Interactive field guide · August 2026

A UPI payment crosses an app, two banks and NPCI before the merchant gets confirmation.

This guide traces one ₹500 payment, then examines identity, fraud, market concentration, public subsidy and the projects India should fund next.

Reading depth
One UPI payment, many participants A phone sends a five hundred rupee payment across a central rail to a merchant QR code, with bank and identity checks around it. PAYMENT ₹500 Pay now UPI rail MERCHANT Payment received Bank approved Identity checked

01 · UPI in one minute

Your payment app does not move the money.

It captures your intent. Banks hold the accounts. NPCI routes the request. Several systems have to agree before the merchant sees “paid.”

Step 1 of 6

You approve ₹500

The app sends your payment instruction. Your UPI PIN or approved on-device method authorizes the request.

What can fail here?

A deceptive QR, collect request or social-engineering prompt can make a genuine user authorize the wrong transaction.

1

The app is an interface

PhonePe, Google Pay, BHIM and bank apps initiate payments. They do not normally hold the linked bank balance.

2

NPCI is the coordinator

It operates the common rail and rules. The payer and beneficiary banks still have to respond correctly.

3

“UPI is down” is ambiguous

The failing layer may be an app, bank, telecom connection, risk engine or the shared network.

Go deeper: trust boundaries and transaction finality

A UPI transfer crosses the customer interface, payment service provider, remitter bank, central routing layer and beneficiary bank. Common network rules let systems owned by different institutions work together, while each institution remains responsible for its part.

A technical decline may start at a bank or the central network. The account balance, a transaction limit or a risk rule may cause a separate business decline. Reversals and disputes begin after the immediate result shown to the customer.

02 · UPI at current scale

UPI processed 241.6 billion transactions in 2025–26.

At this volume, outages, weak fraud controls and funding decisions affect millions of people.

24,161.7 crore transactions in FY 2025–26 ≈ 241.6 billion
₹314.2 lakh crore value in FY 2025–26 ≈ ₹314.2 trillion
55.49 crore users by June 2026 ≈ 554.9 million
720 banks live in May 2026 up from 21 at launch
Official annual volume

UPI grew 5.3× in four years

crore transactions
UPI annual transaction volume from financial year 2021–22 to 2025–26 Volume rises from 4,595.61 crore transactions in 2021–22 to 24,161.69 crore in 2025–26. 0 6k 12k 18k 24k FY 2021–22: 4,595.61 crore FY 2022–23: 8,371.44 crore FY 2023–24: 13,112.95 crore FY 2024–25: 18,586.60 crore FY 2025–26: 24,161.69 crore 21–22 22–23 23–24 24–25 25–26
UPI annual transaction volume
Financial yearVolume in crore
2021–224,595.61
2022–238,371.44
2023–2413,112.95
2024–2518,586.60
2025–2624,161.69

Source: Ministry of Finance, July 2026. Values are financial-year totals.

Interface layer

Two apps handle 81% of payer volume

PhonePe + Google Pay Every other payer app

Calculated from NPCI payer-app volume for August 2025. Concentration can change; this is a dated snapshot.

03 · Aadhaar's role in UPI

Aadhaar appears during identity checks and account recovery. Routine payments use other controls.

KYC, PIN reset, on-device biometrics and AePS use different systems and controls. Grouping them all under “Aadhaar-linked UPI” hides those differences.

Identity proof

Aadhaar can establish who opened the account.

Banks may use Aadhaar for voluntary KYC; Aadhaar is required for receiving benefits under notified schemes. UIDAI does not approve each UPI payment.

Opportunity

Fast, paperless onboarding and easier access to benefit-linked accounts.

Guardrail

Offer equivalent non-Aadhaar KYC and store masked or tokenized identifiers.

What the breach record shows

Aadhaar data has leaked from systems outside UIDAI’s central database.

UIDAI reports no breach of the Central Identities Data Repository. Documented exposures of Aadhaar numbers and related personal data have come from other government and institutional systems.

1Peripheral leakAadhaar + phone + address
2TargetingConvincing impersonation
3Recovery attackSIM, device or PIN reset
4Financial lossIf bank controls also fail

Knowing an Aadhaar number alone should not authorize a withdrawal. The risk comes from combining leaked attributes with weaknesses elsewhere.

Recommended boundary

Use Aadhaar for identity checks and exceptional recovery. Require separate approval for each payment.

  • Optional for onboarding and exceptional recovery
  • Never exposed as a public UPI address
  • Domain-specific tokens instead of stored Aadhaar numbers
  • Device possession, bank risk checks and cooling-off after reset
  • UPI PIN or on-device cryptographic approval for routine payments
Go deeper: three documented claims
Official position

No confirmed CIDR breach

UIDAI states that its central repository and core biometrics have not been breached. That claim covers CIDR, not Aadhaar data copied into other databases.

