Security and Privacy Advice for UPI Users in India

Deepthi Mungara and Harshini Sri Ramulu, Paderborn University; Yasemin Acar, Paderborn University and The George Washington University

Unified Payments Interface (UPI) payment systems are widely used in India and are also gaining global traction. UPI enables people to make quick everyday transactions and recurring payments, including rent, gas, and electricity, using the same app. The widespread adoption of UPI has sparked significant concerns regarding users' security and privacy, especially due to an alarming number of UPI-related scams and fraudulent transactions. While prior work has explored the technical security of UPI, to address security threats effectively, we must understand user mental models, concerns, security information sources, and behaviors. In a mixed-methods study of 26 semi-structured interviews with UPI users from India and content analysis of 16 security information sources from regulatory bodies, UPI apps, and banks offering UPI, we explore user mental models, concerns, where and how they receive security advice, as well as their security-relevant behaviors. We provide an analysis of users' concerns and threats around UPI security and privacy and highlight gaps where official advice falls short. Further, we recommend UPI providers and banks to curate accessible and useful advice to better alleviate users' concerns, and increase their reach. We also recommend individual security and privacy practices for UPI users to protect themselves.

Category: 
Short Presentation

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {308030,
author = {Deepthi Mungara and Harshini Sri Ramulu and Yasemin Acar},
title = {Security and Privacy Advice for {UPI} Users in India},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {6085--6103},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/mungara},
publisher = {USENIX Association},
month = aug
}

Presentation Video