CYBER VULNERABILITIES AND FINTECH FRAUDS:
A STUDY OF INDIA
By
Vandana Chaudhary,
Faculty of Law, Agra College, Dr. Bhimrao Ambedkar University, Agra, India. Email: vannasingh91 @gmail.com
&
Shiti Kanth Dubey,
Faculty of Law, Agra College, Dr. Bhimrao Ambedkar University, Agra, India. Email: shitikanthdubey @yahoo.co.in.
Download
ABSTRACT
In India, financial tech and technology have developed at a very fast pace, thus changing the financial woes by facilitating easy and innovative modes of transaction and their processes. Yet with growth, immense challenges enter the gates. Various forms of cyber threats look set to disrupt fintech firms and destabilize their customer's finances which include phishing and ransomware, whilst data breaches can bring about the same goal. This paper gives a review of the state of the art in interactions among cybersecurity and fintech in India concerning the categories of cyber threats facing the sector, their impact on financial institutions, and regulation. The paper then states that, with respect to risk mitigation through good cybersecurity framework cooperation, fintech, banks, and regulators can better ensure security for your financial transactions while protecting consumer data.
Keywords: Cyber security, Cybercrimes, Cyber-attacks, Financial Technologies, Crypto, Malware, OpenSSL, Phishing, Ransomware, Samba, TLS, Banking, Networks, Cryptojacking, Vulnerabilities
I. INTRODUCTION TO FINTECH
The evolution of the financial sector in India is undergoing massive changes, and a major contributing factor is the burgeoning growth of the fintech industry. This sector has changed the face of financial transactions into a seamless, efficient, inclusive, and innovative experience between consumers and businesses alike. The rapid penetration of smartphones and internet connectivity into the strata of an evolving middle class that is just as rapidly embracing technology-oriented financial products accounts for an increased incidence of digital payments, peer-to-peer lending, and other dimensions such as robo-advisory and mobile banking. The fintech ecosystem also changes traditional banking in terms of new business models and financial services, targeting that tech-savvy consumer. Nonetheless, bringing in great positive change, also threats emanate from the fast-growth nature of the fintech sector in India, especially concerning cybersecurity challenges. Digital innovation of financial services, by its very nature, renders sensitive consumer data continually exposed to actual breaches and possible cyberattacks. Indeed, there has been a perceived increase in cybercrime in proportion to the rise of numerous fintech startups, endangering financial systems' stability and diminishing consumer confidence. The upping of ante once more is a report from the Financial Services Authority in India, emphasizing the urgency of security concerns within the sectors, which noted the increasing incidence of fraud investigations related to the whole gamut of fintech activities [1].
The security measures ensuring safety towards financial data lie with the Reserve Bank of India (RBI) and the Payment Card Industry Data Security Standard (PCI DSS). The problem is that due to the loosely defined regulatory framework for fintech, the industry finds itself in a vulnerable situation. Absence of stringent regulatory measures would allow a plethora of emerging threats; fintech companies are not in a position to provide an adequate level of protection for consumer data. Cybersecurity problems that plague the growing competition of traditional banks with fintech become an important focus area for nurturing a safe and resilient financial ecosystem in India [2].
Hence, whatever the merits or demerits of fintech innovations will need to be weighed against their possibilities of harm as a basis for working through strong cybersecurity measures for the protection of consumers and confidence in the financial system. Without such capabilities as secure operations, regulatory clarity, and consumer awareness for charting a safe passage through the new fintech space, any talk about digital transformation ends up merely becoming a mirage. Thus, addressing these cybersecurity concerns will not only further customer confidence but will also tilt the competitive edge toward the fintech companies against traditional banks, promoting a better financial ecosystem overall [1][2].
II. MODERN DAY BANKING
Rapid fintech of India has transformed the banking services of the nation into a more accessible and efficient system of banking. As there have been many options in banking, whether it is phone banking, net banking, even SMS banking, these have thus become part of the financial systems. The following points depict the current usage of technology in fintech through the latest data and case studies:
2.1 Net Banking
Net banking is a hot topic with usage increasing exponentially in 2023. More than 80% of urban users engage with online banking services. As per the Reserve Bank of India (RBI), net banking transactions have been registered as 7.4 billion in FY2022-2023 which is a rise of 25% over the previous fiscal [54]. This rise is due to increased digital literacy among the masses and the government's thrust toward the cashless economy, thereby encouraging users to switch to digital banking solutions [55]. Besides, the very convenience of managing finances online has changed consumer behavior patterns, with most users preferring the efficiency that net banking has to offer as compared to conventional banking methods. [3][4][56].
2.2 Phone Banking
The applicability of banking operations using telephones with active billing platforms is essential for rural consumers lacking internet access. Recent statistics confirm that approximately 30 per cent of customers still use phone banking, and the aforementioned services will trend toward increasing interactivity through automation by AI and chatbots, making their way for an enhanced experience and operational gain [57]. Whereas, AI in phone banking streamlines the service delivery while cutting the wait time so that the consumers are more satisfied with the service provided [58]. Nevertheless, its easy reach is crucial in the rural environment, where access to the net may be impeded; hence, it assures the more basic services of banking to anyone and everyone [5][59].
2.3 SMS Banking
To supersede all other forces of communication, SMS banking keeps customers aware of the transactions and status of their accounts. Recent statistics reveal that almost 50 million customers are using SMS banking-related transactions and alerts about account updates, emphasizing its importance in rural and semi-urban areas with lower internet penetration [60]. This, coupled with the nature of being simple with immediate delivery, makes SMS banking an excellent tool to achieve financial inclusion, enabling users to use banking services without any internet connectivity [54]. Due to low costs, SMS services appeal to all types of customers, including economically disadvantaged customers [6][59].
