UPSC Darpan

Internal SecurityGS37 October 2026

SPIR 2026: Indians Who Trust UPI Most Are Likelier Fraud Victims, Banks Deny Liability

Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें

The news

New Delhi. Two Hindu pieces draw new findings on trust and banks from the Status of Policing in India Report 2026, a Common Cause–Lokniti-CSDS survey of 8,306 people in 16 States. Half (49%) use UPI daily, and 75% call it safe. Trust tracks risk: 28% of those who rated online banking “very safe” had been victims, against 14% of those who rated it “very unsafe”, and frequent UPI users were likelier victims. As The Hindu reads the data, 52% of digital-fraud victims complained to their bank, 63% of them within 24 hours, yet banks typically said the victim had “collaborated”; 40% suspected a bank insider leaked their data. Weak KYC lets fraudsters open mule accounts, which receive and pass on stolen money. The report finds about three in four victims recovered nothing.

The chain in one line: UPI makes payment instant and trusted → fraudsters trick users into authorising payments, routed through mule accounts opened under weak KYC → banks call these customer-authorised and deny liability → most victims recover nothing

Static syllabus linkage

  1. RBI’s 2017 framework decides who bears an unauthorised electronic loss. RBI’s 2017 circular gives customers zero liability where the bank is at fault, or where a third-party breach is reported within three working days; later reporting brings limited liability. The burden of proving customer liability lies on the bank. The Hindu reports a 2026 pilot extending limited bank liability to customers tricked into paying.
  2. I4C and the CFCFRMS are the State’s fast-response machinery. The Home Ministry’s Indian Cyber Crime Coordination Centre (I4C) runs the 1930 helpline. Its Citizen Financial Cyber Fraud Reporting and Management System links police with banks to freeze stolen money quickly. Section 66D of the IT Act, 2000 punishes cheating by personation using a computer resource.

Why UPSC loves this

  1. GS3 treats fraud networks as a security and money-laundering problem. The syllabus lists “basics of cyber security; money-laundering and its prevention”. Mule accounts join the two.

Prelims nuggets

  • Under RBI’s 2017 customer-liability framework, a customer bears zero liability for an unauthorised electronic transaction caused by a third-party breach if the bank is notified within three working days.
  • Under the same framework, the burden of proving customer liability lies on the bank.
  • The Citizen Financial Cyber Fraud Reporting and Management System is operated by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs.

Analysis

  1. The trust paradox is a design problem, not only a literacy problem. UPI succeeded by removing friction, and fraud uses the same ease: the victim approves the payment himself. Urging distrust of a system the state promotes sends mixed signals; safety must be built in at risky moments, such as a first large payment to a new payee.
  2. Lens — Innovation and safeguards: liability rules have not caught up with how fraud works. The 2017 rule covers unauthorised transactions, but most UPI fraud is authorised by a deceived customer, hence “collaborated”. A sensible officer would put part of the loss on the receiving bank whose weak KYC opened the mule account, placing cost where failure occurs. The counter-view is moral hazard, so liability should be shared and capped.
  3. Mule accounts make the bank part of the crime scene. Fraud kits of SIM cards, accounts and phones sell for ₹10,000–20,000; account lenders are the most replaceable link, so arresting them spares the organisers. Insider-leak suspicion adds an accountability gap: banks are data fiduciaries under the Digital Personal Data Protection Act, 2023.

Possible Mains question

Indians who trust digital payments most are likelier to be defrauded, and banks often deny liability. Examine how cyber-fraud losses should be shared between banks and customers. (15 marks, 250 words)

Model approach

  1. Directive — Examine. Probe the paradox, test the options, conclude.
  2. Introduction — the trust paradox. SPIR 2026: trusting, frequent UPI users were likelier victims.
  3. Body — the 2017 framework misses deceived customers. Value addition: 63% complained within 24 hours, yet banks claimed collaboration.
  4. Body — weak KYC makes the receiving bank a co-author of the loss. Flowchart: victim → payer bank → mule account → layering, marking intervention points.
  5. Conclusion — shared, capped liability and friction at risky moments. Plus faster freezing.

Administrator's brainstorm

As Superintendent of Police, you find most local fraud money passes through mule accounts at a few branches. What do you do?

I would map the accounts by branch and ask the banks and the RBI’s regional office for a KYC review. Account holders would be questioned to trace the organisers, not treated as the case’s end. With the lead bank I would agree to freeze money within hours of a 1930 complaint.