<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Dan Foley</title>
    <description>The latest articles on DEV Community by Dan Foley (@danfoley1).</description>
    <link>https://dev.to/danfoley1</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4101661%2F2520809f-2d8b-481f-81ea-a215d4d64c61.png</url>
      <title>DEV Community: Dan Foley</title>
      <link>https://dev.to/danfoley1</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/danfoley1"/>
    <language>en</language>
    <item>
      <title>India Skipped the Credit Card. Now It's Paying for It.</title>
      <dc:creator>Dan Foley</dc:creator>
      <pubDate>Tue, 01 Sep 2026 09:52:09 +0000</pubDate>
      <link>https://dev.to/danfoley1/india-skipped-the-credit-card-now-its-paying-for-it-fpk</link>
      <guid>https://dev.to/danfoley1/india-skipped-the-credit-card-now-its-paying-for-it-fpk</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;A handy new technology spreads halfway around the world before security gets its shoes on.&lt;/em&gt;&lt;br&gt;
— a riff on the famous old saying about a lie and the truth; it seems even more fitting today.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For the last few months, my security alert feed has been filled with India. Not by design (I follow QR fraud globally), but the coverage keeps arriving from Indian outlets, faster and more voluminous than from anywhere else. Fake refund codes. Poisoned parking stickers, KYC updates needed, and more. Each piece outlines a particular scam, replays warnings from CERT-In, India's national cyber agency, and closes with advice that conveys little more than 'be careful'.&lt;/p&gt;

&lt;p&gt;The lazy read is that India is more careless than everyone else. It isn't. Something structural is going on, and it's more interesting, and more universal, than a story about one country's explosive growth of scams.&lt;/p&gt;

&lt;h2&gt;
  
  
  India Didn't Fall Behind. It Jumped a Generation
&lt;/h2&gt;

&lt;p&gt;Most of the world crept into digital payments. India vaulted.&lt;/p&gt;

&lt;p&gt;Financial institutions in the West spent fifty years laying down plastic: credit cards to imprint, then with magnetic stripes, ultimately embedded chips. Behind the convenient plastic card in the user's hand was a vast network of point-of-sale terminals, merchant onboarding services, transaction incentives, and network providers.&lt;/p&gt;

&lt;p&gt;India never fully adopted any of it. Card penetration and terminal coverage stayed thin. So when digital payments arrived, India didn't need to retrofit the old rails. It skipped them entirely and built &lt;strong&gt;UPI&lt;/strong&gt;, the Unified Payments Interface, launched by a national body (NPCI) in 2016. Real-time. Account-to-account. Free at the point of use. A customer pays by &lt;strong&gt;scanning a QR code&lt;/strong&gt;. No card reader, no terminal, no special hardware at all. A printed square taped to a counter turns a fruit cart into a merchant.&lt;/p&gt;

&lt;p&gt;This remains a genuine triumph. UPI moves more real-time transactions than any system on Earth, by a wide margin. It is, by most measures, the most advanced consumer payment rail humanity has built. Designed by Indian engineers, endorsed by the Indian government, and supported across Indian institutions.&lt;/p&gt;

&lt;p&gt;When people talk about "technology leapfrogging", Scandinavia skipping copper wire and going direct to mobile services has been the canonical example. India's jump to UPI belongs in that category, and maybe not as the second example.&lt;/p&gt;

&lt;p&gt;Yet every leapfrog carries a hidden cost, and it's the same cost every time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Leapfrogging skips the immune system
&lt;/h2&gt;

&lt;p&gt;When you jump a technological generation, you don't just skip the plumbing. You skip the &lt;em&gt;immune system that co-evolved with the thing you jumped over.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The West's card economy dragged a half-century of defenses behind it, most of them invisible until they fire: chargebacks, dispute resolution, issuer fraud-scoring, liability shift, terminal vetting, the whole apparatus that quietly identifies fraudulent transactions and stops them. Nobody experiences that scaffolding directly; it doesn't introduce any friction in the transaction. You notice it only on the rare occasion that something gets flagged. And if you dispute it, the provider shifts the cost from you. The benefit of this immune system is not just the infrastructure built around transaction integrity, it's also the business model designed to absorb a certain amount of fraud. Credit card users benefit from both convenience and peace of mind.&lt;/p&gt;

