🏦 Tabletop Scenario — India

UPI Payment System Attack

Adversary compromises a payment aggregator's API gateway, triggering cascading UPI failures across NPCI infrastructure. RBI, CERT-In, and DPDP response exercise.

📋 Scenario Brief

Organisation
FinPay Solutions Pvt Ltd — a licensed Payment Aggregator (PA) under RBI
Sector
BFSI / Payments Infrastructure
Exercise Duration
3-4 hours recommended
Participants
CISO, CTO, Legal, Compliance, Customer Relations, PR, Senior Management
Threat Actor
Nation-state affiliated group with financial sector motivation (APT41-like TTPs)
MITRE ATT&CK
T1190 (Exploit Public App), T1059 (Command Line), T1071 (C2), T1657 (Financial Theft)

Background

FinPay Solutions processes ₹8,000 crore in UPI transactions daily for 120 merchant clients including three major e-commerce platforms and two government service portals. The company holds a Payment Aggregator licence from RBI and is classified as a Critical Information Infrastructure (CII) operator by NCIIPC.

Scenario Setup — Read to Participants

It is Tuesday, 11:23 AM. Your SIEM has generated 847 alerts in the last 40 minutes — far above the normal 12/hour baseline. The monitoring dashboard shows API error rates on your NPCI connection have spiked to 34%. Three merchant clients have called in the last 10 minutes reporting transaction failures. The on-call SOC analyst has escalated to you. Your CEO has just forwarded a tweet from a prominent fintech journalist: "Hearing from multiple merchants that @FinPaySolutions is down — anyone else?"

⏱️ Incident Timeline — Facilitator Guide

Release each inject at the indicated time. Do not reveal future injects. Observe team discussion and note decision quality.

T+0 minInitial Detection
SIEM alert volume 70× baseline. API gateway logs show repeated authentication failures from an IP range not previously seen — 103.21.47.0/24 (later attributed to bulletproof hosting). NPCI API returning HTTP 503 on 34% of requests.
Inject: SOC analyst calls: "We're seeing what looks like credential stuffing against our merchant API. 12,000 failed auth attempts in 20 minutes from rotating IPs. Some are succeeding — I can see valid merchant tokens being used for unusual transaction patterns."
T+15 minEscalation & Scope
Valid merchant tokens compromised. Attacker is routing micro-transactions (₹1-9) through thousands of merchant accounts to avoid velocity checks. Transaction volume is 4× normal — NPCI rate limits triggered.
Inject: Head of Engineering: "I've found the entry point — a 0-day in the payment gateway API endpoint /v2/merchant/auth. It's been exploited since 10:41 AM. Someone found the JWT secret hardcoded in a public GitHub commit from 3 months ago. We have logs but they show 40+ merchants affected."
T+30 minRegulatory Clock Starts
Confirmed breach of payment infrastructure. NPCI has detected anomalous traffic from FinPay's IP range and sent an automated alert. You now have confirmation of a cyber incident affecting a Payment System Operator.
Inject (phone call): "This is the Cyber Fraud Helpline, RBI DPSS calling. We've received an automated flag from NPCI about unusual traffic originating from your systems. Can you confirm the status of your payment processing infrastructure? We need a preliminary report within 2 hours."
T+45 minCustomer Impact Confirmed
Forensic analysis reveals attacker exfiltrated 2.3 lakh customer transaction records including name, phone number, bank account masked details, and UPI VPA (Virtual Payment Address). DPDP Act breach notification obligations triggered.
Inject (email): Subject: "URGENT — Customer data on dark web?" From: your Head of Customer Relations. "A journalist from The Economic Times just contacted us with screenshots of what appears to be our customer data on a Telegram channel. They're asking for comment within 30 minutes for a story going live at 2 PM."
T+90 minContainment Decision
Security team has identified the compromised API endpoint. Taking it offline stops the attack but also stops all payment processing — impacting ₹600+ crore in pending transactions and all 120 merchant clients.
Inject: CEO enters the room: "The board is asking me to make a decision. Do we take the system offline completely and eat the business impact, or do we try to patch while running? I need your recommendation in 5 minutes."
T+3 hoursRecovery & Reporting
Systems brought online after emergency patch. CERT-In 6-hour notification deadline approaching. RBI has requested a written preliminary report. ET story published — moderate national coverage. Three merchants have sent legal notices.
Inject: Legal counsel: "RBI wants a formal incident report. NPCI has suspended our direct NPCI membership pending investigation. We also need to decide what to tell the Data Protection Board — the DPDP rules on notification timelines aren't fully notified yet but we're exposed. What do we file and when?"