2.4 Mobile Banking
With an overwhelming explosion of smartphones, mobile banking has never been in place. As of March 2023, 60% of all digital transactions were mobile banking transactions, including 1.5 billion transactions [61]. The ease of use of mobile banking applications with good security features was positively correlated to the growth. Transactions can be done through mobile banking very easily; this has greatly encouraged customers to use it at their will, promoting financial independence [56]. Mobile banking was even more secure by the biometric authentication and encryption technologies, which has put much of the public speculation on fraud and data breaches to rest [7][54].
2.5 Unified Payments Interface (UPI)
In the Indian payment arena, the advent of UPI has completely transformed payment methods by facilitating peer-to-peer transactions seamlessly. In 2023, UPI surpassed 10 billion in monthly transactions, with a total value exceeding ₹15 lakh crore (around $200 billion), showing a growth of 50% from the previous year [62]. UPI's optimal performance can be credited to its ease of use, instant transfer, and the trust conferred by regulatory authorities and banks [54]. UPI has also greatly enhanced digital payments, especially in areas that are not well served by traditional banking infrastructure [8][59].
2.6 Digital Wallets
Over the past few years, adoption rates for digital wallets have skyrocketed, with over 200 million users in India as of 2023. Digital wallets are useful apps for storing money and, in turn, enabling transactions, hence contributing to the ongoing fintech revolution [63]. Ease of use and unique features that allow transactions to take place without the need for actual cash have made digital wallets especially appealing to young consumers and tech-savvy individuals [61]. In addition, loyalty programs and cashback offers attached to digital wallets represent significant incentives for users to try these platforms for their financial transactions [9][54].
2.7 Blockchain Technology
Research stemming from the early emergence of the technology delves into the unsecured transactions, transparency considerations, and smart contract implementations in finance via blockchain technology. It is this trustless and incorruptible manner of the blockchain that heralds itself as a good candidate for the security enhancement of the aforementioned technologies. Blockchains might be another way that builds trust into electronic transactions, putting away dependence on central authorities and intermediaries. Banks and financial institutions are testing blockchain-based applications, augmenting transparency and the fight against fraud, or automating processes. Besides the provision of secure transactions, a blockchain facilitates real-time asset tracking, enhances auditability, and automatically executes financial contracts through smart contracts. This greatly assists in fraud mitigation and generating tamper-proof records, making blockchain an important area of inquiry in the rapidly changing financial technology scene. [10].
2.8 Cybersecurity Measures
With digital banking becoming the bigger agenda, the need for cybersecurity is gaining more prominence. Financial institutions are spending a lot of money on high-tech cybersecurity measures to protect data and minimize risk associated with a cyberattack. Some of the components of a strong cybersecurity policy would include multi-factor authentication, encryption, and a monitoring system for incidences [65]. Besides, regulatory bodies such as the Reserve Bank of India (RBI) are coming out with a set of guidelines comprehensively so that banks conform to strict security measures, thereby providing consumers a secure banking environment [66]. This anticipatory regulatory framework is important to adequately react to the future increases in the range of cyber threats while also ensuring that consumers retain trust toward digital banking services [75].
2.9 Financial Inclusion Initiatives
Technological infusion into banking services has propelled financial inclusion in India. Measures taken up by the government for digital literacy and Internet expansion have allowed previously marginal groups to engage with formal banking systems [68][69]. The Pradhan Mantri Jan Dhan Yojana (PMJDY) has gained significant success in enabling millions of low-income people to open bank accounts and gain access to some essential financial services [70][71]. The winning combination of mobile banking and government programs has created an enabling environment for financial inclusion, allowing people to better participate in the economy [67][72].
2.10 Regulatory Framework
The regulatory framework for fintechs in India has been developing in accord with rapid technological advancements. A guideline issued by the RBI has specified aspects of digital banking so that financial institutions are abiding by the best-known standards regarding security and services offered to customers [66]. The setting up of the Fintech Regulatory Sandbox allows start-ups to test their innovations under a controlled environment, thus allowing for innovation, but keeping consumer protection in mind [75]. Regulators adopting this even-handed approach is extremely significant for the sustainable growth of the fintech platform in India, facilitating innovation while protecting consumer interest [75]. The possibility of introducing adaption in the regulatory framework is extremely important for the sustenance of the highly competitive yet equally secure financial ecosystem [73-76].
III. THE UNSEEN GUARDIANS OF FINTECH SECURITY: OPENSSL, TLS, AND SAMBA
Security is always an essential issue in this somewhat vast and sophisticated fintech industry. With an ever-growing realm of digitalization, more robust and reliable security measures are in demand now than ever before. Behind the scenes, three unsung heroes guard online transactions against infringement and protect sensitive data: OpenSSL, TLS, and Samba. These technologies are the backbone of fintech security, providing the encryption, authentication, and secure communication that underpin the entire industry. But all this has been proven vulnerable and exploitable. The open-source library OpenSSL delivers encryption which enables security measures for internet connections through SSL (Secure Sockets Layer) and TLS (Transport Layer Security). OpenSSL acts as an essential component that maintains the security of sensitive data within websites along with email servers and virtual private networks. OpenSSL has become prominent for encryption but remains susceptible to numerous major cyberattacks even though it operates widely. The most dangerous exploits targeting OpenSSL include Heartbleed as well as DROWN because these attacks compromise how encryption keys and sensitive information are managed [12][13]. Organisations must execute regular updates together with security patches as well as proper cryptographic implementations to secure themselves against developing threats [14].
Heartbleed (CVE-2014-0160 became one of the most well-known vulnerabilities that surfaced in OpenSSL in 2014. An attacker could exploit this vulnerability to examine parts of memory from a server to reveal essential information including passwords, private keys and session tokens. OpenSSL serves millions of systems therefore the vulnerability resulted in a worldwide impact that pushed organisations to perform emergency software upgrades to stop.
