Security and Privacy Advice for UPI Users in India

Deepthi Mungara (PhD student · University of Padaborn)

34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Usable Privacy and Security 3

Overview

India's Unified Payments Interface (UPI) stands as a monumental success in digital finance, connecting millions of users from street vendors to online shoppers. Facilitating transactions from a mere 1 Indian Rupee up to 1 lakh Indian Rupees per day (approximately $1 to $1,000 USD), UPI has become the backbone of India's digital economy. In the last financial year, it processed an astounding 2.57 trillion USD, accounting for 85% of India's digital payment volume and nearly half of all global real-time payments. However, this explosive growth has unfortunately been mirrored by a sharp increase in fraud cases, with roughly one in five Indian users experiencing a UPI-related attack since 2022, making up 55% of all digital payment frauds.

Watch on YouTube · Slides

Visual summary for Security and Privacy Advice for UPI Users in India by Deepthi Mungara
Visual summary for Security and Privacy Advice for UPI Users in India by Deepthi Mungara

Key moments

  1. 0:00 Introduction to UPI and its exponential growth in India
  2. 2:00 The rise of UPI scams and fraud statistics
  3. 3:00 Key research questions and study methodology
  4. 4:30 Six distinct categories of UPI safety advice
  5. 7:00 User concerns: financial sensitivity and profile authenticity
  6. 8:00 Personal information risks and cross-platform trust-building
  7. 9:00 User recommendations for platform privacy and verification features

Security and Privacy Advice for UPI Users in India

Speakers: Deepthi Mungara, Second-Year PhD Student, University of Paderborn, Germany

Conference: USENIX Security

YouTube: https://www.youtube.com/watch?v=wdf074Th0Ak

Overview

India's Unified Payments Interface (UPI) stands as a monumental success in digital finance, connecting millions of users from street vendors to online shoppers. Facilitating transactions from a mere 1 Indian Rupee up to 1 lakh Indian Rupees per day (approximately $1 to $1,000 USD), UPI has become the backbone of India's digital economy. In the last financial year, it processed an astounding 2.57 trillion USD, accounting for 85% of India's digital payment volume and nearly half of all global real-time payments. However, this explosive growth has unfortunately been mirrored by a sharp increase in fraud cases, with roughly one in five Indian users experiencing a UPI-related attack since 2022, making up 55% of all digital payment frauds.

In this critical talk, Deepthi Mungara, a second-year PhD student at the University of Paderborn, Germany, presented findings from a study co-authored with Hashini Shi Ramlu and Yasamin Achar. The research, published in the proceedings of the 34th USENIX Security Symposium, aimed to understand and improve UPI security for real users. The study delved into how users perceive security, their behavioral patterns, the sources from which they learn about digital safety, and critically, how these perceptions and learning sources align or misalign with the formal advice provided by banks, UPI applications, and regulators.

The findings from Mungara's research are invaluable for anyone involved in digital payments, cybersecurity, or user experience design, particularly in high-growth markets. By meticulously analyzing both the formal security advice landscape and the actual lived experiences and perceptions of UPI users, the study highlights significant gaps in awareness and education. It provides actionable recommendations for both users to better protect themselves and for UPI entities to enhance their security guidance and platform features, ultimately striving for a safer, more informed, and confident UPI ecosystem.

Background

▶ Watch: Introduction to UPI and its exponential growth in India (0:00)

The Unified Payments Interface (UPI), developed by the National Payments Corporation of India (NPCI), has revolutionized digital transactions in India. Its ubiquity is unparalleled, integrated into everything from roadside vendors and public transport to e-commerce platforms and food delivery services. Users can transact using various identifiers such as phone numbers, Virtual Payment Addresses (VPAs), or QR codes, making payments incredibly convenient and accessible. This ease of use, while driving adoption, has also created fertile ground for sophisticated scammers.