🤔 Key Decision Points

Present each decision to participants before revealing the guidance. There are no definitively correct answers — the goal is structured discussion.

T+30 min: RBI DPSS has called asking for a preliminary report within 2 hours. What do you do?
Guidance: Best practice: A + C together. Acknowledge the call, confirm you are investigating a potential incident, commit to the 2-hour timeline, and immediately loop in Legal and CEO. RBI DPSS has direct supervisory authority over Payment Aggregators — do not stonewall or delay. The 2-hour NPCI notification is a condition of your PA licence. Silence is not neutral — it creates regulatory risk.
T+45 min: ET journalist has screenshots of customer data. You have 30 minutes before publication. What do you do?
Guidance: Best practice: B. A holding statement ("We are aware of reports and are investigating") prevents a vacuum that the journalist will fill with speculation. Option C risks a false denial that damages credibility when the breach is confirmed. Option D (news embargo for exclusive) is a recognised PR strategy but creates ethical complications and usually backfires. Option A is legally safe but appears evasive in Indian media coverage.
T+90 min: Take the system fully offline (stopping ₹600 crore in transactions) or attempt live patching?
Guidance: Best practice: C, then A if segmentation fails. Segmentation allows continued operation on clean paths while the compromised endpoint is isolated. Full offline (A) is the most defensible position for regulatory reporting. Live patching (B) under active attack is high risk — patch may fail or be incomplete. Option D (continue and monitor) is indefensible to RBI if the attacker exfiltrates more data during the monitoring window.

📋 Regulatory Response Checklist

RegulatorObligationTimelineContactStatus
NPCINotify of payment system disruption affecting UPI operations2 hours from detectionNPCI Cybersecurity Operations — npci.org.in
RBI DPSSPreliminary incident report (cyber incident affecting PA licence)2 hours from detectionRBI Cyber Security and IT Examination Cell
CERT-InMandatory incident report — cyber attack on payment infrastructure6 hours from detectionincident@cert-in.org.in / 1800-11-4949
Data Protection BoardPersonal data breach notification (2.3 lakh customer records)72 hours (when DPB operational)dpboard.gov.in (pending operationalisation)
NCIIPCReport as CII operator — payment infrastructure incidentWithin 24 hoursincident@nciipc.gov.in
Cyber Cell (Police)File FIR for financial fraud — mandatory for amounts above ₹10 lakhAs soon as feasibleLocal Commissioner of Police Cyber Cell
Affected MerchantsContractual obligation to notify breach affecting their transaction dataPer merchant agreement (check SLAs)Direct via account managers

📊 Debrief Guide — Facilitator

Discussion questions

Did the team know the RBI DPSS 2-hour notification requirement before this exercise? Who in the organisation owns that notification?
At what point did Legal get involved? Was it soon enough? What would have happened if Legal was only called at T+90 min?
How did the team handle the media pressure? Who is authorised to speak to journalists during an incident?
The CEO asked for a recommendation in 5 minutes. Was the team ready to make that call? What information was missing?
Was there a clear decision owner for each action? Or did the group try to reach consensus on every decision?
What existing runbooks or procedures did the team reference? Where were the gaps?
How would this scenario differ if FinPay was a Small Finance Bank rather than a Payment Aggregator?

Common gaps found in Indian BFSI tabletops

RBI DPSS contact details not known — most teams google it during the exercise
CERT-In incident form not pre-filled — teams spend 40+ minutes on paperwork during a live incident
No pre-approved holding statement — PR drafts from scratch under pressure
Legal not empowered to make decisions — escalation loops consume the response window
NPCI suspension not anticipated — no contingency for operating without NPCI membership