Synthetic identities — built by combining real and fabricated personal details — are being used to open UPI-linked accounts at scale, slipping through simplified eKYC checks that were designed to speed up financial inclusion
India's financial system has undergone one of the most dramatic transformations of any major economy in the past decade. From 250 million internet users in 2014 to nearly a billion today, and from a cash-heavy culture to the world's largest real-time payments network, the country has rewritten the rules of money. But as digital transactions multiply at a pace few could have predicted, a quieter and more troubling story is unfolding: financial crime has evolved just as fast, and in some cases, faster than the systems designed to stop it.
A Revolution Built on UPI
The numbers are hard to argue with. In 2025, the Unified Payments Interface (UPI) processed 228.5 billion transactions. That's roughly half of all digital payments made anywhere in the world. The RBI's Digital Payments Index has quadrupled since 2018. India now hosts more than 10,000 active fintechs and is projected to become an $867 billion financial services market by 2033, growing at nearly 29% annually.
Much of this growth has come from pulling people into the formal economy who were previously excluded from it entirely. Tier-2 and Tier-3 cities have driven a surge in crypto adoption, with around 119 million active users today. Digital gold investing has grown from 30-40 million people in 2022 to roughly 120 million in 2025. The speed and reach of this inclusion are genuinely remarkable.
The problem is that the compliance systems designed to keep financial crime in check were built for a different world — one accustomed to batch processing (high-volume, repetitive data jobs), slower transaction speeds, and fewer payment channels. That world no longer exists.
Compliance Infrastructure Left Behind
Every UPI transaction is irrevocable. There are over 20 billion of them every month. The window for detecting something suspicious has collapsed from days to seconds. Banks and payment providers now operate across multiple rails simultaneously — UPI, IMPS, digital wallets, BNPL platforms, and cross-border transfers — each with different data formats and identity standards. The result is a fragmented screening environment full of blind spots.
The scale of the problem is no longer abstract. UPI fraud cases jumped 85% in FY2023-24 alone, and by September 2024, over 630,000 incidents had already been reported for that financial year. Government projections put total cybercrime losses in 2025 at over ₹1.2 lakh crore - roughly ₹10,000 crore lost every month. Since 2022, cumulative losses from UPI-related fraud have crossed $21 billion across 2.7 million reported cases. One in five UPI users has experienced fraud in the past three years, and more than half of victims never file a complaint.
Fraudsters have adapted quickly to the new environment. Synthetic identities — built by combining real and fabricated personal details — are being used to open UPI-linked accounts at scale, slipping through simplified eKYC checks that were designed to speed up financial inclusion. Mule networks are now industrial in size: the RBI and the CBI revealed in 2025 that there were approximately 8.5 lakh mule accounts in the country, while the Indian Cyber Crime Coordination Centre estimates that the numbers could be over 20 lakh. These accounts are typically opened using someone else’s KYC documents and used to receive and disperse stolen funds before anyone notices.
QR code fraud has become a staple of street-level crime. The Delhi Police have documented schemes where fake QR codes were embedded in hotel booking websites, redirecting payments to fraudsters while victims believed they were paying legitimate merchants. In Tier-2 and Tier-3 cities, OTP-sharing bots now mimic delivery alerts to trick users into authorising payments. Regulators have also shifted their expectations. They are no longer satisfied with knowing that a financial institution has a compliance system. They want to know whether it actually works. The RBI has increased the number of penalties imposed on financial institutions by 88 per cent from 2021 to 2024, with Know Your Customer (KYC) and Anti-Money Laundering (AML) violations being the most common, according to a report by The Economic Times. Additionally, to keep digital fraud in check, the regulators have reinforced focus on AI-driven monitoring, mule account detection, and cross-institution data sharing, signalling a move from isolated controls to network-level intelligence. The question has moved from "do you have controls in place?" to "can you prove they're effective at scale?" The burden of proof now rests with the institution.
What Needs to Change
The gap between how fast money moves and how fast compliance catches up is not a technology problem alone — it's a strategic one. Financial institutions that want to keep up need to rethink their approach across four areas.
First is accuracy. Reducing the noise of false positives while keeping detection rates high is the central operational challenge for most compliance teams. Advanced matching techniques — fuzzy logic, phonetic matching, transliteration-aware algorithms — can help, but only if the underlying models can be explained to regulators and auditors, not just trusted blindly.
Second is speed. Real-time, high-throughput screening through cloud-native and API-first infrastructure is no longer optional. A centralised list management — a single source of truth across all payment rails — removes the inconsistencies that criminals exploit.
Third is identity intelligence. KYC records capture a moment in time; they don't reflect how people actually behave. The systems that enabled financial inclusion at scale — Aadhaar-based onboarding and simplified KYC — have also lowered barriers for identity misuse. Layering in digital identity signals — device behaviour, location data, email and phone history — closes the gap between what an institution knows about a customer on paper and who is actually transacting.
Fourth is convergence. Fraud and financial crime are no longer separate problems. In India, mule accounts sit at the intersection of fraud operations and AML compliance, and yet aren’t often owned fully by either. Keeping fraud teams and financial crime compliance teams in separate silos means sharing neither data nor intelligence. Unified case management and industry-wide data sharing would allow patterns to be detected that no single institution could see on its own.
The author is Director, Financial Crime Compliance (Market Planning), LexisNexis® Risk Solutions. Views expressed are personal.

