Domestic UPI Frauds: Finance Ministry Presented Data in LokSabha
Introduction
According to the Finance Ministry's data, the incidence of domestic Unified Payment Interface (UPI) fraud rose by 85% in FY 2023-24 compared to FY 2022-23. Further, as of September of FY 2024-25, 6.32 lakh fraud cases had been already reported, amounting to Rs 485 crore. The data was shared on 25th November 2024, by the Finance Ministry in response to a question in Lok Sabha’s winter session about the fraud in UPI transactions during the past three fiscal years.
Statistics

UPI Frauds and Government's Countermeasures
On the query as to measures taken by the government for safe and secure UPI transactions and prevention of fraud in the transactions, the ministry has highlighted the measures as follows:
- The Reserve Bank of India (RBI) has launched the Central Payment Fraud Information Registry (CPFIR), a web-based tool for reporting payment-related frauds, operational since March 2020, and it requires requiring all Regulated Entities (RE) to report payment-related frauds to the said CPFIR.
- The Government, RBI, and National Payments Corporation of India (NPCI) have implemented various measures to prevent payment-related frauds, including UPI transaction frauds. These include device binding, two-factor authentication through PIN, daily transaction limits, and limits on use cases.
- Further, NPCI offers a fraud monitoring solution for banks, enabling them to alert and decline transactions using AI/ML models. RBI and banks are also promoting awareness through SMS, radio, and publicity on 'cyber-crime prevention'.
- The Ministry of Home Affairs has launched a National Cybercrime Reporting Portal (NCRP) (www.cybercrime.gov.in) and a National Cybercrime Helpline Number 1930 to help citizens report cyber incidents, including financial fraud. Customers can also report fraud on the official websites of their bank or bank branches.
- The Department of Telecommunications has introduced the Digital Intelligence Platform (DIP) and 'Chakshu' facility on the Sanchar Saathi portal, enabling citizens to report suspected fraud messages via call, SMS, or WhatsApp.
Conclusion
UPI is India's most popular digital payment method. As of June 2024, there are around 350 million active users of the UPI in India. The Indian Cyber Crime Coordination Centre (I4C) report indicates that ‘Online Financial Fraud’, a cyber crime category under NCRP, is the most prevalent among others. The rise of financial fraud, particularly UPI fraud is cause for alarm, the scammers use sophisticated strategies to deceive victims. It is high time for netizens to exercise caution and care with their personal and financial information, stay aware of common tactics used by fraudsters, and adhere to best security practices for secure transactions and the safe use of UPI services.
References
Related Blogs

Introduction
The development of high-speed broadband internet in the 90s triggered a growth in online gaming, particularly in East Asian countries like South Korea and China. This culminated in the proliferation of competitive video game genres, which had otherwise existed mostly in the form of high-score and face-to-face competitions at arcades. The online competitive gaming market has only become bigger over the years, with a separate domain for professional competition, called esports. This industry is projected to reach US$4.3 billion by 2029, driven by advancements in gaming technology, increased viewership, multi-million dollar tournaments, professional leagues, sponsorships, and advertising revenues. However, the industry is still in its infancy and struggles with fairness and integrity issues. It can draw lessons in regulation from the traditional sports market to address these challenges for uniform global growth.
The Growth of Esports
The appeal of online gaming lies in its design innovations, social connectivity, and accessibility. Its rising popularity has culminated in online gaming competitions becoming an industry, formally organised into leagues and tournaments with reward prizes reaching up to millions of dollars. Professional teams now have coaches, analysts and psychologists supporting their players. For scale, the 2024 ESports World Cup (EWS) held in Saudi Arabia had the largest combined prize pool of over US$60 million. Such tournaments can be viewed in arenas and streamed online, and by 2025, around 322.7 million people are forecast to be occasional viewers of esports events.
According to Statista, esports revenue is expected to demonstrate an annual growth rate (CAGR 2024-2029) of 6.59%, resulting in a projected market volume of US$5.9 billion by 2029. Esports has even been recognised in traditional sporting events, debuting as a medal sport in the Asian Games 2022. In 2024, the International Olympic Committee (IOC) announced the Olympic Esports Games, with the inaugural event set to take place in 2025 in Saudi Arabia. Hosting esports events such as the EWS is expected to boost tourism and the host country’s local economy.