The scale of the fraud problem is alarming. With one in five Indian users reportedly facing a UPI-related attack since 2022, and UPI scams constituting 55% of all digital payment frauds, the economic and personal impact is substantial. These incidents range from phishing attempts and unauthorized transactions to identity theft and social engineering. The proliferation of scams underscores a critical challenge: as payment systems become smarter, so do the adversaries exploiting them.

The research presented by Deepthi Mungara sought to address this escalating problem by focusing on three core research questions:

  1. User Perception: How do users genuinely perceive security? What are their primary concerns, how do they behave, and what motivates these behaviors?
  2. Information Sources: Where do users obtain information about staying safe online, and what sources influence their understanding of security?
  3. Alignment with Formal Advice: How well does user understanding and behavior align with the formal security advice disseminated by banks, UPI applications, and regulatory bodies?

To thoroughly investigate these questions, the study employed a two-step methodology: an advice analysis and a user perception analysis. This comprehensive approach aimed to map the current landscape of security guidance and compare it against the reality of user comprehension and protective behaviors, thereby identifying critical areas for improvement in the UPI ecosystem.

Key Findings

▶ Watch: Key research questions and study methodology (3:00)

The study yielded profound insights by systematically analyzing both the formal security advice available and the real-world perceptions and behaviors of UPI users. This dual approach allowed the researchers to identify critical discrepancies and areas for improvement.

Advice Analysis: Categorizing the Landscape of Guidance

For the advice analysis, the researchers manually collected UPI safety advice from the official websites of 16 key entities. This included two major regulatory bodies, 10 of the most widely used banks, and four prominent UPI applications in India. They utilized keywords such as "UPI," "safety," "privacy," "security," "tips," and "advice" to ensure a comprehensive collection. A key contribution of this study was the systematic organization of this often scattered guidance into six distinct categories, providing a structured framework for analysis:

  1. UPI Transaction Security Advice: This category includes guidance directly related to the transaction process. Examples include:
  • Entering the UPI PIN only when sending money.
  • Scanning QR codes exclusively for sending money.
  • Verifying recipient details thoroughly before and after a transaction.
  1. UPI User Data Protection Advice: This focuses on safeguarding personal and banking information. Examples include:
  • Never sharing personal or banking details.
  • Avoiding saving banking credentials on mobile devices.
  • Refraining from sharing sensitive information via unsolicited calls, texts, or emails.
  1. Password Protection Advice: This category encompasses general advice for securing access credentials. Examples include:
  • Never sharing PINs, One-Time Passwords (OTPs), CVVs, or other passwords.
  • Creating strong, complex, and unique PINs and passwords.
  • Regularly changing PINs and passwords.
  1. Device and UPI Application Security Advice: This section provides guidance on securing the devices and applications used for UPI. Examples include:
  • Avoiding public Wi-Fi networks for financial transactions.
  • Avoiding third-party screen sharing applications.
  • Installing and regularly updating valid antivirus software.
  1. Customer Support and Reporting Sources: This category focuses on how users can seek help and report issues. Examples include:
  • Using only valid and official helpline sources.
  • Downloading UPI applications exclusively from trusted platforms like Google Play Store or Apple App Store.
  • Reporting unauthorized transactions promptly.
  1. Handling Unknown Situations Advice: This provides general cautionary advice against common scam tactics. Examples include:
  • Avoiding clicking unknown or suspicious links.
  • Exercising caution with unknown emails, texts, or calls.
  • Avoiding suspicious applications or unsolicited cashback offers.