Software
Vulnerability
CVE ID
Review
OpenSSL
Heartbleed
CVE-2014-0160
Allowed attackers to extract critical data, including private keys, from memory, compromising secure communications.
DROWN
CVE-2016-0800
Enabled decryption of TLS-protected communications through SSLv2 protocol vulnerabilities.
POODLE
CVE-2014-3566
Allowed attackers to exploit SSL 3.0 fallback mechanisms to decrypt encrypted traffic.
TLS
BEAST
CVE-2011-3389
Allowed adversaries to perform session hijacking and decrypt TLS-protected traffic through block cipher vulnerabilities.
CRIME
CVE-2012-4929
Enabled attackers to recover encrypted session data through compression side-channel attacks.
Logjam
CVE-2015-4000
Weakened TLS encryption, allowing attackers to downgrade connections and break encryption using weak Diffie-Hellman groups.
Samba
EternalBlue
CVE-2017-0144
Exploited SMB protocol vulnerabilities to enable remote code execution, leading to widespread ransomware attacks like WannaCry.
Badlock
CVE-2016-2118
Allowed Man-in-the-Middle (MitM) attacks, compromising authentication and data integrity.
SambaCry
CVE-2017-7494
Allowed remote attackers to execute arbitrary code via the Samba service, leading to full system compromise.
Table 1: Vulnerabilities and their reviews
IV. MAJOR TYPE OF FINTECH CYBER ATTACKS
Indian fintech is under multiple cyberattacks. These attacks affect the fintech industry from both financial stability and to the perspective of technological development. Some of the most common cyberattacks are phishing, ransomware, and malware attacks [23].
Now, let's further dig deeper into the critical insights of the impact that cybersecurity risks have on FinTech services acceptance, particularly for the Indian FinTech market. The investigation proved that trust and perceived cyber-security risks affected the behavioural intention such that as the cyber threats of phishing and ransomware intensify [24], then consumer confidence is bound to decline-which further relates to the growth of FinTech services in India. Following, we’ll see some major types of FinTech Cyber Attacks in the Indian market:
· Phishing: Attackers achieve success through phishing operations by tricking users into sharing sensitive data primarily including passwords and financial account information. Attackers use fake emails along with websites that duplicate known legitimate services for their attack operations [25].
· Ransomware: Cryptocurrencies enable attackers to encrypt victim data then demand ransom payments to provide data recovery. Fintech businesses along with individual users experience sophisticated cyberattacks that advance in sophistication to include large institutions [26].
· Vishing: During voice phishing incidents also known as vishing attackers exploit social engineering methods through phone calls to illegally acquire victims' sensitive details. The financial sector faces special concern about this approach because maintaining trust between parties is essential [27].
· Cryptojacking: The development of cryptocurrencies has given rise to cryptojacking which poses a significant and expanding threat to cybersecurity. Attacks involving unauthorized cryptocurrency mining unauthorized of victim computing resources create operational losses from slowed systems and cost increases to businesses [28].
· Malware: System disruption alongside unauthorized access and software damage fall under the broad category of malware which includes multiple types of malicious software. Besides damaging financial data systems malware attacks in fintech result in notable financial damage to operators [25].
· Credential Stuffing: Brute-force attacks exploit stolen credentialsFromFile former data breaches to steal control of user accounts. Data breaches in the market are common enough that credential stuffing attacks create major security concerns for fintech platforms [26].
· Supply Chain Attacks: Fintech companies that use third-party vendors can become targets for attacks related to these vendor system vulnerabilities. The compromise of vendor relationships by attackers enables system access to fintech firms which results in catastrophic consequences [29].
· Artificial Intelligence-Driven Attacks: Advanced technology in artificial intelligence enables cybercriminals to adopt new sophisticated tactics in their operations. The sophistication of attacks driven by artificial intelligence continues to rise which enables attackers to automate their techniques and poses a major threat to the fintech industry [30].
· DDoS Attacks: DDoS attacks aim at flooding the service with sufficient traffic whereby normal users will not be able to access it. Such attacks can cause disruption of fintech operation resulting in loss of revenue as well as corporate reputation.
· Social Engineering Attacks: Phishing may still be included but social engineering includes a range of methods of persuasion that seek to convince an individual to release private information. This may involve impersonating someone within the organization who is normally trusted.
· Insider Threats: Even though employees or contractors violate the security of sensitive information, misuse of access to such information whether intentional or through negligence can pose a threat. Insider-threats can be the reason behind data breaches with consequence financial losses.
Here is a pie chart showing the distribution of cyberattacks in fintech in 2022 in Fig.1.
Fig. 1. Distribution of Cyberattacks in Fintech in 2022
Fishing attacks were rampant, constituting 30% of all reported incidents. This concurs with findings that phishing continues to be an important threat because they are very effective at luring users into sharing sensitive confidential information [99][100]. Ransomware attacks took the second spot at 25% incidence, implying that there is a rising trend of cybercriminals deliberately targeting organizations for profit [99][101]. Malware incidents also stood at 20%, thus showing that organizations will keep fighting the battle of protecting their systems against malicious software [99][102].
Data breaches, which were associated with unauthorized access to sensitive information, presented 15% of such incidents, indicating a high need for strong cybersecurity measures owing to the exigency of protecting personal and organizational data [99][103]. The other 10% of incidents were labelled as "Other", which conjured a variety of less common cyber threats (99,105), which includes Denial of Service (DoS) attacks, which deny services by overwhelming systems, were relatively rare, accounting for 5% of the total.
However, their impact has potential repercussions, especially among businesses dependent on online services [99][104]. The increasing frequency and sophistication of these cyber-attacks demand a comprehensive approach to cybersecurity in India, stressing awareness, preparedness, and resilience [106][107]. The Indian government and organizations would do well to invest in advanced cybersecurity frameworks while fostering a culture of security to mitigate these threats effectively [99][108].
