In today’s rapidly evolving digital landscape, securing the future of payments is paramount. There is an imperative need for constant innovation, agile adaptation to emerging threats, and unwavering commitment to regulatory compliance. A compilation of speeches delivered at the event—“Securing the Future of Digital Safe Payments.”
Crime & the opportunity
V Rajendran, Chairman, DiSAI
Crime is quite old. When the first man and woman came on earth, crime also came in simultaneously. Crime has penetrated technology, and technology has also penetrated crime. There are three sides to a crime and we call it the crime or fraud triangle. The first side is the intention, need, greed or the urge to commit a crime. The second is rationalisation or justification of the crime. In movies, if a hero commits a crime, it is acceptable and if a villain commits the crime, it is not acceptable. The third is the opportunity.

We must be focussed on reducing the opportunity to commit a crime and for this, everyone must have awareness. The less we give opportunity, the less we’ll be victimized in a crime. Nowadays, to become a cybercrime victim is extremely simple. If you give your mobile phone to someone, within a minute, they can inject it with a malware and can keep tracing your phone. Associations like Digital Security Association of India and seminars and conferences on digital security are all focused on how we can avoid giving any opportunity for crimes. Often, we share confidential data, click unsolicited links or fall into traps. We should not become vulnerable to frauds.
Remember the safeguards
Uma Sankar, Regional Director, RBI
Being in the Reserve Bank, we are also privy to certain latest types of cybercrimes that are taking place. The number of cybercrime complaints have risen from 9.67 lakh in 2022 to 11.5 lakh in 2023. In terms of amount, it is a whopping Rs.5,574 crore, which was reported just between January and October 2023. It is significantly higher than the corresponding figures of 2022. The types of financial frauds basically include customer care number frauds, KYC based frauds, Aadhaar enabled payment systems based frauds, etc. In the Aadhaar enabled payment transactions, even dummy or rubber fingers are being used to falsify biometric authentication. While we thought that biometrics is the ultimate safeguard, even that is being falsified. Micro ATMs are misused to siphon off money.
The amount of recovery of money has been abysmally low—just 10%. Each one of us has a role to play and if we play our part well, perhaps we can try to minimise, if not completely avoid or root out cybercrime. We are living in a digital world and many of us do not go to a bank today. Net banking was considered to be a safe haven, but even here, frauds are being committed. We have the QR code-based cashless digital payments. RBI is also backing the Central Bank Digital Currency (CBDC). Cryptocurrency is speculative in nature and does not have any backing. The RBI governor has frequently warned against crypto, though the technology on which it rides—the blockchain—lends itself to wonderful benefits for the entire financial ecosystem.
There is no escape from artificial intelligence and machine learning but we have also seen how hackers use AI today to mimic our own voices and victimise us. Technology is always a double-edged sword. I am not advocating that we get back to the bullock cart age and don’t do any digital transactions. Of course, we need to do it but we have to be aware. The RBI has brought out a series of comics called Raju and the 40 Thieves. We keep updating it with the latest financial crimes including cybercrimes.
Triple Safeguards
We must use a three-pronged approach to safeguard us and it involves people; processes; and policies and governance frameworks. People must be empowered through training and awareness on cyber hygiene. When we go for supervision and auditing of entities, we emphasise these things and we see whether the governance and their assurance are functioning in the regulated entities. We look at the IT systems and if it meets our expectations.
In the recent past, RBI has come down very heavily on certain entities, which, having promised digital products, have not been able to deliver that, resulting in a lot of customer inconvenience. We have all the antivirus, firewall, intrusion detection, software updates and Vulnerability Assessment & Penetration Testing (VAPT). When the banks and other regulated entities also have them in their place, they can minimise the incidence of cyber frauds.
We come across social media frauds, mobile security breach, near field communication frauds, SIM swapping, FinTech frauds and so on. At RBI, we conduct many outreach programs and educate the public on various methods to be cyber-safe. We have been actively collaborating with the police, the State governments and the government of India to make people more aware about what they can do at an individual level.