User Perception Analysis: Understanding User Behavior and Concerns

The user perception analysis involved semi-structured interviews with 26 general UPI users, recruited through a convenient sampling method. The interviews covered various aspects, including user background, mental models, motivations, security concerns, awareness levels, safety measures adopted, and information sources. The key findings from this analysis revealed several critical user behaviors and concerns:

  • Financial Information Sensitivity: Participants expressed significant concern that sharing financial information publicly could expose them to exploitation. As a protective measure, they chose to disclose sensitive details, such as salary, only within highly trusted and private settings. This highlights that users treat financial data with extreme caution, limiting its exposure to intimate and verified interactions.
  • Concern about Fake Profiles and Misuse of Information: Users were wary of fake profiles and the potential misuse of their information, including unauthorized sharing and identity theft. To mitigate this, they actively engaged in behaviors like carefully screening profiles for signs of authenticity, such as age and establishment of the profile, and relying on community networks for "background checks."
  • Protection Against Harassment and Abuse: Participants voiced concerns that sharing personal contact information and identifiable details could lead to harassment or abuse, citing instances of impersonation and even kidnapping attempts. Their protective behavior involved withholding names, family details, and location information. They preferred safer contact methods like email or social media over direct phone numbers.
  • Cross-Platform Verification for Trust Building: Users actively employed cross-platform verification to establish trust. For example, they might add someone on Snapchat to review live photos, check their followers and friends, and simultaneously verify professional details on LinkedIn, such as schooling or workplace. This multi-platform approach helps confirm authenticity across both social and professional spheres.
  • Desire for Platform-Level Privacy Controls: Participants strongly articulated a desire for platforms to integrate features that enhance privacy and build trust. Suggestions included features to prevent screenshots and image downloads of personal photos, and the display of a verified identity checkmark beside user profiles. These suggestions underscore a significant demand for robust platform-driven security and privacy mechanisms to foster a safer sharing environment.

In summary, the study revealed a significant gap between the extensive security advice available online and what actually reaches and is understood by users. While users possess some basic safety knowledge, their protective behaviors are often reactive and based on personal experiences or community wisdom rather than comprehensive, formally provided guidance.

Technical Deep Dive

▶ Watch: Six distinct categories of UPI safety advice (4:30)

While this talk did not present novel code or protocol vulnerabilities, its technical depth lies in its rigorous socio-technical methodology for analyzing human factors in cybersecurity. The research systematically investigated the intersection of user behavior, perception, and the effectiveness of security advice within the context of India's UPI ecosystem. This "technical deep dive" focuses on the structured approach taken to gather and analyze data, which forms the scientific foundation of their findings.

The study's methodology was bifurcated into two distinct, yet complementary, phases: Advice Analysis and User Perception Analysis.

Advice Analysis Methodology

The advice analysis phase involved a structured approach to collect and categorize existing security guidance:

  1. Entity Selection: The researchers identified 16 key entities providing UPI security advice in India. This included two regulatory bodies (e.g., Reserve Bank of India, NPCI), 10 of the most frequently used banks (e.g., State Bank of India, ICICI Bank), and four of the most popular UPI applications (e.g., Google Pay, PhonePe). This selection ensured a broad representation of authoritative sources.
  2. Data Collection: Advice was manually collected by navigating to the official websites and in-app security sections of these 16 entities. A standardized set of keywords was used to search for relevant information: "UPI," "safety," "privacy," "security," "tips," and "advice." This manual, keyword-driven approach ensured that the collected data directly reflected the publicly available and officially sanctioned guidance.
  3. Categorization Framework: A critical technical contribution was the development of a six-category framework to organize the collected advice. This categorization was not pre-defined but emerged from an inductive analysis of the data, allowing the researchers to systematically group similar pieces of advice. This structured approach is vital for making sense of a large, disparate body of information, enabling systematic identification of common themes, overlaps, and gaps in guidance across different entities. The categories (UPI Transaction Security, UPI User Data Protection, Password Protection, Device and UPI Application Security, Customer Support and Reporting Sources, and Handling Unknown Situations) provide a robust taxonomy for future research and for entities to audit their own advice.

The importance of this structured categorization cannot be overstated. In an environment where users are "often faced with a flood of guidance that is scattered across websites and apps," this framework provides a clear, actionable structure that makes the advice "easier to access, understand, or put into practice."