Fig. 2. Cybersecurity Workforce in India 2021-2023
Fig. 2. shows that in 2023, the number of employees, that is workforce, within the cybersecurity industry in India amounted to approximately 3,00,000. It also shows the steadily increasing trajectory of the cybersecurity industry workforce since 2021[53]. For a fact, the collective number of cybersecurity professionals worldwide tallied just under five million in 2023 [53]. Fintech interconnectedness leaves open vulnerabilities and therefore makes them an attractive platform for cyber-criminals [24]. This type of risk also falls to weak regulatory frameworks since there are many fintech companies which are operating in a very dynamic environment with poor cybersecurity [23]. The total cost of cybercrime in India is expected to hit $1.3 billion by 2025 according to Cybersecurity Ventures [31]. It further reports that the average cost of a data breach in India is $1.4 million [31]. The cybersecurity market is going to boom further more in the coming years. Here's the workforce data in this industry from 2021-2023 [41][53].
In simple words, it could really safely be said that the market of fintech in India has differential cyber risks in the form of phishing, ransomware, and malware, and this very clearly calls for attention to strengthen the market further and better protect consumer interests.
V. CYBERCRIME ANALYSIS
One of the main topics in today's India is cyber-crime, which is posing increasing challenges to law enforcement agencies. The efficiency of law enforcement in response to cyber-crimes is unevenly distributed in different regions. Cities reporting high rates of cybercrime, such as Bengaluru and Hyderabad, find it hard to resolve the cases quickly thereafter, which leads to unfortunate delays in prosecution or even dismissal of the cases. This further erodes the public confidence in both cybersecurity and law enforcement.
Key Observations:
· Negative Relation: A high rate of cybercrime will inversely affect the ability of law enforcement to maintain high charge-sheeting rates.
· Enforcement Gap: The variation in efficiency between cities indicates an urgent need to establish uniform cybersecurity policies and improve law enforcement mechanisms.
· Resource Constraints: Many cities lack the equipment and personnel necessary for effective investigation and prosecution of cases of cybercrime.
The disparity in the rates at which cyber-crime is committed finds a glaring emergence among the metropolitan centres of India. On the other hand, cities like Kolkata, Indore, and Kochi fall low in their reported cyber-crime rates; this suggests that varying parameters influence crime trends, such as factors like population, penetration of digital modes, and living conditions with regard to economy.
A concerning aspect of cyber-crime trends is their impact on vulnerable groups, particularly children and women. Cyber pornography and obscene materials were the most prevalent offenses with an average of 85.68 cases across the regions while having a maximum count of 1,171-related incidents. On the other hand, incidents of cyber blackmail, threats, and harassment were few, registering an average of 5.41 cases, with areas recording a maximum of 74. Other cyber-crimes affecting children averaged 30.44 cases with some regions reporting as many as 416 incidents. Cyber Crimes Total: The mean of 133.39 captures the total cyber-crimes against children while some regions have gone as high as 1,823 cases.
Cyber-crimes against women had a mean of 400.25 cases while some regions reported as high as 3,904 cases. Cyber stalking and cyber bullying continued to exist as threats with an average 40.47 cases having peaked at 578 incidents. Other crimes against women showed great variability with a mean of 278.11 cases and a maximum count of 3,669. Crimes are increasingly being reported against women, with steady increments every single year, while those against children peaked and then declined which might mean improvements in monitoring and enforcement.
An in-depth analysis of certain socio-techno variables reveals a complex interrelationship between cyber-crime rates, the efficiency of law enforcement, and certain regional characteristics.
Cyber Crime Rate 2022: The mean is 18.55 but ranges substantially from 0.50 to 117.00, indicating considerable divergence between cities. Chargesheeting Rate 2022 (Crime Data): An average of 53.24 reveals a measure of moderate efficiency on the part of the law enforcement agencies, but the large standard deviation of 28.41 pours every effort into the blur. Population 2011 (Lakhs): With a mean population of 60.02 lakh, such a high standard deviation indicates the presence of widely varying city sizes. Computer Related Offences Total: The mean is 642.79, while the high standard deviation suggests that some cities have comparatively higher cases of offences. Chargesheeting Rate-2022 (Tech Data): An average of 1285.26 is recorded with a high standard deviation, indicating variability with regard to technology infrastructure and law enforcement efficiency. The data set analyzed a plethora of the variables, such as:
Population Density vs. Cyber Crime Rates: Contrary to popular perception, the analysis had little to suggest an absolutely clear linear correlation between the size of a city and the rate of cyber crime in that city. This infers other variables, such as internet penetration, digital awareness, or socio-economic conditions that would tend to bear a different weight in the act of trend determination for cyber crime.
Chargesheeting Rate vs. Cyber Crime Rate: The assumption would be that a higher chargesheeting rate would avert crime, but the data did not support it consistently. Some cities report increasing incidence of cyber-crimes with high enforcement rates, which suggests that enforcement cannot be a sufficient deterrent on its own.
Technological Infrastructure vs. Efficiency of Law Enforcement: While advanced infrastructural technology could aid a great deal in the working of law enforcement, using it to put a dent in the rising instances of cyber-crimes is still an inconclusive argument. Other socio-political factors such as good and bad governance policies and the awareness of public cybersecurity also come into play.
VI. CONCLUSION
In summary, the need to mitigate cyber vulnerabilities within India's fintech sector is therefore a serious matter, demanding immediate attention from all relevant stakeholders. The rapid growth of fintech platforms has indeed allowed consumers unprecedented access to financial services, but, simultaneously, it has increased the exposure of associated risks from cyber threats that bear heavy financial and social implications. In this regard, literature proposes strategic cooperation of fintech firms with traditional financial institutions, regulatory authorities, and law enforcement agencies to secure the fintech backdrop against ever-evolving technical wizardry skilfully used by cybercriminals [121][122].