Limited Liability
You must have heard about ‘limited liability,’ which the Reserve Bank has introduced. If any cyber fraud is reported to the bank by a customer through a visit or call to the bank or to the call centre, then the bank becomes responsible for any money siphoned off from the customer’s account after the fraud is reported. Then we have an important circular for outsourcing of IT services. When any entity grows, they can’t do everything inhouse. We have asked the banks to follow certain digital payment security controls. We have directions on UPIs and the comprehensive cyber security framework.
The Reserve Bank of India through various regulations has been trying to have a level playing field between various entities. Earlier, we used to have a separate set of instructions for commercial banks, for non-banking financial companies, and for cooperative banks. Now we have realised that there are certain common minimum standards, which any entity has to adhere to.
Banking Ombudsman
We have the Integrated Banking Ombudsman scheme. Some of the big corporate banks are supposed to have an internal ombudsman who will process your complaint and see if it’s justified. If, even after a month, your grievance is not redressed, you can approach the RBI portal and apply under the integrated banking ombudsman scheme by producing sufficient documentary evidence that you have been scammed; that you have informed the bank (date to be specified); and that you have approached the bank in the first instance to get your grievance redressed but it stands unaddressed or you are not happy with the redressal of the grievance.
Also, there is a myth that QR code can be used for receiving as well as sending payments. But please be aware that it is meant only for sending payments and not for receiving money. Many people have been duped without this awareness. Recently, we come across many investment scams. Even some of our educated colleagues who have been dealing in the stock market have been duped. They buy stocks based on the advice of an investment analyst or a broker and their stock prices go up. They invest more and when they want to sell those shares for a profit, things will not move. Then only they realise that they have been scammed.
In social engineering scams such as the FedEx parcel scam, the scamster digitally arrests you in your home and terrorise you that you are not even able to even respond. They somehow manage to jam your phones and you are not able to make any calls. If someone says that the police is going to arrest you, just say, ‘Thank you for the information. I will contact the nearest police station.’
One of our retired colleagues received such a call and the scamster told him that he has to verify his bank statement for any unauthorised transaction and asked him to send some money. How can anyone verify an account by one transaction? He sensed something sinister and said, ‘Thank you very much. I will take care.”
In the recent past, even the Reserve Bank governor’s signature was forged and scam letters were sent soliciting deposits from people. Then links were sent for revival of accounts. Sharing passwords or pins have become slightly cliched. Currently, the modus operandi is sending you a suspicious link, which is basically sending you a link for doing something very legitimate. Once you click that, the entire contents of your mobile or money in your account get wiped out.
Money Laundering
The Reserve Bank has found that fraudsters take over the accounts of very poor people from marginalized sections, who do not have much awareness but who look up for a quick way of earning money. They sell their passbooks or accounts for a certain sum of money. Within a short period, these accounts would see huge inflow and outflow of money, obviously linked to money laundering. We have cautioned banks to monitor suspicious transactions and reported to Financial Intelligence Unit (FIU). Such things can’t be traced manually. They must be tracked only through software.
The MLM schemes—the pyramid kinds of schemes—are also going up today. The instant loan app fraud is on the rise. The apps are very malicious and fake. Basically poor people who want very small sums of money use these apps and they end up being extorted for huge sums of money. The RBI has issued digital lending guidelines to make the customers, as well as the banks, aware about their duties and responsibilities so that they should not become victims.
Avoid loan apps that are not affiliated with any RBI registered bank or NBFC. All the others are unregulated and could be illegal also. These are some of the safeguards that we must follow. Don’t download any app from App Store which is unverified. Avoid loan apps which don’t have clear cut terms and conditions. Check the lenders’ website for a physical address, and especially if the lender is giving suspiciously attractive interest rates.