The Challenges of Esports Regulation
While the esports ecosystem provides numerous opportunities for growth and partnerships, its under-regulation presents challenges. Due to the lack of a single governing body like the IOC for the Olympics or FIFA for football to lay down centralised rules, the industry faces certain challenges, such as :
- Integrity issues: Esports are not immune to cheating attempts. Match-fixing, using advanced software hacks, doping (e.g., Adderall use), and the use of other illegal aids are common. DOTA, Counter-Strike, and Overwatch tournaments are particularly susceptible to cheating scandals.
- Players’ Rights: The teams that contractually own professional players provide remuneration and exercise significant control over athletes, who face issues like overwork, a short-lived career, stress, the absence of collective bargaining forums, instability, etc.
- Fragmented National Regulations: While multiple countries have recognised esports as a sport, policies on esports governance and allied regulation vary within and across borders. For example, age restrictions and laws on gambling, taxation, labour, and advertising differ by country. This can create confusion, risks and extra costs, impacting the growth of the ecosystem.
- Cybersecurity Concerns: The esports industry carries substantial prize pools and has growing viewer engagement, which makes it increasingly vulnerable to Distributed Denial of Service (DDoS) attacks, malware, ransomware, data breaches, phishing, and account hijacking. Tournament organisers must prioritise investments in secure network infrastructure, perform regular security audits, encrypt sensitive data, implement network monitoring, utilise API penetration testing tools, deploy intrusion detection systems, and establish comprehensive incident response and mitigation plans.
Proposals for Esports Regulation: Lessons from Traditional Sports
To address the most urgent challenges to the esports industry as outlined above, the following interventions, drawing on the governance and regulatory frameworks of traditional sports, can be made:
- Need for a Centralised Esports Governing Body: Unlike traditional sports, the esports landscape lacks a Global Sports Organisation (GSO) to oversee its governance. Instead, it is handled de facto by game publishers with industry interests different from those of traditional GSOs. Publishers’ primary source of revenue is not esports, which means they can adopt policies unsuitable for its growth but good for their core business. Appointing a centralised governing body with the power to balance the interests of multiple stakeholders and manage issues like unregulated gambling, athlete health, and integrity challenges is a logical next step for this industry.
- Gambling/Betting Regulations: While national laws on gambling/betting vary, GSOs establish uniform codes of conduct that bind participants contractually, ensuring consistent ethical standards across jurisdictions. Similar rules in esports are managed by individual publishers/ tournament organisers, leading to inconsistencies and legal grey areas. The esports ecosystem needs standardised regulation to preserve fair play codes and competitive integrity.
- Anti-Doping Policies: There is increasing adderall abuse among young players to enhance performance with the rising monetary stakes in esports. The industry must establish a global framework similar to the World Anti-Doping Code, which, in conjunction with eight international standards, harmonises anti-doping policies across all traditional sports and countries in the world. The esports industry should either adopt this or develop its own policy to curb stimulant abuse.
- Norms for Participant Health: Professional players start around age 16 or 17 and tend to retire around 24. They may be subjected to rigorous practice hours and stringent contracts by the teams that own them. There is a need for international norm-setting by a federation overseeing the protection of underage players. Enforcement of these norms can be one of the responsibilities of a decentralised system comprising country and state-level bodies. This also ensures fair play governance.
- Respect and Diversity: While esports is technologically accessible, it still has room for better representation of diverse gender identities, age groups, abilities, races, ethnicities, religions, and sexual orientations. Embracing greater diversity and inclusivity would benefit the industry's growth and enhance its potential to foster social connectivity through healthy competition.
Conclusion
The development of the world’s first esports island in Abu Dhabi gives impetus to the rapidly growing esports industry with millions of fans across the globe. To sustain this momentum, stakeholders must collaborate to build a strong governance framework that protects players, supports fans, and strengthens the ecosystem. By learning from traditional sports, esports can establish centralised governance, enforce standardised anti-doping measures, safeguard athlete rights, and promote inclusivity, especially for young and diverse communities. Embracing regulation and inclusivity will not only enhance esports' credibility but also position it as a powerful platform for unity, creativity, and social connection in the digital age.
Resources
- https://www.statista.com/outlook/amo/esports/worldwide
- https://www.statista.com/statistics/490480/global-esports-audience-size-viewer-type/
- https://asoworld.com/blog/global-esports-market-report-2024/#:~:text=A%20key%20driver%20of%20this%20growth%20is%20the%20Sponsorship%20%26%20Advertising,US%24288.9%20million%20in%202024.