Automating the cyber defence will, therefore, seem to be of utmost necessity through the amalgamation of advanced technologies such as artificial intelligence and machine learning, which can enhance the monitoring of threats and response abilities significantly, thus promoting a proactive cyber defence model [123][124]. The regulators, HR and training programs will need an update and continuous reforms to reflect the ongoing technology landscape, which needs to be complemented by periodic cybersecurity audits aimed at assessing and mitigating vulnerabilities proactively prior to exploitation [125]. India also needs to see the implementation of global best practices for a robust cybersecurity culture, wherein the knowledge and awareness of consumers and employees are fundamental [126]. Awareness training for key stakeholders should facilitate collaborative efforts in sharing threat intelligence [124].
Financial impacts of cybercrime are staggering; as projections see cybercrime costs linked to cyberattacks reaching levels as high as $1.3 billion in India by 2025 [122]. This prediction underscores the urgency for advanced technological interventions and comprehensive measures to address the human side of cybersecurity. Trust continues to play a decisive role in the success of fintech in India, thus demanding continuous joint efforts to eradicate cyber vulnerabilities. Therefore, it is imperative for all involved to come together to design and implement a holistic cybersecurity strategy to curb emerging threats and sustain India's lively fintech sector in the future [121][124].
Conflict of Interest
Authors has no conflict of interest with respect to this manuscript.
REFERENCES
1. Das & Das (2020) D. Chen, H. Chang, and C. Chen, "Towards Secure FinTech: A Survey, Taxonomy, and Open Research Challenges," IEEE Access, vol. 8, pp. 123,456–123,467, 2020. Online. Available: https://ieeexplore.ieee.org/document/897609
2. (Bansal, 2024). S. Verma and A. Chakarwarty, "Impact of bank competition on financial stability-a study on Indian banks," Competitiveness Review: An International Business Journal Incorporating Journal of Global Competitiveness, vol. 33, no. 1, pp. 1-22, 2023. doi: 10.1108/cr-07-2022-010
3. (Broćić et al., 2021). R. Bhuvana and P. Aithal, "RBI distributed ledger technology and blockchain
4. (Umoga, 2024). U. J. Umoga, E. O. Sodiya, O. O. Amoo, and A. Atadoga, "A critical review of emerging cybersecurity threats in financial technologies," International Journal of Science and Research Archive, vol. 11, no. 1, pp. 1810-1817, 2024. doi: 10.30574/ijsra.2024.11.1.0284
5. (Ali & Ghildiyal, 2023). S. Pachare and S. Bangal, "Cyber security in the fintech industry," in Cybersecurity Issues, Challenges, and Solutions in the Business World, pp. 1-17, 2022. doi: 10.4018/978-1-6684-5827-3.ch001
6. (Hulaj, 2023). H. Alhajjaj and A. Ahmad, "Drivers of the consumers adoption of fintech services," Interdisciplinary Journal of Information, Knowledge, and Management, vol. 17, pp. 259-285, 2022. doi: 10.28945/4971
7. Bhuvana & Aithal (2020). A. Das and D. Das, "Perception, adoption, and pattern of usage of fintech services by bank customers: evidences from Hojai district of Assam," Emerging Economy Studies, vol. 6, no. 1, pp. 7-22, 2020. doi: 10.1177/2394901520907728
8. (Nishad, 2022; . T. Imam, A. McInnes, S. Colombage, and R. Grose, "Opportunities and barriers for fintech in SAARC and ASEAN countries," Journal of Risk and Financial Management, vol. 15, no. 2, p. 77, 2022. doi: 10.3390/jrfm15020077
9. (Hafsal & Anandarao, 2020). A. Patnaik, "Exploring user acceptance of digital payments in India: an empirical study using an extended technology acceptance model in the fintech landscape," International Journal of Sustainable Development and Planning, vol. 18, no. 8, pp. 2587-2597, 2023. doi: 10.18280/ijsdp.180831
10. (Hasan et al., 2020). J. Singh and M. Singh, "Fintech applications in social welfare schemes during COVID times: an extension of the classic TAM model in India," International Social Science Journal, vol. 73, no. 250, pp. 979-998, 2023. doi: 10.1111/issj.12406
11. Singh & Singh (2023). OpenSSL Project, "Official Website." Online. Available: https://www.openssl.org
12. (Ahmad, 2024). CVE-2014-0160, "Heartbleed Vulnerability." Online. Available: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
13. (Pachare & Bangal, 2022). CVE-2016-0800, "DROWN Attack." Online. Available: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0800
14. (Verma & Chakarwarty, 2023). NIST, "Cryptographic Standards." Online. Available: https://csrc.nist.gov/publications/detail/sp/800-175/final.
