Compared to many other countries, India has taken a very nuanced approach towards fighting cybercrime. In my blog post entitled How Are Regulators Cracking Down on Cybercrime In Different Countries?, I’d applauded Indian innovations like Cybercrime I4C Portal and regulatory playbook driving collaboration between banks, payments operator and law enforcement.
For the uninitiated, here’s the canonical example of a cybercrime:
Joe pays Jane online for something and does not receive that something he was promised.
I’d hoped that those collaborative innovations would adequately curb cybercrime.
Alas, they have not. Cybercrime continues unabated in a nod to the old adage “there’s a sucker born every minute” (H/T Barnum & Bailey), thus proving Matt Levine right.
Victims Of Frauds Are Promising Targets For Subsequent Frauds. Nobody Ever Learns Anything From Experience.
In April, India’s banking regulator Reserve Bank of India released two new measures to fight cybercrime for public consultation:
- Direct banks to reimburse scam victims up to INR 20,000, no questions asked. This chimes with the first strike of my Three Strikes Rule To Eliminate Cybercrime.
- Direct the UPI payments operator National Payments Corporation of India to introduce a one hour cooling period for all person-to-person (P2P) UPI payments exceeding INR 10,000 to new phone numbers. This is similar to the one hour cooling period in effect for adding new payees in other retail methods of payments like NEFT and IMPS.
Banks pushed back on both measures: #1 because it could lead to “friendly fraud” where the payor and payee collude with each other to dupe the bank; and #2 because it would remove the realtime nature of UPI.
Instead they came up with a counterproposal to add a YES / NO button in UPI apps. According to Economic Times article entitled Banks Moot ‘Yes-No’ Prompt to Cut Friction:
A number of them are proposing a software tweak for the payment app to throw up a prompt, seeking a go-ahead from the payer before the beneficiary’s account is credited in peer-to-peer (P2P) transactions. If a customer says ‘Yes’, the payment is executed within seconds; if she says ‘No’, the transaction is cancelled; and, if she says nothing, the money-transfer goes through and the beneficiary’s account gets credited after an hour.
Let’s do a small thought experiment on how this feature would work in real life.
I’ll start with the two screens in the payment workflow of my Walmart PhonePe app.
The first screen has the term PAY and the expression “Transfer Money“, as shown in the following exhibit.
The second screen prompts the payor to enter her PIN and hit the PAY button to confirm the payment. When I tried to screenshot it, I got a message that the app doesn’t allow screenshoting (although it did allow me to screenshot the previous screen, go figure!).
If I enter the correct PIN on the second screen and hit the PAY button, the payment goes through without any further confirmation from me.
Therefore the YES / NO button proposed by banks will need to put on a new screen to be inserted after the second (PIN entry) screen.
Let’s assume that the third screen is added, and map the user’s journey against time.
- t= 0. Screen 1. Deceived by the scammer, the payor enters the amount, and taps the PAY button.
- t=5 seconds. Screen 2. Continuing to be deceived by the scammer, she enters her PIN, and taps the PAY button.
- t=10 seconds. Screen 3. She sees the YES / NO button.
What will she do?
I find it very hard to believe that the payor will tap the NO button now.
Generally people realize they have been scammed only after their spouse / children / coworker expresses skepticism about the genuineness of the transaction or they receive an SMS alert from their bank or whatever.
Bereft of any such external stimulus, I can bet that a vast majority of victims will not tap the NO button in the third screen. Very few people, who have been conned on the previous two screens, will suddenly see god after a few seconds on the next screen.
Therefore most payors will tap YES on Screen 3 – and get scammed.
Accordingly, this YES / NO tweak will not move the needle on curbing cybercrime.
On the other hand, a one hour cooling period, as proposed by RBI, can help – a lot can happen in that time for the victim to realize that s/he has been scammed and one hour is long enough time for them to cancel the payment after arriving at that realization.
But I do get banks’ pushback that it will remove the realtime nature of UPI. How big a deal is it, really?
- It’s not a big deal for pure P2P payments that are typically not time-sensitive e.g friends splitting the cost of a meal.
- It could be a big deal for P2M payments masquerading as P2P payments that are time-sensitive e.g. settling bills of plumbers, electricians, and other handymen who lack current accounts, and receive payments through QR codes linked to their savings accounts.
I guess if handymen want to sight good funds immediately, they should sign up for merchant accounts with their banks so that their payments fall under P2M mode, and are exempted from the cooling period. Even otherwise, this is a step in the right direction of driving greater formalization of the economy à la GST. I reckon it should be way easier to get a merchant account to receive UPI payments as against credit card payments.
Let me take the opportunity to make a few general observations about mainstream media’s coverage of the cybercrime topic, using the aforementioned article as an example:
- “Authorized Push Payment” abbreviates handily to APP. APP is what it’s called in UK, where the term originated a few years ago. Not sure why it’s called AAP by the media. Going forward, I’ll switch to the term “APP Scam” since cybercrime has become too broad in the AI era and includes cryptowallet theft, business email compromise and many types of crimes carried out online.
- There’s a fundamental difference between scam and fraud: Scam is authorized payment; fraud is unauthorized payment. By definition, APP means “Authorized Push Payment”. The article also explicitly states “victim initiate(s) and authenticate(s) transactions” in most cases. This means the victim has authorized the payment. Therefore, it can’t be unauthorized payment aka fraud. It’s a scam, not a fraud. The term “APP Fraud” is an oxymoron. It should be changed to “APP Scam”.
- Glad to see MSM explicitly acknowledging that many UPI P2P payments are actually payments for sale-purchase P2M transactions that are processed as P2P payments because the merchant does not have a Merchant Account. As an aside, in highly formalized economies like USA, P2P payments are two orders of magnitude lower in volume than P2P payments. P2P volumes are artificially boosted in India because they include many payments that would have been reckoned as P2M payments in formalized economies.
Hope MSM outlets change their reporting lest their wrong nomenclature creates unnecessary FUD (Fear Uncertainty Doubt) about cybercrime and hampers the growth of digital payments.
I know APP Scam is a big issue but I continue to advocate my Three Strikes Rule to eliminate it instead of tinkering with payment apps and resorting to regulatory overreach.