&lt;p&gt;India inherited none of it. Not because it was reckless, but because India never adopted the cards that the immune system was built around. You can leap to the destination. You cannot leap to the antibodies. They only come from having lived through the disease and building defenses bit by bit.&lt;/p&gt;

&lt;p&gt;If that sounds like a metaphor doing too much work, consider that we have already run this exact experiment once, with the last technology the world leapfrogged into.&lt;/p&gt;

&lt;h2&gt;
  
  
  We have seen this movie before. It was called wireless.
&lt;/h2&gt;

&lt;p&gt;The first automatic mobile networks, Nordic &lt;strong&gt;NMT&lt;/strong&gt;, launched 1981. Automatic, in this case meaning no human operator was involved, the network was connected across international carrier networks, and rather than a single radio tower covering a single geography, a grid of smaller, geographically distributed radios each allowing frequency re-use within its area of coverage. A communications miracle that wasn't constrained by existing infrastructure that needed repurposing. This approach was clearly superior to others. The cellular game was on.&lt;/p&gt;

&lt;p&gt;Since this analog 'cellular network' model was built from a clean sheet, they didn't carry forward any of the antibodies previous network operators had developed. They shipped with essentially &lt;strong&gt;no authentication and no encryption.&lt;/strong&gt; A phone announced its identity over the air in the clear, and anyone with the right radio gear could capture that identity and &lt;strong&gt;clone&lt;/strong&gt; the handset, charging their calls to a stranger.&lt;/p&gt;

&lt;p&gt;This was not a fringe problem. At its peak, cloning fraud cost U.S. analog carriers &lt;strong&gt;more than $500 million a year.&lt;/strong&gt; The convenience had spread halfway around the world; the security was still lacing its shoes.&lt;/p&gt;

&lt;p&gt;The fix was not a patch. It was a new generation of hardware, protocol, and handset. By the early 90s, carriers knew they needed to move to digital (marketed as 'second generation,' or 2G). The &lt;strong&gt;GSM&lt;/strong&gt; standard introduced the &lt;strong&gt;SIM card&lt;/strong&gt;, a tamper-resistant chip holding a secret key, running a cryptographic challenge-and-response so the network could verify a phone was really itself. Authentication, the immune system that analog never had, was &lt;em&gt;retrofitted after the fraud, in response to it.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;That is the pattern, stripped to its bones: convenience ships first, fraud fills available capacity, and the defensive layer gets built afterward. At a cost and in a hurry.&lt;/p&gt;

&lt;p&gt;India's QR fraud is not a new story. It is the same movie playing out in a new medium: payments instead of phone calls, a printed square with black dots instead of an unencrypted radio signal.&lt;/p&gt;

&lt;p&gt;Except the QR turns out to be an even better weapon for scammers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the QR rail turbocharges fraud
&lt;/h2&gt;

&lt;p&gt;Three features of the way India pays turn "no immune system yet" into "epicenter." Each is a major boon for digital payments, but each presents vulnerability in the immune system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;First, UPI is a push, not a pull.&lt;/strong&gt; A credit card payment is a &lt;em&gt;pull&lt;/em&gt;: the merchant requests money from the card issuer after the transaction, and the whole disputable, reversible card machinery sits between the request and your money.&lt;/p&gt;

