A handy new technology spreads halfway around the world before security gets its shoes on.— a riff on the famous old saying about a lie and the truth; it seems even more fitting today.
For the last few months, my security alert feed has been filled with India. Not by design — I follow QR fraud globally — but the coverage keeps arriving from Indian outlets, faster and more voluminous than from anywhere else. Fake refund codes. Poisoned parking stickers, KYC updates needed, and more. Each piece outlines a particular scam, replays warnings from CERT-In, India’s national cyber agency, and closes with advice that conveys little more than ‘be careful’.
The lazy read is that India is more careless than everyone else. It isn’t. Something structural is going on, and it’s more interesting — and more universal — than a story about one country’s explosive growth of scams.
India Didn’t Fall Behind. It Jumped a Generation
Most of the world crept into digital payments. India vaulted.
Financial institutions in the West spent fifty years laying down plastic: credit cards to imprint, then with magnetic stripes, ultimately embedded chips. Behind the convenient plastic card in the user’s hand was a vast network of point-of-sale terminals, merchant onboarding services, transaction incentives, and network providers.
India never fully adopted any of it — card penetration and terminal coverage stayed thin. So when digital payments arrived, India didn’t need to retrofit the old rails. It skipped them entirely and built UPI — the Unified Payments Interface, launched by a national body (NPCI) in 2016. Real-time. Account-to-account. Free at the point of use. A customer pays by scanning a QR code — no card reader, no terminal, no special hardware at all. A printed square taped to a counter turns a fruit cart into a merchant.
This remains a genuine triumph. UPI moves more real-time transactions than any system on Earth, by a wide margin. It is, by most measures, the most advanced consumer payment rail humanity has built. Designed by Indian engineers, endorsed by the Indian government, and supported across Indian institutions.
When people talk about “technology leapfrogging”, Scandinavia skipping copper wire and going direct to mobile services has been the canonical example. India’s jump to UPI belongs in that category, and maybe not as the second example.
Yet every leapfrog carries a hidden cost, and it’s the same cost every time.
Leapfrogging skips the immune system
When you jump a technological generation, you don’t just skip the plumbing. You skip the immune system that co-evolved with the thing you jumped over.
The West’s card economy dragged a half-century of defenses behind it, most of them invisible until they fire: chargebacks, dispute resolution, issuer fraud-scoring, liability shift, terminal vetting, the whole apparatus that quietly identifies fraudulent transactions and stops them. Nobody experiences that scaffolding directly — it doesn’t introduce any friction in the transaction. You notice it only on the rare occasion that something gets flagged. And if you dispute it, the provider shifts the cost from you. The benefit of this immune system is not just the infrastructure built around transaction integrity, it’s also the business model designed to absorb a certain amount of fraud. Credit card users benefit from both convenience and peace of mind.
India inherited none of it. Not because it was reckless, but because India never adopted the cards that the immune system was built around. You can leap to the destination. You cannot leap to the antibodies. They only come from having lived through the disease and building defenses bit by bit.
If that sounds like a metaphor doing too much work, consider that we have already run this exact experiment once — with the last technology the world leapfrogged into.
We have seen this movie before. It was called wireless.
The first automatic mobile networks — Nordic NMT, launched 1981. Automatic, in this case meaning no human operator was involved, the network was connected across international carrier networks, and rather than a single radio tower covering a single geography, a grid of smaller, geographically distributed radios each allowing frequency re-use within its area of coverage. A communications miracle that wasn’t constrained by existing infrastructure that needed repurposing. This approach was clearly superior to others — the cellular game was on.
Since this analog ‘cellular network’ model was built from a clean sheet, they didn’t carry forward any of the antibodies previous network operators had developed. They shipped with essentially no authentication and no encryption. A phone announced its identity over the air in the clear, and anyone with the right radio gear could capture that identity and clone the handset, charging their calls to a stranger.
This was not a fringe problem. At its peak, cloning fraud cost U.S. analog carriers more than $500 million a year. The convenience had spread halfway around the world; the security was still lacing its shoes.
The fix was not a patch. It was a new generation of hardware, protocol, and handset. By the early 90s, carriers knew they needed to move to digital (marketed as ‘second generation,’ or 2G). The GSM standard introduced the SIM card — a tamper-resistant chip holding a secret key, running a cryptographic challenge-and-response so the network could verify a phone was really itself. Authentication, the immune system that analog never had, was retrofitted after the fraud, in response to it.
That is the pattern, stripped to its bones: convenience ships first, fraud fills available capacity, and the defensive layer gets built afterward. At a cost and in a hurry.
India’s QR fraud is not a new story. It is the same movie playing out in a new medium — payments instead of phone calls, a printed square with black dots instead of an unencrypted radio signal.