Though we have educated members of the public, we feel that greed is something common to all. People fall prey to greed and invest in schemes that promise 15% or 20% return. The return is great in the beginning but that runs out after three or four months and the principal is entirely lost. We have a state level coordination committee headed by the Chief Secretary of the State and the Reserve Bank of India, who is the convener of the forum. It meets every quarter and we provide market intelligence inputs to the forum, so that the law enforcement agencies are able to take it forward.
An indicative list of safeguards:
- Do not use open Wifi.
- Install antivirus on your mobile.
- Do not log into internet banking in browsing centers.
- Do not use unauthorised loan apps.
- Use social media pages wisely.
- Manage your debit card and credit cards. Place limits on your cards, with which, you can limit your loss.
- Don’t share OTP and CVV.
- Do not install apps from unauthorised sources
- Review your mobile app permissions regularly.
- Lodge any complaints of loss within the golden hour.
Customers have to play their part
Mr Benjamin Ambrose,Chief Information Security Officer (CISO), National Payments Corporation of India (NPCI)
UPI is one of our flagship products. We have products like AEPS, which is Aadhar Enabled Payment System. We have around 10 plus products. We are enabling CBDC (digital currency) on behalf of RBI. We are considered predominantly as a network, just as the network service providers for credit cards. Networks have a responsibility in stemming these frauds. Banks and third party application service providers are the second part of the ecosystem.
We ensure that cyber security processes, technology and people are really attuned to what they do. Even when a small feature is introduced in UPI, we, along with the fraud risk management team, collaborate, look at the abuse cases, think of what can happen, and we present it to various internal committees, board risk management committee and also the RBI. A lot of thought process goes behind launching even a minor feature in the market.
Since the technology explosion happened, India has leapfrogged. We went straight into mobile and that too, mostly smartphones. Unfortunately, mobile is a complicated space. I was working with banks five years ago. As an information cyber security expert, I told them that we must shut down our mobile banking application if we sense that the device is jail broken. The head of business stared at me and asked me, “Ben, do you want me to drop $500 million business on the table?” I was doing a regional role while he was managing 14 markets across Asia Pacific. But after two years, I was able to convey my point. The regulators have also stepped up their game. The Monetary Authority of Singapore was one of the thought leaders in this space across Asia Pacific, besides the RBI.
The cybercriminals operate like a business. We compete hard but we play the defence and catch-up game while they play offensively. That is why, education and awareness is key. Criminals play on the minds of the people. NPCI is spending a lot of money on prime time advertisements where we educate people. It is a hard game. I’ve been in this industry for 20 years. Day in and day out, we fix technological vulnerabilities, but it is difficult to fix the vulnerabilities of people. We always say that our staff can be our weakest links, because they click on a phishing link and download malware into our environment. The malware spreads and we do not have any control.
The DPIP Platform
The RBI has come up with a program called DPIP: Digital Payments Intelligence Platform. A protocol will be defined by this committee in which every player, networks, banks and third-party application providers will be given specific instructions on how to share intelligence in a centralised manner and how to consume data. There is common minimum cyber hygiene for every financial institution at varying levels. We cannot expect a cooperative bank to be operating or competing at the level of an international bank. DPIP will give a level playing field to everyone.
In NPCI, we try to pass intelligence, especially in the mule account activity and anti-money laundering activity, back to the banks. But our transactions are mostly small ticket items. The amount of information that we feed to the banks is huge. They, in turn, use auto diallers to reach out to customers. As a customer, if I get an automated voice message from the bank, I feel really suspicious and doubt if it is genuine or from a fraudster. It is totally ineffective. Even when the bank decides to call the customer for at least high ticket items, the customer gets irritated.
What we recommend as part of the DPIP program is that the banks should go and ask the next steps like, ‘What is the purpose of the transfer?’ to see if we can warn the customers before they end up in a fraud. To summarise, the customers have to play their part; and the ecosystem, along with the regulator, has to play their part together. We cannot eliminate frauds but we can certainly strive towards minimising them.
Psychological reasons are behind digital frauds
R Lakshmi Venkatesh,General Manager, Indian Overseas Bank.