&lt;p&gt;UPI is a &lt;em&gt;push&lt;/em&gt;: you authorize money out, and it is gone. Instant, irreversible, into a real bank account, with no chargeback to claw it back. It's akin to a debit transaction rather than a credit one, but without the physical card or the point-of-sale terminal; you approve the push right on your phone. That single design choice moves the entire attack surface. Card fraud is a &lt;em&gt;data&lt;/em&gt; problem: steal the number, try to use the card. UPI fraud is a &lt;em&gt;consent&lt;/em&gt; problem: convince a human that the transaction is normal and as-expected. The attacker's job is no longer technical. It's persuasion.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Second, the trust surface is paper.&lt;/strong&gt; There's no terminal to vet, no card skimmer to check for, no hardware to compromise, just a sticker with some dots. Anyone can print one, and the way they work, that printed sticker can instruct the phone to connect to &lt;em&gt;anywhere&lt;/em&gt;. My sticker can be pasted over your sticker, and I've redirected the transaction to my bank account. In a shop or restaurant, on a parking meter, anywhere. A clean reprint is indistinguishable from the original; humans can't parse the dots the way the phone can. The thing standing between a payment and a fraudster is an adhesive rectangle.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Third, the QR hides the 'direction of travel'.&lt;/strong&gt; A QR collapses "who am I paying, and which way is the money going" into an opaque square the eye cannot read. That's why the single most common Indian con is &lt;em&gt;"scan this to receive your refund."&lt;/em&gt; It works because most people don't know the one rule that would save them. As Indian outlets themselves now state plainly, &lt;strong&gt;you never need a UPI PIN or an OTP to &lt;em&gt;receive&lt;/em&gt; money, only to send it.&lt;/strong&gt; The victim thinks they're accepting cash. They're actually authorizing its exit. The square never showed them the arrow.&lt;/p&gt;

&lt;p&gt;In addition, an accelerant. In 2016, the same year UPI launched, India's disruptive newcomer MNO, Reliance Jio, collapsed the price of mobile data to among the cheapest in the world, putting a smartphone into hundreds of millions of first-time hands. India didn't onboard a generation to digital payments gradually. It onboarded them &lt;em&gt;all at once&lt;/em&gt;, like a Cambrian Explosion, and faster than the security antibodies could imprint. The convenience arrived instantly. The security immune system is still developing.&lt;/p&gt;

&lt;h2&gt;
  
  
  This isn't about India getting it wrong
&lt;/h2&gt;

&lt;p&gt;India is going through a natural evolutionary cycle, and doing it pretty well.&lt;/p&gt;

&lt;p&gt;India is not unique, but it is the &lt;em&gt;clearest, best-documented case of a universal pattern&lt;/em&gt;. UPI provides the biggest, most transparent instance, which is why it dominates my alerts. Wherever push-payments and QR codes leapfrog the old rails, the same frontier opens: Brazil with PIX, Southeast Asia with QRIS and PromptPay, Kenya with M-Pesa. And, one generation back, everyone using analog wireless. This pattern generalizes across &lt;em&gt;space&lt;/em&gt; (from India to Brazil) and across &lt;em&gt;time&lt;/em&gt; (from cloned phones to poisoned payment codes). It is not an emerging-markets quirk. It is simply what technological leapfrogs do.&lt;/p&gt;

&lt;p&gt;And India is institutionalizing its immunity development. Regular notifications and warnings from CERT-In; the RBI acts; NPCI moving to rein in the collect-request feature the scammers abused. The immune system is mobilizing; it's simply behind the adoption curve, which is exactly what "leapfrogging skips the immune system" predicts. A rate mismatch, not a social failing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Rebuilding the antibodies
&lt;/h2&gt;

&lt;p&gt;The useful thing about an immune system framing is that antibodies can be built deliberately, but that doesn't mean you have to catch every disease first. Some defenses are concrete and available to you today.&lt;/p&gt;

&lt;p&gt;If you accept payments by QR, the most important move is to own the destination: point your QR at a domain you control, not a third-party redirect. These 'dynamic QR providers' can change terms of service under you or hold your printed codes hostage behind a subscription fee.&lt;/p&gt;

&lt;p&gt;Make your domain simple and legible, then print it in plain text right next to your QR code. This lets the user match their phone preview with your destination.&lt;/p&gt;