- https://lawschoolpolicyreview.com/2023/12/28/a-case-for-recognising-professional-esports-players-as-employees-of-their-game-publisher/
- https://levelblue.com/blogs/security-essentials/the-hidden-risks-of-esports-cybersecurity-on-the-virtual-battlefield
- https://medium.com/@heyimJoost/esports-governance-and-its-failures-9ac7b3ec37ea
- https://www.google.com/search?q=adderall+abuse+in+esports&oq=adderall+abuse+in+esports&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDU2MDdqMGo5qAIAsAIB&sourceid=chrome&ie=UTF-8
- https://americanaddictioncenters.org/blog/esports-adderall-abuse#:~:text=A%202020%20piece%20by%20the,it%20because%20everyone%20was%20using

Introduction
India officially became part of the US-led Pax Silica project on February 20, 2026, at the India AI Impact Summit in New Delhi. This was a significant milestone in India’s involvement in global technology and supply chain cooperation. India joined a coalition of advanced economies by signing the Pax Silica Declaration in a move aimed at strengthening coordination over technology supply chains on which artificial intelligence, semiconductors, critical minerals and advanced manufacturing rely. The entry of India into the global technology landscape is indicative of India’s growing role in the global technology order and reflects broader shifts in how countries are responding to the geopolitics of silicon and AI infrastructure.
What Is Pax Silica and Why It Matters
The United States Department of State introduced Pax Silica as a strategic program launched in December 2025. It seeks to establish safe, resilient and innovation-driven supply chains for emerging technologies that are the foundations of the AI era. This encompasses activities ranging from mining and refining of rare earths, gallium and germanium to semiconductor manufacturing, the creation of advanced computing hardware and energy infrastructure. The project describes cooperation as a method of reducing what are termed as coercive dependencies on any one supplier or economy, thereby supporting sustained access to building blocks of state-of-the-art technology.
Pax Silica derives its name from the Latin terms for 'peace' and the substrate material of 'silicon', meaning that the coalition aims at achieving stability and prosperity by working together in supply chains of technology. Early signatories were the United States, Japan, South Korea, Australia, the United Kingdom, Israel, Singapore, the Netherlands, Greece, Qatar and the United Arab Emirates. India was the twelfth member to sign the declaration.
India’s Strategic Interests in Pax Silica
The move to join Pax Silica is both a diplomatic and economic decision. The incorporation of India into a network led ostensibly by the Western bloc and containing developed economy players in the technological supply chain creates the messaging that it wants to be more deeply integrated into the global high-tech ecosystems.
India currently relies on importing a large proportion of the chips for its electronics production sector, while its domestic manufacturing capacity remains limited. Pax Silica membership could provide Indian firms with advanced manufacturing equipment, process expertise and joint ventures with their partners, who have already developed the fabrication capabilities.
The signing of the declaration was done by the current Union Minister of Electronics and Information Technology (MeitY) , the Union Minister, who noted that India is expanding its technological capabilities and future ambitions. He observed that the Indian engineers already play a role in designing advanced semiconductor chips and that the increase in semiconductor capacity will demand a professional workforce. He also emphasised that the availability of international tools and alliances would help accelerate India’s growth in this sector.
Another strategic area is the critical minerals. India is estimated to have significant rare earth reserves, but the resources remain largely underdeveloped. The diversification strategy of Pax Silica in terms of supply and processing routes provides India with an opportunity to have joint ventures and infrastructure projects that could help unlock domestic mineral potential within the country.
Supply Chains, AI, and Geopolitical Context
Pax Silica has emerged within a broader geopolitical and supply chain context rather than as a purely economic initiative. The last few years have placed a strain on global technology supply chains with disruptions caused by pandemics, trade tensions, export controls, and the concentrated control of some components of the value chain. China currently dominates in the refinement of rare earths as well as in a variety of legacy semiconductor manufacturing. The concentration has raised concerns about resilience and strategic autonomy among the technology-producing democracies.
This initiative is based on the premise that a diversified and trusted supply chain will make the economic security of countries participating in Pax Silica more secure in case of a trade embargo or as a tool of political leverage. The voluntary and non-binding framework by the coalition only provides a guide to cooperation instead of a binding commitment, though it highlights an acknowledgement of risk and opportunity in global technology markets.
Such concerns as strategic autonomy and the extent of India’s involvement in the initiative have been expressed by those who criticise it, particularly because the coalition is perceived to be partially designed to respond to Chinese dominance in the most important technological sectors. Some analysts have also suggested that India will have to balance its participation in Pax Silica by taking special care of its own interests and alliances outside this coalition.
