Why growing trust in digital payments may make Indians more vulnerable to cybercrime
At a roadside tea stall, a QR code neatly stuck on a biscuit tin will do more work than a cash register. Scan, password and a reassuring beep. No change to count, no note to fumble. In a country where your greengrocer, auto driver and doctor get paid the same way, digital payments, especially UPI, have become where bread and butter is bought and sold.
Scale is hard to overestimate. UPI processed more than 24,000 crore transactions in FY 2025-26 with transaction values exceeding ₹314 crore. As the world’s most populous country, India has 70% of its population connected to the Internet, making it one of the most sought-after global markets for Internet services and digital platforms. This large, eager and active user base is also a tempting target. One that is ripe for the picking by cybercriminals. The State of Policing in India Report (SPIR) 2026 shows how these two things meet: how India uses the Internet and how cybercriminals are one step ahead of users.
Wallet phone
Digital payments are a daily habit for Indians. About half (49%) of respondents use UPI apps every day, while another quarter (24%) use them once or twice a week. UPI also stood out as the most used online payment method, with nearly half (48%) saying they use it “many times”, ahead of card, wallet and NEFT/RTGS payment methods (Table 1).
Trust follows usage. UPI received the most trust of all payment methods, with a third (34%) of respondents considering it “very secure” and two in five (41%) considering it “somewhat secure”, meaning three out of four people consider it secure. Card payments came in second place, with around two in three (65%) seeing it as secure – 28% as “very secure” and 37% as “somewhat secure” – followed by wallet-based apps and mobile banking apps. Taking all methods of online banking together, the majority of respondents consider it safe, with around a quarter (23%) considering it ‘very safe’ and around two in five (40%) considering it ‘somewhat safe’. It’s a success story in itself. People trust the system they use all the time, and the system usually delivers.
The paradox of trust
The SPIR also asked a different set of behavioral questions that together measure how vulnerable a person is to dangerous online practices. Would they open a link from an unverified sender? Photo, video or file from a stranger? Share OTP with unknown caller? And so on.
When trust is juxtaposed with vulnerability, the pattern is striking. People most prone to unsafe online practices also had the most confidence in online banking. Among the highly vulnerable, about half (49%) rated online banking modes as “very safe” and a further 39% considered them “somewhat safe”. Among those with moderate to no vulnerability, only about a fifth on average consider online banking to be “very safe”.
Following this thread towards victimization, it was found that those who considered online banking regimes to be “very safe” were also more likely to be victims of cybercrime in the last 2-3 years. Among victims, 28% considered online banking modes to be “very safe” compared to 14% who considered online banking modes to be “very unsafe”. (Table 2). As their perception of safety decreased, so did their likelihood of becoming a victim.
Usage tells the same story. Those who use UPI “many times” were more likely to be victims of cybercrime in the last 2-3 years compared to those who used it “never”.
People’s high trust and use of online banking methods is met with an adversary that is organized and resourceful. In a report, a cybercrime expert described a supply chain that sells “kits” of pre-activated SIM cards, bank accounts and mobile phones to fraudsters. For a small investment of ₹10,000-20,000 in these kits, fraudsters can swindle someone’s life savings worth tens of crores or crores and remain largely untraceable. Victims interviewed further shed light on the various inventive schemes cybercriminals use to scam people. Fraudsters create entire investment/betting applications, convincingly hold victims under digital arrest for several days and gain victims’ trust and convince them to share personal information.
The scam doesn’t stop with the victims. Two people interviewed for this report, both charged with cybercrime, said they lent their bank accounts to fraudsters who tricked them into becoming part of a crime they didn’t fully understand. Fraudsters not only exploit loopholes in the financial system, but recruit its users and have them detained by the police as the most replaceable link in the chain, while they themselves remain untouched.
SPIR 2026 points to an almost paradoxical connection: the more people use digital payments, the more they trust them and the more likely they are to become victims of cybercrime. But that’s only one half of the picture. The other half is a sophisticated adversary who is armed with the right tools, exploits people’s trust in their financial systems, and quite tactfully plays on the human psyche to deceive their victims.
(Vinson Prakash is a researcher at Common Cause)
Published – 07 Oct 2026 08:30 IST