Observed exposure

Peripheral systems have leaked

In 2024, MeitY blocked websites exposing Aadhaar and PAN details. Earlier disclosures involved institutional or beneficiary datasets rather than a demonstrated extraction from CIDR.

Investigated claim

The 2023 ICMR dataset

CERT-In acknowledged samples claiming to originate from ICMR. Reporting described verified sample records and arrests, but this was not evidence that UIDAI’s central repository was penetrated.

04 · Where fraud and failure happen

A valid UPI transaction can still be fraudulent.

The main risks involve payment prompts, account recovery, devices, telecom providers, banks, agents and mule accounts.

Higher impactLower impact
Harder to exploitEasier to exploit
Human

Social engineering

A real user is manipulated into authorizing the wrong transaction.

Institution

Mule networks

Funds move rapidly through recruited or compromised accounts.

Human

SIM or recovery takeover

Attackers target identity recovery instead of payment encryption.

System

Bank technical decline

A bank or network dependency times out or rejects the request.

Institution

Interface concentration

Failure or policy changes at a dominant app affect a large user base.

Institution

Dispute friction

Responsibility is split across the app, two banks and the network.

This matrix is my qualitative assessment, not an official loss-frequency model. The placement compares potential impact with ease of exploitation.

01

Authenticate the transaction, not only the person

Approval screens should bind the amount and payee to the user’s action. Strong identity proof cannot rescue an ambiguous payment prompt.

02

Make recovery harder than routine use

PIN reset and device rebinding should trigger cooling-off periods, lower limits and multi-channel alerts.

03

Put liability where control sits

Users should not have to diagnose which institution’s seeding, onboarding, agent or risk control failed.

05 · The price of free

UPI's operating costs are spread across taxpayers, banks, apps, merchants and users.

Every payment consumes switching, core banking, authentication, fraud monitoring, settlement, support, dispute resolution and regulatory capacity.

Government

Public incentive schemes and broader digital public infrastructure.

N

NPCI & members

Central rail, standards, switching, settlement coordination and resilience.

B

Banks

Core systems, APIs, authentication, AML, fraud controls, reversals and support.

A

Apps & PSPs

Consumer software, support, acquisition, redundancy and fraud tooling.

M

Merchants

Devices, reconciliation, operations, fraud exposure and downtime.

U

Users

No normal explicit fee, but indirect exposure to fraud, failure and lost time.

₹1,500 crFY 2024–25 estimated incentive outlay
₹2,000 crFY 2026–27 budget envelope

The public figures disclose subsidies, not UPI’s total economic cost. Banks and apps do not publish unit costs, so outsiders cannot calculate a reliable cost per transaction.

Compare three funding models

Who should cover UPI's operating costs?

1Universal railPublic-service funding
2Large-merchant commerceSmall, capped MDR
3Value-added servicesBeneficiary pays
4Risk & resiliencePerformance-weighted levy
My view

Keep routine payments free. Charge some higher-value commercial use.

Keep P2P and low-value small-merchant payments free. Charge a small, capped amount for higher-value commerce, premium services and cross-border payments. Banks and payment providers should contribute more when their scale or risk increases operating costs.

Useful for
Keeping basic use free while raising operating revenue
Main risk
Complex rules and lobbying around thresholds

06 · My 2030 priorities

Fund recovery and resilience before expansion.

The projects below address poor connectivity, reusable credentials, international connections and the digital rupee.

Resilience

Make small payments less dependent on bank availability.

UPI Lite and proximity modes can reduce load on core banking systems and make low-value payments more tolerant of uneven connectivity.

Opportunity

Faster small payments and better access in low-connectivity settings.

Question to answer

Who carries loss when devices are offline, duplicated or compromised?

01

Keep an accessible fallback

Retain PIN and assisted options for people who cannot use a newer identity method.

02

Publish costs and obligations

Show cost bands, incentive flows and the performance expected in return.

03

Prevent app lock-in

Users should be able to switch apps without losing service or access to their transaction records.

04

Show cross-border fees

Payers should see compliance and foreign-exchange costs before approving a payment.

The argument in one sentence

Keep the universal rail free. Price commercial value. Subsidize measurable public benefits. Make participants pay for the risk they create.

Hundreds of millions of people depend on UPI and Aadhaar. NPCI and participating institutions should publish operating costs, fallback procedures, service levels and liability rules.

Sources & method

Sources, assumptions and remaining gaps.

I used primary material from NPCI, RBI, UIDAI, the Ministry of Finance, CAG and BIS wherever available. Dated snapshots are labelled. The recommendations are mine.

Known gaps: Public sources do not disclose a complete per-transaction cost, app-level fraud rate, or adoption and false-rejection data for the new Aadhaar face-authentication flow. The risk matrix and funding recommendation are analytical, not official.

Currency: Facts checked through 21 August 2026. The app-concentration chart uses August 2025, the latest detailed NPCI snapshot used in this analysis.