Except the QR turns out to be an even better weapon for scammers.
Why the QR rail turbocharges fraud
Three features of the way India pays turn “no immune system yet” into “epicenter.” Each is a major boon for digital payments, but each presents vulnerability in the immune system.
First, UPI is a push, not a pull. A credit card payment is a pull: the merchant requests money from the card issuer after the transaction, and the whole disputable, reversible card machinery sits between the request and your money.
UPI is a push: you authorize money out, and it is gone — instant, irreversible, into a real bank account, with no chargeback to claw it back. It’s akin to a debit transaction rather than a credit one — but without the physical card or the point-of-sale terminal; you approve the push right on your phone. That single design choice moves the entire attack surface. Card fraud is a data problem: steal the number, try to use the card. UPI fraud is a consent problem: convince a human that the transaction is normal and as-expected. The attacker’s job is no longer technical. It’s persuasion.
Second, the trust surface is paper. There’s no terminal to vet, no card skimmer to check for, no hardware to compromise — just a sticker with some dots. Anyone can print one, and the way they work, that printed sticker can instruct the phone to connect to anywhere. My sticker can be pasted over your sticker, and I’ve redirected the transaction to my bank account. In a shop or restaurant, on a parking meter, anywhere. A clean reprint is indistinguishable from the original — humans can’t parse the dots the way the phone can. The thing standing between a payment and a fraudster is an adhesive rectangle.
Third, the QR hides the ‘direction of travel’. A QR collapses “who am I paying, and which way is the money going” into an opaque square the eye cannot read. That’s why the single most common Indian con is “scan this to receive your refund.” It works because most people don’t know the one rule that would save them — as Indian outlets themselves now state plainly, you never need a UPI PIN or an OTP to receive money, only to send it. The victim thinks they’re accepting cash. They’re actually authorizing its exit. The square never showed them the arrow.
In addition, an accelerant. In 2016 — the same year UPI launched — India’s disruptive newcomer MNO, Reliance Jio, collapsed the price of mobile data to among the cheapest in the world, putting a smartphone into hundreds of millions of first-time hands. India didn’t onboard a generation to digital payments gradually. It onboarded them all at once, like a Cambrian Explosion, and faster than the security antibodies could imprint. The convenience arrived instantly. The security immune system is still developing.
This isn’t about India getting it wrong
India is going through a natural evolutionary cycle — and doing it pretty well.
India is not unique, but it is the clearest, best-documented case of a universal pattern. UPI provides the biggest, most transparent instance, which is why it dominates my alerts. Wherever push-payments and QR codes leapfrog the old rails, the same frontier opens: Brazil with PIX, Southeast Asia with QRIS and PromptPay, Kenya with M-Pesa. And, one generation back, everyone using analog wireless. This pattern generalizes across space — from India to Brazil — and across time — from cloned phones to poisoned payment codes. It is not an emerging-markets quirk. It is simply what technological leapfrogs do.
And India is institutionalizing its immunity development. Regular notifications and warnings from CERT-In; the RBI acts; NPCI moving to rein in the collect-request feature the scammers abused. The immune system is mobilizing — it’s simply behind the adoption curve, which is exactly what “leapfrogging skips the immune system” predicts. A rate mismatch, not a social failing.
The square you cannot read
Step back far enough and the QR code is a single, radical idea: a trust-compression device. It takes everything you’d want to know before parting with money or attention — who is on the other end, where this leads, which direction the value flows — and compresses it into a pattern of squares that no human can decode by looking.
For most of economic history, that trust lived in institutions you could see: a bank branch with a name over the door, a card network’s logo, a payment terminal a merchant had to be vetted to own. The QR economy strips the institution out of the middle and puts the transaction directly between two phones. That’s the source of its magic — a fruit cart becomes a merchant with a fifty-cent sticker — and the source of its danger. Because when you remove the institution, you remove the place the immune system used to live. The defensive layer has to be rebuilt somewhere new: not in a bank’s back office, but at the point of scan, in the individual’s hand.
That is not an Indian problem. It’s the frontier every QR-native economy is walking toward, whether it’s noticed yet or not. India just got there first — the way pioneers always reach the frontier first, and meet its hazards first, and end up writing the field guide the rest of the world will read.
The scams filling my newsfeed aren’t evidence that India got it wrong. They’re evidence that India got it early. India succeeded at convenience so completely, and so fast, that it arrived at the place the rest of us are still heading — the place where the technology has spread halfway around the world and security is only now reaching for its shoes.
It’s a postcard from the future. Worth reading closely, because the return address is us.
Sources & further reading: Ericsson — the launch of NMT · Analog cellular “cloning” fraud · CERT-In / India QR-fraud coverage.