Economic and Industrial Implications for India
Joining Pax Silica offers India potential benefits on multiple fronts.
Strengthening Innovation and Manufacturing Ecosystems
India's membership will allow cooperation in semiconductor production, development of advanced computing infrastructure and implementation of AI. The government and industry players could attract investments through partnerships, technology transfer and joint R&D. India’s emerging design and fabrication projects could use a greater international integration in this venture.
Talent and Skills Development
A recurring theme among Indian policymakers is the issue of a skilled workforce. As the world semiconductor and AI sector is expected to need millions of specialists in the next 10 years, India’s large talent pool presents an opportunity to produce local talent that is capable of catering to local demands as well as international supply needs. Initiatives linked to Pax Silica have the potential to establish training pathways and institutional bridges that facilitate workforce preparedness.
Diversification of Supply Partnerships
In the case of India, the diversification of suppliers and partners goes beyond the availability of materials and technologies. It also implies reducing exposure to supply shocks and enhancing resilience in important industries such as consumer electronics, automotive manufacturing, defence systems and digital infrastructure, all of which rely on semiconductors and advanced computing hardware.
Broader Industrial Readiness and Domestic Challenges
India’s participation in Pax Silica highlights the domestic conditions required to support advanced technology manufacturing. A conducive environment will depend on reliable infrastructure, regulatory stability, specialised industrial clusters and sustained policy coordination across government and industry. Semiconductor and AI hardware production are resource-intensive, requiring significant energy, water and chemical management, making environmental safeguards and sustainable industrial planning essential to prevent long-term ecological strain.
At the same time, India faces gaps in its human resource development ecosystem. While engineering talent is abundant, specialised training in semiconductor fabrication, materials science and advanced manufacturing remains limited. Additionally, the relative lack of applied research and development initiatives aimed at reducing technological and financial risks may constrain large-scale industrial expansion, underscoring the need for stronger industry–academia collaboration and targeted innovation support.
Conclusion: A Strategic Step into the AI Era
India’s formal entry into the Pax Silica initiative at the 2026 India AI Impact Summit reflects a thoughtful recalibration of its global technology engagement. By aligning with a coalition aimed at securing the supply chains that make modern digital economies possible, India has signalled its intent to be more than just a consumer of technology. It seeks to help shape the infrastructure, partnerships and norms that will define the next generation of AI, semiconductors and critical technologies.
While questions around strategic autonomy and long-term dependencies remain important considerations, Pax Silica offers India access to networks, capabilities and collaborative frameworks that can accelerate its semiconductor ambitions and broaden its role in the global tech order. The move underscores how technology cooperation today increasingly interacts with geopolitics, economic strategy and national aspirations for growth and innovation.
Sources
- https://timesofindia.indiatimes.com/technology/tech-news/what-is-pax-silica-and-why-does-india-joining-the-ai-supply-chain-alliance-matter/articleshow/128594775.cms
- https://paxsilica.org/f/pax-silica-securing-the-foundations-of-the-ai-era
- https://www.businesstoday.in/india/story/ai-impact-summit-2026-india-set-to-join-us-led-pax-silica-today-517167-2026-02-20
- https://www.business-standard.com/india-news/pax-silica-india-joins-us-supply-chain-initiative-ai-impact-summit-2026-126022000339_1.html

Introduction
Web applications are essential in various sectors, including online shopping, social networks, banking, and healthcare systems. However, they also pose numerous security threats, including Cross-Site Scripting (XSS), a client-side code injection vulnerability. XSS attacks exploit the trust relationship between users and websites, allowing them to change web content, steal private information, hijack sessions, and gain full control of user accounts without breaking into the core server. This vulnerability is part of the OWASP Top 10 Web Application Security Risks.
What is Cross-Site Scripting (XSS)?
An XSS attack occurs when an attacker injects client-side scripts into web pages viewed by other users. When users visit the affected pages, their browsers naively execute the inserted scripts. The exploit takes advantage of web applications that allow users to submit content without properly sanitising inputs or encoding outputs. These scripts can cause a wide range of damage, including but not limited to stealing session cookies for session hijacking, redirecting users to malicious sites, logging keystrokes to capture credentials, and altering the DOM to display fake or phishing content.
How Does XSS Work?
- Injection: A malicious user submits code through a website input, like a comment or form.
