UPI Payment System Attack
Adversary compromises a payment aggregator's API gateway, triggering cascading UPI failures across NPCI infrastructure. RBI, CERT-In, and DPDP response exercise.
📋 Scenario Brief
Background
FinPay Solutions processes ₹8,000 crore in UPI transactions daily for 120 merchant clients including three major e-commerce platforms and two government service portals. The company holds a Payment Aggregator licence from RBI and is classified as a Critical Information Infrastructure (CII) operator by NCIIPC.
Scenario Setup — Read to Participants
⏱️ Incident Timeline — Facilitator Guide
Release each inject at the indicated time. Do not reveal future injects. Observe team discussion and note decision quality.
🤔 Key Decision Points
Present each decision to participants before revealing the guidance. There are no definitively correct answers — the goal is structured discussion.
📋 Regulatory Response Checklist
| Regulator | Obligation | Timeline | Contact | Status |
|---|---|---|---|---|
| NPCI | Notify of payment system disruption affecting UPI operations | 2 hours from detection | NPCI Cybersecurity Operations — npci.org.in | |
| RBI DPSS | Preliminary incident report (cyber incident affecting PA licence) | 2 hours from detection | RBI Cyber Security and IT Examination Cell | |
| CERT-In | Mandatory incident report — cyber attack on payment infrastructure | 6 hours from detection | incident@cert-in.org.in / 1800-11-4949 | |
| Data Protection Board | Personal data breach notification (2.3 lakh customer records) | 72 hours (when DPB operational) | dpboard.gov.in (pending operationalisation) | |
| NCIIPC | Report as CII operator — payment infrastructure incident | Within 24 hours | incident@nciipc.gov.in | |
| Cyber Cell (Police) | File FIR for financial fraud — mandatory for amounts above ₹10 lakh | As soon as feasible | Local Commissioner of Police Cyber Cell | |
| Affected Merchants | Contractual obligation to notify breach affecting their transaction data | Per merchant agreement (check SLAs) | Direct via account managers |