At a roadside tea stall, the QR code neatly taped on the can of biscuits now does more work than the cash box. A scan, a password, and a reassuring beep. No change to count, no note to fumble. In a country where your vegetable vendor, the auto driver and the doctor all get paid the same way, digital payments, especially UPI, have become a site where one’s bread and butter are bought and sold.
The scale is hard to overstate. UPI has processed over 24,000 crore transactions in FY 2025-26, with the transaction values crossing ₹314 lakh crore. As the world’s most populous country, India has 70% of its population connected to the internet, making it one of the most sought-after global markets for internet services and digital platforms. That vast, eager, and active user base is also a tempting target. One that is ripe to be picked on by cybercriminals. The Status of Policing in India Report (SPIR) 2026 shows how the two meet: how India uses the internet and how cybercriminals stay one step ahead of users.
The phone for a wallet
Digital payments are a daily habit for Indians. About half (49%) of the respondents use UPI apps every day, while another quarter (24%) use them once or twice a week. UPI also stood out as the most frequently used online payment method, with almost half (48%) saying they use it “many times”, ahead of card, wallet, and NEFT/RTGS payment methods (Table 1).
Trust follows usage. UPI garnered the most trust out of all payment methods, with a third (34%) of the respondents considering it “very safe” and two in five (41%) considering it “somewhat safe”, meaning three in four people consider it to be safe. Card payments came in second, with about two in three (65%) considering it safe — 28% considering it ‘very safe’ and 37% ‘somewhat safe’ — followed by wallet-based apps and mobile banking apps. Taking all online banking modes together, a majority of the respondents find them to be safe, with about a quarter (23%) finding them “very safe” and about two in five (40%) finding them “somewhat safe”. On its own, this is a success story. People trust a system they use constantly, and the system mostly delivers.
The trust paradox
SPIR also asked a different set of questions about behaviour, which together measure how vulnerable a person is to unsafe online practices. Would they open a link from an unverified sender? A photo, video, or file from a stranger? Share an OTP with an unknown caller? And so on.
When trust is set beside vulnerability, the pattern is striking. The people most prone to unsafe online practices were also the most confident about online banking. Among the highly vulnerable, about half (49%) called online banking modes “very safe” and another 39% considered them “somewhat safe”. Among those with moderate to no vulnerability, only about a fifth, on average, considered online banking to be “very safe”.
Following this thread towards victimisation, it was found that those who considered online banking modes as “very safe” were also more likely to have been victims of cybercrimes in the past 2-3 years. Among victims, 28% considered online banking modes to be “very safe” compared with 14% who considered online banking modes ‘very unsafe’. (Table 2). As perceptions of safety decreased, so did their likelihood of being a victim.

Usage tells the same story. Those who use UPI “many times” were more likely to have been victims of cybercrime in the last 2-3 years, compared to those who “never” use it.
People’s high trust and usage of online banking methods is being met with an adversary that is organised and inventive. A cybercrime expert in the report described a supply chain that sells fraudsters “kits” of pre-activated SIM cards, bank accounts, and cell phones. For a small investment of ₹10,000-20,000 in these kits, the fraudsters can swindle someone’s life savings worth tens of lakhs or crores, and remain largely untraceable. The interviewed victims further shed light on the various inventive schemes cybercriminals use to defraud people. The fraudsters create entire investment/betting apps, convincingly hold victims under digital arrest for several days, and gain victims’ trust and convince them to share personal information.
The deception does not stop at victims. Two people interviewed for the report, both accused of perpetrating cybercrime, said they had lent their bank accounts to fraudsters who deceived them, leaving them part of a crime they did not fully understand. Fraudsters are not only exploiting gaps in the financial system, but they are recruiting its users and leaving them to be apprehended by the police as the most replaceable link in the chain, while they themselves go untouched.
The SPIR 2026 points to an almost paradoxical association: the more people use digital payments, the more they trust them, and the more likely they are to be victims of cybercrime. But that is only one half of the picture. The other half is a sophisticated adversary who is armed with the right tools, exploits the trust people have in their financial systems, and quite tactfully plays on the human psyche to deceive their victims.
(Vinson Prakash is a researcher at Common Cause)
Published – October 07, 2026 08:30 am IST
Click Here For The Original Source.
