The complex identity system behind India’s UPI payments exposes vulnerabilities

India’s Unified Payments Interface offers seamless transactions but conceals a layered identity infrastructure controlled by NPCI and payment service providers, raising concerns over fragility and security risks when providers exit or handles are abandoned.

India’s Unified Payments Interface has made sending money feel as simple as sending a text, but the identity sitting behind a UPI handle is more layered than most users realise. A name like rahul@oksbi looks like a personal alias created inside an app, yet the handle is only the visible end of a wider system in which the National Payments Corporation of India sets the rules, banks and payment firms register identities, and third-party apps provide the front end. Google Pay, PhonePe and similar services do not own the payment identity itself; they present a way to use it.

That distinction matters because the part after the @ is not a branding flourish. It identifies the payment service provider that controls the namespace for that address within the UPI network. According to Google’s own explanation of NPCI’s role, the payments body owns and operates UPI, approves participants and handles routing, processing and settlement. Paytm’s description of the system makes the same basic point: NPCI sits at the centre, PSPs manage the customer-facing and operational layer, and third-party apps connect users to the network.

The result is that one bank account can carry several UPI identities at once, each created through a different provider. A user may see a mobile-number handle from one app, a name-based handle from another and a merchant-facing address elsewhere, yet all of them can still point to the same underlying account. That is why the same person can pay or be paid through different handles depending on which application was used to register the identity. The address before the @ is the user-facing choice; the suffix is the provider’s.

UPI handles are also not permanent in the way many people assume. They can move through different states, from active to dormant and eventually inactive, depending on whether they continue to be used and whether the linked account remains available. Deleting an app does not automatically erase the underlying UPI identity, because the app is only the interface. The registration lives in the network and on the provider’s systems, which means payments can still reach that handle even after the application has been removed from a phone.

The more serious risk is what happens if the provider itself leaves the ecosystem. Handles are tied to PSP-owned namespaces, so a failure or withdrawal by that provider can put every address under that suffix in jeopardy. The Paytm Payments Bank episode in 2024 showed how disruptive that can become: users and merchants tied to @paytm had to shift to other arrangements, but there is no true porting mechanism for a VPA, only the creation of a new one and a race to update contacts, QR codes and records. In practice, that makes the namespace itself a point of fragility.

There is also little public clarity on what happens to abandoned handles if they are later recycled. That raises the possibility of confusion, mistaken payments and even impersonation if a dormant identity is reassigned. Because UPI is designed primarily for uniqueness and routing rather than trademark enforcement, protection against brand-like abuse tends to be reactive rather than preventive. The system is excellent at moving money quickly, but the ownership model behind each handle remains more complex, and less familiar, than the simple username format suggests.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.