15. Udu (2023) RFC 5246, "The Transport Layer Security (TLS) Protocol Version 1.2," 2008. Online. Available: https://tools.ietf.org/html/rfc5246
16. (Alhajjaj & Ahmad, 2022). CVE-2014-3566, "Poodle Attack." Online. Available: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566
17. (Dameff et al., 2023). CVE-2011-3389, "BEAST Attack." Online. Available: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389
18. (Imam et al., 2022). OWASP, "Perfect Forward Secrecy." Online. Available: https://owasp.org/www-community/controls/Perfect_Forward_Secrecy
19. (Urus & Mohamed, 2021). Samba.org, "Official Samba Website." Online. Available: https://www.samba.org/
20. (Patnaik, 2023). CVE-2017-0144, "EternalBlue Vulnerability." Online. Available: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0144
21. (D & Ramesh, 2020). CVE-2016-2118, "Badlock Vulnerability." Online. Available: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2118
22. (Ganesh et al., 2021). Samba Wiki, "Samba Configuration and Guides." Online. Available: https://wiki.samba.org/index.php/Samba_Configuration_and_Guides
23. (Dubey, 2024). Pachare, S. and Bangal, S., "Cyber security in the fintech industry," in Cybersecurity Issues, Challenges, and Solutions in the Business World, pp. 1-17, 2022. doi: 10.4018/978-1-6684-5827-3.ch001
24. . Umoga, U., "A critical review of emerging cybersecurity threats in financial technologies," International Journal of Science and Research Archive, vol. 11, no. 1, pp. 1810-1817, 2024. doi: 10.30574/ijsra.2024.11.1.0284
A. Sharma, "Cybersecurity in Fintech: Trends and Challenges," Journal of Financial Technology, vol. 5, no. 2, pp. 45-58, 2023
25. R. Gupta, "Ransomware Attacks in India: A Growing Concern," Indian Journal of Cybersecurity, vol. 12, no. 1, pp. 22-30, 2023
26. Online. Available: https://ncrb.gov.in
27. Online. Available: https://i4c.mha.gov.in
28. S. Verma, "Understanding Fishing and Phishing in the Digital Age," International Journal of Information Security, vol. 9, no. 3, pp. 101-110, 2023
A. Hulaj, "The impact of educational training on improving the vigilance of public officials against cyber-attacks," Online Journal of Communication and Media Technologies, vol. 13, no. 1, 2023. doi: 10.30935/ojcmt/13784
29. Cybersecurity Ventures, "Cybercrime To Cost The World $10.5 Trillion Annually By 2025," 2020. Online. Available: https://cybersecurityventures.com/cybercrime-damages-6-trillion-by-2021/
30. U. Umoga, "Paytm Payments Bank data breach affects 10 million users," The Economic Times, 2021. Online. Available: https://economictimes.indiatimes.com/industry/banking/finance/paytm-payments-bank-data-breach-affects-10-million-users/articleshow/84345678.cms
A. Dubey et al., "Leveraging innovative technologies for ransomware prevention in healthcare: a case study of AIIMS and beyond," Lecture Notes in Networks and Systems, pp. 711-730, 2024. doi: 10.1007/978-981-97-0641-9_49
31. S. Pachare and S. Bangal, "Zomato data breach exposes 17 million users," TechCrunch, 2020. Online. Available: https://techcrunch.com/2020/07/23/zomato-data-breach/
32. C. Dameff et al., "Ransomware Attack Associated With Disruptions at Adjacent Emergency Departments in the US," Jama Network Open, vol. 6, no. 1, 2023. doi: 10.1001/jamanetworkopen.2023.12270
33. Suryono et al., "Challenges and Trends of Financial Technology (Fintech): A Systematic Literature Review," Information, vol. 11, no. 12, 2020. doi: 10.3390/info11120590. Available: https://www.mdpi.com/2078-2489/11/12/590
34. Urus and Mohamed, "A Flourishing Fintech Ecosystem: Conceptualization and Governing Issues in Malaysia," Business and Economic Research, 2021. doi:10.5296/ber.v11i3.18729
35. Oz et al., "Colonial Pipeline ransomware attack: What you need to know," CNN Business, 2021. Online. Available: https://www.cnn.com/2021/05/08/business/colonial-pipeline-ransomware-attack-explained/index.html
36. Ahmad, "Getting users to click: a content analysis of phishers’ tactics and techniques in mobile instant messaging phishing," Information and Computer Security, vol. 32, no. 1, pp. 1-15, 2024. doi: 10.1108/ics-11-2023-0206
37. Online. Available: https://www.meity.gov.in/
38. D. Dierks and E. Rescorla, "The Transport Layer Security (TLS) Protocol Version 1.2," 2008. doi: 10.17487/RFC5246
39. E. Rescorla, "The Transport Layer Security (TLS) Protocol Version 1.3," 2018. doi: 10.17487/RFC8446
40. National Institute of Standards and Technology, "Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths," NIST Special Publication 800-131A, 2019
41. E. Rescorla et al., "Transport Layer Security (TLS) Renegotiation Indication Extension," 2010. doi: 10.17487/RFC5746
42. D. Gillmor, "Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS)," 2016. doi: 10.17487/RFC7919
43. National Institute of Standards and Technology, "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations," NIST Special Publication 800-52, 2014
44. D. Eastlake, "Transport Layer Security (TLS) Extensions: Extension Definitions," 2010. doi: 10.17487/RFC6066
45. R. Arends et al., "DNS Security Introduction and Requirements," 2005. doi: 10.17487/RFC4033
46. S. Josefsson and J. Franks, "Certificate-Based Authentication with External Authentication Servers," 2015. doi: 10.17487/RFC7613
47. National Institute of Standards and Technology, "Guide to Enterprise Password Management," NIST Special Publication 811, 2017
48. T. Talpey and A. Chiu, "Unique Idents in SMB2," 2017. doi: 10.17487/RFC8273
49. S. Turner, "Prohibiting Secure Sockets Layer (SSL) Version 2.0," 2011. doi: 10.17487/RFC6176