User Perception Analysis Methodology

The user perception analysis employed a qualitative research design to delve into the nuanced experiences of UPI users:

  1. Participant Recruitment: 26 general UPI users were recruited using a convenience sampling method. While convenience sampling has limitations regarding generalizability, it is often practical for initial qualitative explorations, allowing for rich data collection from readily available participants. The focus was on gathering diverse perspectives rather than statistical representation.
  2. Interview Structure: Semi-structured interviews were conducted, allowing for both a consistent set of core questions and the flexibility to explore emergent themes. This balance is crucial for qualitative research, ensuring comparability across participants while also capturing individual depth and unexpected insights.
  3. Interview Question Categories: The interviews were designed around specific categories of questions to comprehensively understand user perspectives:
  • User Background: Demographics, frequency of UPI usage, types of transactions.
  • User Mental Models and Motivations: How users conceptualize UPI security, their reasons for using or avoiding certain features.
  • Security Concerns and Challenges: Specific fears, past experiences with scams, perceived vulnerabilities.
  • Level of Awareness and Safety Measures: Knowledge of official advice, self-reported protective behaviors, tools used.
  • Sources of Information: Where users learn about security (e.g., friends, family, social media, official channels).

By combining these two methodologies, the researchers were able to draw direct comparisons between the intended security posture (as communicated by entities) and the actual security practices and concerns of users. This socio-technical gap analysis is a critical technical contribution, revealing that while basic safety measures are known, a "significant gap" exists between available advice and its effective dissemination and comprehension by users. The study's rigor in defining and executing these methodologies provides a solid foundation for its conclusions and recommendations.

Demo / Proof of Concept

▶ Watch: Personal information risks and cross-platform trust-building (8:00)

This research-focused presentation did not include a live demonstration or a proof of concept in the traditional sense of exploiting a vulnerability or showcasing a new security tool. Instead, the "demonstration" was the comprehensive presentation of the study's findings, meticulously laid out through the advice analysis and user perception analysis. The talk itself served as a detailed exposition of the methodology, the categorized advice, and the observed user behaviors and concerns, effectively demonstrating the existing landscape of UPI security and privacy from both the provider and user perspectives. The efficacy of the research was proven through the systematic collection and analysis of data, culminating in actionable recommendations rather than a technical exploit.

Defensive Implications

▶ Watch: User recommendations for platform privacy and verification features (9:00)

The findings from this study offer critical defensive implications for both individual UPI users and the entities responsible for the UPI ecosystem. Bridging the identified gap between available advice and user awareness is paramount to enhancing overall security and trust.

For Individual UPI Users (Self-Defense)

Users are the first line of defense in the digital payment landscape. The study emphasizes several proactive measures:

  • Prioritize Official Information Sources: Users must actively seek and rely solely on official channels for security advice and updates. This includes the dedicated security sections of their banks' official websites and trusted, verified UPI application interfaces. Unsolicited advice from unknown sources, social media, or forwarded messages should be treated with extreme skepticism.
  • Master UPI App Security Settings: It is crucial for users to explore and configure all available security settings within their UPI applications. This includes setting appropriate transaction limits to minimize potential losses from unauthorized transactions, enabling biometric authentication (fingerprint, facial recognition) for enhanced access control, and regularly reviewing account management options for suspicious activity. These features are designed to enhance security and convenience, but only if utilized.
  • Exercise Caution with QR Codes: While convenient, QR codes can be vectors for fraud. Users should be particularly cautious in unfamiliar situations, verifying the recipient's name and details before scanning and authorizing any payment. Malicious QR codes can redirect to fraudulent payment gateways or initiate unintended transactions.
  • Never Share Sensitive Information: This is a foundational principle. Users must unequivocally refuse to share sensitive details such as their UPI PIN, OTPs, bank account numbers, or card CVVs with anyone, regardless of how convincing the request seems. Scammers frequently impersonate bank officials or customer support to solicit this information, and legitimate entities will never ask for such details over the phone, email, or text.

