safe they think online banking is, and whether they experienced cybercrime. The core finding is an association, not proof that payment use directly causes victimisation. It suggests that confidence can coexist with unsafe online behaviour.

Highly vulnerable respondents were especially confident. About 49% called online banking modes “very safe,” and another 39% called them “somewhat safe.” Among cybercrime victims, 28% considered online banking very safe, compared with 14% who considered it very unsafe. People using UPI many times were also more likely to report victimisation than those who never used it.

The pattern matters because frequent users encounter more payment interactions and may let familiarity lower their guard. Digital payment systems can remain useful and trusted, but users need stronger caution around links, unknown callers, files, OTPs, and unusual requests.

What kinds of scams are cybercriminals using to trick digital-payment users?

Cybercriminals are using elaborate deception rather than relying only on obvious fake messages. Their goal is to make a victim believe the interaction is genuine, urgent, or profitable. This matters because a trusted conversation can persuade people to reveal information or transfer money voluntarily.

The report describes fraudsters creating entire investment or betting apps that appear convincing. In other cases, they hold victims under “digital arrest” for several days. By sustaining fear, authority, or apparent opportunity, they gain trust and persuade victims to share personal information. The report also highlights unsafe behaviour involving unknown links, files, photos, videos, and OTP requests.

These methods show why secure payment technology alone cannot prevent every fraud. The criminal may not need to break the payment system if the victim authorises the action. Users should pause, independently verify identities, avoid unknown links, and never disclose OTPs or sensitive information under pressure.

How do fraudsters obtain SIM cards, bank accounts, and phones, and why do they recruit ordinary account holders?

The report describes cybercrime as an organised supply chain. Fraudsters do not always build every part of their operation themselves. Instead, they can obtain packages containing pre-activated SIM cards, bank accounts, and mobile phones. This lowers the effort needed to contact victims, receive money, and hide the operation.

A cybercrime expert said such kits cost about ₹10,000–20,000. The report also interviewed two people accused of cybercrime who said they had lent their bank accounts to fraudsters who deceived them. Their accounts became part of a crime they did not fully understand. The accounts then served as channels for stolen money.

Recruiting ordinary holders gives the main fraudsters distance from the transaction and makes account owners easier to replace. The report says these users may be apprehended by police as the most replaceable link, while organisers remain untouched. This reveals a financial and human chain behind many digital scams.

What are phishing, social engineering, and OTP theft, and why can human trust weaken otherwise secure payment systems?

Phishing is a deceptive message, website, or link designed to obtain information or trigger an unsafe action. Social engineering is the broader manipulation of a person through trust, fear, urgency, or authority. OTP theft occurs when a criminal tricks someone into revealing a one-time password or approving a transaction. These methods target judgement rather than software.

For example, an unknown caller may pose as a bank official and ask for an OTP. A fake message may urge someone to open a link, download a file, or confirm account details. The article specifically measures willingness to share an OTP with an unknown caller and open content from unverified senders or strangers.

Digital payment security cannot fully help if a user willingly hands over credentials or authorises a transfer. That is why caution matters: verify the sender independently, reject pressure, avoid unknown links, and keep OTPs private. Trust should support safe use, not replace verification.

Key Facts:

📌 Twenty-eight percent of victims called online banking “very safe.”

📌 Highly vulnerable users showed unusually high confidence in online banking.

📌 Frequent UPI users were more likely to report cybercrime victimisation.

📌 UPI processed over 24,000 crore transactions in FY 2025-26.

📌 UPI transaction value crossed ₹314 lakh crore.

📌 Forty-nine percent of respondents used UPI apps daily.

📌 UPI means Unified Payments Interface.

More on JupiteX