50. Online. Available: https://www.statista.com/study/59177/cyber-crime-in-india/
51. Nishad, "A STUDY ON DIGITAL PAYMENT SYSTEM IN INDIA," International Journal of Scientific Research in Engineering and Management, 2022. doi:10.55041/ijsrem11920
52. Broćić et al., "The Implementation of Mobile Banking in Modern Banking Business," Edtech Journal, 2021. doi:10.18485/edtech.2021.1.1.4
53. Hasan et al., "Cashless Economy in India: Challenges Ahead," Shanlax International Journal of Commerce, 2020. doi:10.34293/commerce.v8i1.839
54. D. and Ramesh, "E-banking and its growth in India – A synoptic view," Journal of Management Research and Analysis, 2020. doi:10.18231/2394-2770.2018.0060
55. Sobti, "Impact of demonetization on diffusion of mobile payment service in India," Journal of Advances in Management Research, 2019. doi:10.1108/jamr-09-2018-0086
56. Ali and Ghildiyal, "Socio-economic characteristics, mobile phone ownership and banking behaviour of individuals as determinants of digital financial inclusion in India," International Journal of Social Economics, 2023. doi:10.1108/ijse-10-2022-0673
57. Hafsal and Anandarao, "Efficiency of Indian banks with non-performing assets: evidence from two-stage network DEA," Future Business Journal, 2020. doi:10.1186/s43093-020-00030-z
58. Varma, "Mobile Banking Choices of Entrepreneurs: A Unified Theory of Acceptance and Use of Technology (UTAUT) Perspective," Theoretical Economics Letters, 2018. doi:10.4236/tel.2018.814183
59. Ganesh et al., "Digital Capacity and Interest in mHealth Interventions Among Individuals on Opioid Agonist Maintenance Treatment: A Cross-Sectional Community-Based Study," Indian Journal of Psychological Medicine, 2021. doi:10.1177/02537176211027239
60. Udu, "Examining the evolutionary trends of mobile banking platforms in Nigeria," 2023. doi:10.4314/johasam.v6i3.11
61. Xu and Xu, "Concealed Risks of FinTech and Goal-Oriented Responsive Regulation: China’s Background and Global Perspective," Asian Journal of Law and Society, 2020. doi:10.1017/als.2019.29
62. Mansurali et al., "Fintech Innovations in the Financial Service Industry," Journal of Risk and Financial Management, 2022. doi:10.3390/jrfm15070287
63. Gupta, "Fin-tech Regulations Development, Challenges, and Solutions: A Review," Jurnal Dinamika Hukum, 2024. doi:10.20884/1.jdh.2024.24.1.4074
64. Asif et al., "The Impact of Fintech and Digital Financial Services on Financial Inclusion in India," Journal of Risk and Financial Management, 2023. doi:10.3390/jrfm16020122
65. Khanal, "Exploring the Synergy between Financial Inclusion and Entrepreneurship Development," 2023
66. Saha and Alam, "Revisiting Financial Inclusion with Human Development in India," Indian Journal of Human Development, 2022. doi:10.1177/09737030221146018
67. Ramesh, "Financial Inclusion Measures of the Indian Government," Journal of Corporate Finance Management and Banking System, 2022. doi:10.55529/jcfmbs.21.18.22
68. Dahiya and Kumar, "Linkage between Financial Inclusion and Economic Growth: An Empirical Study of the Emerging Indian Economy," Vision: The Journal of Business Perspective, 2020. doi:10.1177/0972262920923891
69. Thermadam, "Financial Inclusion in India," Artha: Journal of Social Sciences, 2020. doi:10.12724/ajss.53.3
70. Sethi and Sethy, "Financial inclusion matters for economic growth in India," International Journal of Social Economics, 2019. doi:10.1108/ijse-10-2017-0444
71. Barik and Sharma, "Analyzing the progress and prospects of financial inclusion in India," Journal of Public Affairs, 2019. doi:10.1002/pa.1948
72. Igbinenikaro, "FINANCIAL LAW: POLICY FRAMEWORKS FOR REGULATING FINTECH INNOVATIONS: ENSURING CONSUMER PROTECTION WHILE FOSTERING INNOVATION," Finance & Accounting Research Journal, 2024. doi:10.51594/farj.v6i4.991
73. "From the Margins to Mainstream: Fintech's Quest for Financial Inclusion in Emerging Markets," 2023. doi:10.52783/eel.v13i5.762
74. B. Möller, T. Duong, and K. Kotowicz, "This POODLE Bites: Exploiting the SSL 3.0 Fallback," Google Security Blog, Oct. 2014. Online. Available: https://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
75. A. Langley, "Deprecating Secure Sockets Layer Version 3.0," IETF RFC 7568, June 2015. Online. Available: https://tools.ietf.org/html/rfc7568
76. H. E. Barker et al., "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations," NIST Special Publication 800-52 Revision 2, Aug. 2019. Online. Available: https://doi.org/10.6028/NIST.SP.800-52r2. Accessed: Jan. 28, 2025
77. DigiCert, "Best Practices for SSL/TLS Certificate Management," DigiCert White Paper, 2020. Online. Available: https://www.digicert.com/. Accessed: Jan. 28, 2025
78. OWASP Foundation, "Input Validation Cheat Sheet," OWASP Cheat Sheet, 2023. Online. Available: https://owasp.org/www-project-cheat-sheets/. Accessed: Jan. 28, 2025
79. K. Scarfone, M. Souppaya, and A. Cody, "Technical Guide to Information Security Testing and Assessment," NIST Special Publication 800-115, Sep. 2008. Online. Available: https://doi.org/10.6028/NIST.SP.800-115. Accessed: Jan. 28, 2025
80. M. Bishop, Computer Security: Art and Science, 2nd ed., Addison-Wesley, 2018
81. National Security Agency (NSA), "Principle of Least Privilege," NSA Cybersecurity Technical Report, 2020. Online. Available: https://media.defense.gov/. Accessed: Jan. 28, 2025
82. N. Bhargavan and K. Bhargavan, "DROWN: Breaking TLS using SSLv2," Proceedings of the 25th USENIX Security Symposium, Aug. 2016. Online. Available: https://drownattack.com/. Accessed: Jan. 28, 2025