For UPI Entities (Organizational Defense)

Banks, UPI application providers, and regulators bear the responsibility of creating a secure and educated user base. The study provides clear directives for improving their defensive posture:

  • Enhance Accessibility and Visibility of Guidance: Security advice must be made easily discoverable and understandable. Entities should move beyond static website pages and actively disseminate guidance across all widely used digital platforms, including within their UPI applications, through push notifications, and via social media channels where users spend their time. The advice should be presented in clear, concise language, potentially using visual aids.
  • Prioritize Targeted User Education: General security advice is often insufficient. Entities need to invest in targeted awareness campaigns that address specific risks and cater to the diverse knowledge levels of UPI users. This includes foundational education on device and app security (e.g., the importance of regular app updates, securing the device with strong passwords/biometrics, avoiding public Wi-Fi for transactions) for new users, and more advanced threat intelligence for experienced users.
  • Simplify and Promote Security Features: All security features, especially advanced options like biometric authentication or transaction limits, must be clearly promoted, easily locatable within the app interface, and simple to understand and configure. Users are more likely to adopt security measures if they perceive them as intuitive and beneficial. User interface design plays a critical role in feature adoption.
  • Proactive Scam Awareness Campaigns: Given the prevalence of scams, entities should proactively inform users about emerging fraud tactics. This could involve real-time alerts about common phishing schemes, impersonation attempts, or fraudulent cashback offers, helping users recognize and avoid these threats.
  • Integrate Platform-Level Trust Mechanisms: Responding to user demand, entities should explore implementing platform-level verification systems (e.g., verified checkmarks for merchants, secure photo sharing options) and privacy controls (e.g., screenshot prevention) to build greater trust and security directly into the UPI ecosystem.

By collectively implementing these defensive measures, the UPI ecosystem can become significantly more resilient against fraud and more empowering for its users. The goal is to bridge the "significant gap between the advice available online and what actually reaches them," fostering a safer, more informed, and confident environment for everyone.

Key Takeaways

  • Explosive Growth, Escalating Fraud: UPI processes trillions of USD annually, but this growth is marred by high fraud rates, with 1 in 5 Indian users experiencing an attack and UPI scams accounting for 55% of digital payment frauds.
  • Six Categories of Advice: The study systematically categorized UPI security advice from 16 entities into six key areas: transaction security, user data protection, password protection, device/app security, customer support, and handling unknown situations.
  • User Desire for Platform Controls: Users strongly desire enhanced privacy controls (e.g., screenshot prevention) and platform-level verification (e.g., verified checkmarks) to build trust and feel safer sharing information online.
  • Awareness Gap: A significant gap exists between the comprehensive security advice available from official sources and the actual awareness and protective behaviors of UPI users.
  • User Actionable Steps: Users should rely exclusively on official sources for security advice, actively utilize all available in-app security settings (like biometric authentication and transaction limits), and never share sensitive information like PINs or OTPs.
  • Entity Responsibilities: UPI entities must make security guidance more accessible and visible, provide targeted user education, and simplify the promotion and usability of all security features to empower users.

About the Speaker(s)

Deepthi Mungara is a second-year PhD student at the University of Paderborn, Germany. Her research, as presented in this talk, focuses on critical aspects of security and privacy in digital payment systems, particularly within high-growth markets like India. She co-authored the presented study, "Security and Privacy Advice for UPI Users in India," with Hashini Shi Ramlu and Yasamin Achar, contributing to the understanding of user perceptions and the effectiveness of security advice in real-world contexts.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A usable social science study dressed up as a security conference talk. The core finding — users don't read or absorb official security advice — is not a novel insight, and the UPI-specific wrapper doesn't change that. Belongs in a CHI or SOUPS proceedings discussion, not a USENIX Security slot.

Heather Calloway (CISO) — WEAK

Solid academic groundwork on a real and underserved problem — fraud at scale in a payment system handling half of global real-time transactions — but the research stops well short of institutional accountability. The findings are descriptive, the recommendations are generic, and nothing here forces a bank, regulator, or platform operator to act.

→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)

All talks from 34th USENIX Security Symposium (USENIX Security '25)