- Execution: The submitted code runs automatically in the browsers of other users who view the page.
- Exploitation:The attacker can steal session information, capture credentials, redirect users, or modify the page content.
The fundamental cause behind the XSS vulnerabilities is the application of:
- Accepting trusted input from the users.
- After users' input, web pages have the strings embedded without any sanitisation.
- Not abiding by security policies like Content Security Policy (CSP).
With such vulnerabilities, attackers can generate malicious payloads like: <script>alert('XSS');</script>
This code might seem simple, but its execution provides the attacker with the possibility to do the following:
- Copy session tokens through hidden HTTP requests.
- From attacker-controlled domains, load attacker scripts.
- Change the DOM structure to show fake login forms for phishing.
Types of XSS Attacks: XSS (Cross-Site Scripting) attacks can occur in three main variations:
- Stored XSS: This type of attack occurs when an attacker injects an administered payload into the database or a message board. The script then runs whenever a user visits the affected board.
- Reflected XSS: In this attack, the danger lies in a parameter of the URL. Its social engineering techniques are attacks, in which it requires tricking people to click on a specially designed link. For example:
- DOM-Based XSS: This technique injects anything harmful without the need for server-side scripts, in contrast to other approaches. It targets JavaScript client-side scripts such as `document.write` and `innerHTML`. Without carrying out any safety checks, these scripts will alter the page's look (DOM stands for Document Object Model). If the hash is given a malicious string, it is run directly within the browser.
What Makes XSS a Threat?
A Cross-Site Scripting attack is only a primary attack vector, and can lead to significant damage that includes the following:
- Statement Hijacking. This uses scripts to steal cookies, which are then used to pose as authorized users.
- Theft of Credentials. Users’ passwords and usernames are wrenched from keystroke trackers.
- Phishing. Users are prompted with deceitful login forms that are used to capture sensitive details.
- Website Vandalism. Modified website material lowers the esteem of the brand.
- Monetary and Legal Consequences. There are compounding effects to GDPR and DPDP Act compliance in case of Data breaches, which incur penalties and fines.
Incidents in the Real World
In 2021, an XSS Stored attack occurred on a famous e-commerce platform eBay, through their product review system. The malicious JavaScript code was set to trigger every time an infected product page was accessed by customers. This caused a lot of problems, including account takeovers, unauthorised purchases, and damage to the company’s reputation. This example further worsens the fact that even reputed platforms can be targeted by XSS attacks.
How to Prevent XSS?
Addressing XSS vulnerabilities demands attention to detail and coordinated efforts across functions, as illustrated in the steps below:
Input Validation and Output Encoding:
- Ensure input validation is in place on the client and server.
- Perform output encoding relative to context: HTML: <, >, &.
- JavaScript: Escape quotes and slashes
Content Security Policy (CSP): CSP allows scripts to be executed only from the verified sources, which helps diminish the odds of harmful scripts running on your website. For example, the Header in the code could look to some degree like this: Content-Security-Policy: script-src 'self';
Unsafe APIs should be dodged: Avoid the use of document.write(), innerHTML, and eval(), and make sure to use:
- TextContent for inserting text.
- CreateElement() and other DOM creation methods for structured content.
Secure Cookies: Apply the HttpOnly and Secure cookie flags to block JavaScript access.
Framework Protections: Use the protective features in frameworks such as:
- React, which escapes data embedded in JSX automatically.
- Angular, which uses context-aware sanitisation.
Periodic Security Assessment:
- Use DAST tools to test the security posture of an application.
- Perform thorough penetration testing and security-oriented code reviews.
Best Practices for Developers: Assume a Secure Development Lifecycle (SDLC) integrating XSS stoppage at each point.
- Educate developers on OWASP secure coding guidelines.
- Automate scanning for vulnerabilities in CI/CD pipelines.
Conclusion:
To reduce the potential danger of XSS, both developers and companies must be diligent in their safety initiatives, ranging from using Content Security Policies (CSP) to verifying user input. Web applications can shield consumers and the company from the subtle but long-lasting threat of Cross-Site Scripting if security controls are implemented during the web application development stage and regular vulnerability scans are conducted.
References
- https://owasp.org/www-community/attacks/xss/
- https://www.paloaltonetworks.com/cyberpedia/xss-cross-site-scripting
- https://developer.mozilla.org/en-US/docs/Glossary/Cross-site_scripting
- https://www.cloudflare.com/learning/security/threats/cross-site-scripting/