Back Sundayguardianlive Why Payment Platforms Are Becoming New Frontline for Cyberattacks
India’s digital payments ecosystem has grown rapidly and is now an integral part of how consumers and businesses transact. In May 2026 alone, UPI processed more than 23.2 billion transactions worth nearly Rs 29.9 lakh crore. Behind this scale is a complex network of banks, fintech platforms, payment gateways, APIs, cloud infrastructure and thirdparty technology providers. This scale and interconnectedness have also made payment platforms an increasingly attractive target for cybercriminals.
The threat landscape is changing. Cyberattacks are no longer limited to stealing credentials or deceiving individual users. Attackers and AI Agents, are increasingly looking for vulnerabilities within the technology infrastructure, Applications, Websites, etc. that connects different participants in the payment ecosystem. The RBI has noted that digital-payment frauds account for the largest of fraud cases by number, with card and internet-related frauds particularly prominent.
For a long time, payment fraud was largely associated with social engineering. Phishing, vishing, fraudulent payment requests and credential theft continue to be serious concerns. An RBI survey found that vishing accounted for 54.2% of reported fraud or attempted fraud methods, followed by phishing at 37.2%. But as digital payments become more deeply embedded across financial services and commerce, the attack surface is expanding to APIs, cloud environments, thirdparty platforms and other technology layers that sit behind every transaction.
The expansion of APIs is one example. APIs allow payment platforms to communicate with banks, merchants, identity providers and other services, making transactions faster and more seamless. However, every API also represents a potential entry point. Poorly secured APIs, excessive permissions, weak authentication or inadequate monitoring can expose sensitive financial and customer data or even manipulation of the data.
The same applies to cloud infrastructure and thirdparty technology providers. Payment companies increasingly depend on external platforms for infrastructure, analytics, fraud detection, identity verification and other capabilities. While this enables faster deployment, it also creates third-party and supply-chain risks. A vulnerability outside an organisation’s direct environment can potentially become a pathway into its wider ecosystem.
This is where cybersecurity needs to become more proactive. Payment platforms need continuous threat monitoring, realtime anomaly detection, vulnerability management, continuous threat exposer management and stronger identity and access controls across their infrastructure. Security also needs to be considered at the design stage rather than added after a product or service is launched.
Artificial intelligence designed towards fraud identification in IT or process standpoint, can play a useful role here. Payment platforms generate enormous volumes of transactional and behavioural data, which can be analysed in real time to identify unusual patterns and potentially fraudulent activity. But AI needs to complement strong cybersecurity fundamentals, governance and human oversight rather than replace them.
Another important shift is towards zero-trust security. In an interconnected payment environment, organisations cannot automatically assume that a user, device, application or third-party connection is trustworthy simply because it is operating within an approved ecosystem. Access needs to be continuously verified and limited according to actual requirements.
Cyber resilience is equally important. Prevention will always be the first line of defence, but organisations also need to prepare for the possibility of a breach. Incident-response plans, system isolation, backup mechanisms and recovery mechanism need to be tested regularly. The objective should be to minimise disruption and restore services quickly.
The RBI’s Cyber Resilience and Digital Payment Security Controls for nonbank payment system operators, which are being implemented in phases, also place greater emphasis on strengthening security practices across the ecosystem. But regulatory compliance should be viewed as a baseline rather than the end goal.
India has built one of the world’s largest digital payment ecosystems. Protecting its phase of growth will require cybersecurity to be built into the architecture of digital payments, rather than treated as an additional layer around it.
Sachhin Gajjaer, Founder & CEO of Sattrix
Sachhin Gajjaer, Founder & CEO of Sattrix
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