&lt;p&gt;But that isn't an airtight approach. A QR that can be covered by a sticker will be, so place the QR where tampering shows and tell users to never trust a sticker overlay. That guidance does a couple of things: it puts you in a better position of control and trustworthiness, and it helps users build up their own antibodies by reading and checking before the scan.&lt;/p&gt;

&lt;p&gt;For the person holding the phone, your immunities will build up over time, but almost all of what you need to do collapses into two habits.&lt;/p&gt;

&lt;p&gt;First, the one rule that defuses the most common con outright, and in India's UPI system it's ironclad: &lt;strong&gt;you never need to enter a PIN or an OTP to &lt;em&gt;receive&lt;/em&gt; money, only to send it.&lt;/strong&gt; Anything that asks you to "scan and approve" to collect a refund is probably taking your money, not giving it.&lt;/p&gt;

&lt;p&gt;Second, know where the QR goes before you act on it. Look at the real URL destination, review the payee and amount. The square shows you none of that by design; a pre-scan step that reads it out &lt;em&gt;before&lt;/em&gt; your phone acts is the point-of-scan antibody the old institutions used to provide for you. Today, institutions don't do that, but there are apps available in both app stores that you can use to pre-scan and safety score QRs. That's the immune system building up, in your hand.&lt;/p&gt;

&lt;h2&gt;
  
  
  The square you cannot read
&lt;/h2&gt;

&lt;p&gt;Step back far enough and the QR code is a single, radical idea: a &lt;strong&gt;trust-compression device.&lt;/strong&gt; It takes everything you'd want to know before parting with money or attention (who is on the other end, where this leads, which direction the value flows) and compresses it into a pattern of squares that no human can decode by looking.&lt;/p&gt;

&lt;p&gt;For most of economic history, that trust lived in &lt;em&gt;institutions you could see&lt;/em&gt;: a bank branch with a name over the door, a card network's logo, a payment terminal a merchant had to be vetted to own. The QR economy strips the institution out of the middle and puts the transaction directly between two phones. That's the source of its magic (a fruit cart becomes a merchant with a fifty-cent sticker) and the source of its danger. Because when you remove the institution, you remove the place the immune system used to live. The defensive layer has to be rebuilt somewhere new: not in a bank's back office, but &lt;strong&gt;at the point of scan, in the individual's hand.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is not an Indian problem. It's the frontier every QR-native economy is walking toward, whether it's noticed yet or not. India just got there first, the way pioneers always reach the frontier first, and meet its hazards first, and end up writing the field guide the rest of the world will read.&lt;/p&gt;

&lt;p&gt;The scams filling my newsfeed aren't evidence that India got it wrong. They're evidence that India got it &lt;em&gt;early&lt;/em&gt;. India succeeded at convenience so completely, and so fast, that it arrived at the place the rest of us are still heading, the place where the technology has spread halfway around the world and security is only now reaching for its shoes.&lt;/p&gt;

&lt;p&gt;It's a postcard from the future. Worth reading closely, because the return address is us.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Sources &amp;amp; further reading:&lt;/em&gt; &lt;a href="https://www.ericsson.com/en/about-us/history/changing-the-world/the-nordics-take-charge/the-launch-of-nmt" rel="noopener noreferrer"&gt;Ericsson — the launch of NMT&lt;/a&gt; · &lt;a href="https://en.wikipedia.org/wiki/Phone_cloning" rel="noopener noreferrer"&gt;Analog cellular "cloning" fraud&lt;/a&gt; · &lt;a href="https://www.analyticsinsight.net/amp/story/cybersecurity/qr-code-scams-how-to-scan-safely-protect-your-data" rel="noopener noreferrer"&gt;CERT-In / India QR-fraud coverage&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>upi</category>
      <category>india</category>
      <category>fintech</category>
      <category>security</category>
    </item>
  </channel>
</rss>
