Centre forms inter-ministerial group for financial-sector cybersecurity strategy

India’s Centre has set up an inter-ministerial group to shape a financial cybersecurity strategy as AI-enabled fraud risks rise. The effort highlights IDPIC, an SBI- and Bank of Baroda-backed entity sharing real-time digital-payment fraud intelligence.

— Source publishedTue, 28 Jul, 2026, 20:42 IST·First seen Tue, 28 Jul, 2026, 21:26 IST·Source Inc42 · Buzz

What happened

The Centre has formed an inter-ministerial group to develop a cybersecurity strategy for India’s financial sector amid AI-driven fraud risks. It also highlighted IDPIC, a 2025-incorporated SBI and Bank of Baroda-backed entity that shares real-time digital-payment fraud intelligence.

Key facts

  • 2025
  • Section 8

Why this matters

Banks, payment firms and retail platforms may seek partnerships or acquisitions that add real-time fraud detection, cyber resilience and intelligence-sharing capabilities.

What to watch

  • Formal terms of reference, membership and deadlines for the inter-ministerial cybersecurity group.
  • RBI, NPCI, MeitY or CERT-In circulars on real-time fraud reporting, payment-risk data sharing, authentication or merchant liability.
  • IDPIC expansion beyond SBI and Bank of Baroda, including onboarding of private banks, payment aggregators, fintechs or merchant networks.
  • Reported increases in AI-enabled voice, deepfake, remote-access or mule-account fraud that create political pressure for rapid controls.
  • New UPI limits, beneficiary cooling periods, device-binding requirements or transaction-risk scoring mandates.
  • Acquirer notices raising merchant reserve levels, requiring additional fraud fields or changing chargeback and reimbursement treatment.
  • Map payment-fraud exposure across UPI, cards, wallets, COD-to-prepaid conversion, refunds, loyalty accounts and marketplace seller payouts.
  • Ask acquiring banks and payment aggregators about planned IDPIC, RBI or government fraud-intelligence integrations, merchant data requirements and revised liability rules.
  • Accelerate risk-based checkout controls rather than blanket authentication: device reputation, behavioral analytics, velocity limits and step-up verification for anomalous orders.
  • Strengthen refund, gift-card, loyalty-point and account-recovery controls, which are likely displacement targets if payment authorization fraud becomes harder.
  • Prepare customer-service scripts and conversion monitoring for possible transaction holds, cooling periods and additional authentication prompts.
  • Review privacy, consent and data-retention governance before sharing customer or transaction signals with external fraud networks.

Also reported by