International Journal For Multidisciplinary Research

E-ISSN: 2582-2160   •   Impact Factor: 9.24

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 8, Issue 5 (September-October 2026) Submit your research before last 3 days of October to publish your research paper in the issue of September-October.

Cybersecurity of Digital Payment Systems in India: Legal and Regulatory Challenges

Author(s) Mr. Joylin Jacob, Parvathy SB
Country India
Abstract The rapid expansion of digital payment systems has fundamentally transformed the Indian financial ecosystem. Payment instruments such as Unified Payments Interface (UPI), mobile banking, internet banking, debit and credit cards, prepaid payment instruments, payment aggregators and digital wallets have facilitated faster, more convenient and increasingly accessible financial transactions. However, the growing dependence on digitally enabled payment infrastructure has simultaneously increased exposure to cybersecurity threats, including phishing, vishing, identity theft, SIM-swap fraud, malware attacks, credential theft, ransomware, social engineering, unauthorised electronic transactions and data breaches. The legal regulation of digital payment cybersecurity in India is therefore distributed across multiple statutes, regulatory directions and institutional mechanisms.
The Information Technology Act, 2000 , the Information Technology Rules, the Payment and Settlement Systems Act, 2007 , the Banking Regulation Act, 1949 , the Digital Personal Data Protection Act, 2023, and various directions issued by the Reserve Bank of India (RBI) collectively constitute the principal legal framework governing digital payment security. The RBI's 2021 Master Direction on Digital Payment Security Controls introduced common minimum-security standards for specified regulated entities, while the 2024 Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank Payment System Operators further emphasise governance, data security, incident response, threat monitoring and resilience. Despite these developments, significant legal and regulatory challenges remain concerning allocation of liability for unauthorised transactions, third-party service-provider responsibility, cross-platform fraud, cybersecurity standards, data breaches, consumer awareness, digital evidence and coordination among regulatory and law-enforcement agencies. This paper critically examines India's existing legal and regulatory framework, analyses contemporary cybersecurity threats affecting digital payment systems, examines relevant judicial decisions and identifies gaps in the existing regime. It proposes a coordinated, risk-based and technologically adaptive regulatory framework to strengthen cybersecurity, consumer protection and institutional accountability in India's digital payment ecosystem.
Keywords Keywords: Cybersecurity, Digital Payments, UPI, Banking Law, Data Protection
Published In Volume 8, Issue 5, September-October 2026
Published On 2026-09-29

Share this