I always used to say that fear and greed are the two elements which contribute to the digital payment frauds. But now, I would like add ‘curiosity’ to the list. We have approximately one crore digital payment transactions every day. That is approximately 30 crore transactions every month. Out of this, roughly 90 percentage is UPA transactions. All other digital payment channels, like cards, ATM transactions, IMPS, AEPS based transactions contribute to about 10 to 12 percentage. As a banker, I can confidently say that the digital payment frauds are not happening because of the flaws in the system. It is more because of psychological reasons and the fraudsters entice people to make some compromise.
One of the recent frauds is the employment scam. They post on Facebook or WhatsApp about part-time jobs and ask you to click a link. It arouses your curiosity and you click the link. They start with Rs 5000 as payment if you complete some tasks. They then keep on increasing the amount but ask you to make a caution deposit of one lakh. If you have already received Rs 2000 or Rs 5000, you trust them. They add you in a WhatsApp group. You see many people there and there are so many messages. They send you a QR code to make the deposit but once you make the payment, you are removed the group. UPI transaction has a cap of one lakh rupees per day. The frauds are big in number, though the value of the fraud is very small. Similar modus operandi is followed for share market trading frauds.
Never allow anyone to help you in withdrawing the money while you are in an ATM. Do not trust anyone. They may swap the card and you will take their card thinking it is the original. We get calls about expiry of credit cards and debit cards or about overshooting the due date for electricity payments. They threaten that electricity will be disconnected if we don’t make payments. In all such cases, remain calm and reveal no information or try to confuse the caller.
It’s a war zone
Raghavendra K Ravi, Dy. Superintendent of Police, Cyber Crime Wing, T.N. Police, Chennai
People always want comfort. We don’t want our ego to be touched or cross-questioned. We think we are supreme. We don’t want to consult. We take our own decisions. This is very good. But when a terrorist enters a country, when cyber pornography is happening, when cyber security is breached and cyber scams spread across like coronavirus, we cannot have ego. We have to enter the field. It applies to all–the regulators, bankers, policemen, citizens and everybody. It’s a war zone and we are fighting cyber terrorism.
When people lose money to frauds, it is pathetic to see their plight. Their hands shiver even while signing a complaint letter. One of the victims told me that he brought all his money saved in Muscat and for the last one month, he had been lured into stock trading and scammed of 6 crores. He lost all his hard earned money. I generally promise the victims that I will catch hold of the cyber criminals—they should be called cyber gundas—and place them before the victims. Otherwise, the victims will lose their peace of mind and life.
The daughter of a senior official working in a government department was searching for a suitable groom on a matrimony website. She selected a UK doctor hailing from Chandigarh. But she fell into a trap and lost Rs 18 lakhs in just six hours. I investigated the case for 16 days during which, 800 phone numbers were scrutinised. I filtered three numbers and went to Delhi. I found that 36 bank accounts had been opened. I analysed the accounts and it took me to Aligarh where I got two persons, each having ten debit cards in one hand and another ten in the other hand. I went with a stun gun because I was dealing with cyber gundas. They have a better infrastructure than most of the departments in the government.
If you have more than 10 SIM cards, you will be imprisoned for three years but here I seized 1000s of SIMs from a single place, buried in the sand in Jharkhand. This is beyond imagination. Finally, I cracked the lady’s case. The scamster was a Nigerian who had uploaded another married person’s photo in the matrimonial website. He called the girl, pretending as if he was calling from Delhi airport. “Honey. I brought costly jewellery, laptops and other gifts for you from UK. But I am apprehended by the customs department. I need money to come out of it.” The girl believed the story and ended up losing her Rs 18 lakhs.
Through sophisticated ways, our money is siphoned off to other countries like Cambodia, Hong Kong and Taiwan. It becomes beyond our reach. One police constable who became a victim of a cyber fraud committed suicide. Do not allow the cyber virus to enter your house. My sincere advice is that people should believe in the system and not be carried away by ego.