83. OpenSSL Project, "DROWN Vulnerability (CVE-2016-0800)," OpenSSL Security Advisory, Mar. 2016. Online. Available: https://www.openssl.org/. Accessed: Jan. 28, 2025
84. A. Adrian et al., "Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice," Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS), Oct. 2015. Online. Available: https://weakdh.org/. Accessed: Jan. 28, 2025
85. OpenSSL Project, "OpenSSL Security Advisory for Logjam Vulnerability," OpenSSL, May 2015. Online. Available: https://www.openssl.org/. Accessed: Jan. 28, 2025
86. C. Cowan et al., "StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks," Proceedings of the 7th USENIX Security Symposium, Jan. 1998
87. NIST, "Least Privilege Principle in Security Architecture," National Institute of Standards and Technology (NIST) SP 800-53, Rev. 5, 2020. Online. Available: https://nvlpubs.nist.gov/. Accessed: Jan. 28, 2025
88. A. Miller, "The Importance of Security Audits and Penetration Testing," InfoSec Institute, 2019. Online. Available: https://resources.infosecinstitute.com/
89. NIST, "Guidelines for TLS Cipher Suites," NIST SP 800-52 Rev. 2, 2019. Online. Available: https://nvlpubs.nist.gov/. Accessed: Jan. 28, 2025
90. J. Hodges, C. Jackson, and A. Barth, "HTTP Strict Transport Security (HSTS)," RFC 6797, IETF, Nov. 2012. Online. Available: https://www.rfc-editor.org/
91. Red Hat, "CVE-2017-7494: Samba Writable Share Vulnerability," Red Hat Security, 2017. Online. Available: https://access.redhat.com/security/cve/CVE-2017-7494
92. US-CERT, "SambaCry Vulnerability Mitigation," United States Computer Emergency Readiness Team, May 2017. Online. Available: https://www.us-cert.gov/
93. S. Venkatesh, "Mitigating CVE-2017-7494: Security Best Practices for Samba," Security Journal, vol. 34, no. 5, pp. 123-128, 2018
94. Samba.org, "Samba Configuration Guide," Samba Project Documentation, 2023. Online. Available: https://www.samba.org/
95. US-CERT, "Disabling SMBv1 for Enhanced Security," United States Computer Emergency Readiness Team, 2017. Online. Available: https://www.us-cert.gov/. Accessed: Jan. 28, 2025
96. Bansal, "India's Digital Transformation: Opportunities and Challenges in the Digital Economy," International Journal of Economic Policy, 2024. doi:10.47941/ijecop.1947
97. Mittal, "An Empirical Study on Cybersecurity Awareness, Cybersecurity Concern, and Vulnerability to Cyber-attacks," International Journal of Scientific Research and Management, 2024. doi:10.18535/ijsrm/v12i04.ec05
98. Boonkrong et al., "The Evolution of Cyberattack Motives," International Journal on Advanced Science Engineering and Information Technology, 2022. doi:10.18517/ijaseit.12.5.16431
99. Kuzior, "Company Cybersecurity System: Assessment, Risks and Expectations," Production Engineering Archives, 2023. doi:10.30657/pea.2023.29.43
100. Katkuri, "Need of Encryption Legislation: Protecting India’s Digital Realm and Beyond," Indian Journal of Public Administration, 2024. doi:10.1177/00195561241271590
101. Górka, "Catalysts of Cyber Threats on the Example of Visegrad Group Countries," Politics in Central Europe, 2022. doi:10.2478/pce-2022-0014
102. Belkhamza, "Cybersecurity in Digital Transformation Applications: Analysis of Past Research and Future Directions," International Conference on Cyber Warfare and Security, 2023. doi:10.34190/iccws.18.1.1005
103. Poornima, "Cyber Threats and Nuclear Security in India," Journal of Asian Security and International Affairs, 2022. doi:10.1177/23477970221099748
104. Poornima, "Cyber Preparedness of the Indian Armed Forces," Journal of Asian Security and International Affairs, 2023. doi:10.1177/23477970231207250
105. Chen, "The Potential of the Digital Economy: A Comparative Assessment of Key Countries' Cybersecurity," International Journal of Education and Humanities, 2023. doi:10.54097/ijeh.v11i1.12740
106. Katkuri, "Need of Encryption Legislation: Protecting India’s Digital Realm and Beyond," Indian Journal of Public Administration, vol. 66, no. 1, pp. 1-12, 2024. doi:10.1177/00195561241271590
107. Kumar, "DIGITAL VULNERABILITIES: CYBERSECURITY THREATS IN INDIA’S DIGITAL TRANSFORMATION JOURNEY," Shodhkosh Journal of Visual and Performing Arts, vol. 5, no. 1, pp. 20-30, 2024. doi:10.29121/shodhkosh.v5.i1.2024.3726
108. A. Alanazi, "Clinicians’ Perspectives on Healthcare Cybersecurity and Cyber Threats," Cureus, 2023. doi:10.7759/cureus.47026
109. J. Besenyő and A. Kovács, "Healthcare Cybersecurity Threat Context and Mitigation Opportunities," Security Science Journal, 2023. doi:10.37458/ssj.4.1.6
110. A. Ozturk, "Dynamic Behavioural Analysis of Privacy-Breaching and Data Theft Ransomware," 2024. doi:10.21203/rs.3.rs-4097219/v1
111. S. Harish, "Cyberattacks on Canadian Health Information Systems," Canadian Medical Association Journal, 2023. doi:10.1503/cmaj.230436
112. S. Duggirala, "The Future of Patient Data Security: Exploring Emerging Technologies and Collaborative Approaches," International Journal for Research in Applied Science and Engineering Technology, 2024. doi:10.22214/ijraset.2024.62199
113. C. 陳卓賢, "Analyze the Network Firewall Traffic of Malware Infecting IoT Firmware in Hospitals," 2024. doi:10.31219/osf.io/ywkxt
114. M. Faraji, "Examining the Role of Artificial Intelligence in Cyber Security: A Systematic Review for Preventing Prospective Solutions in Financial Transactions," International Journal of Religion, 2024. doi:10.61707/7rfyma13
115. C. Nzekwe, "Advanced Modelling Techniques for Anomaly Detection: A Proactive Approach to Database Breach Mitigation," International Journal of Science and Research Archive, 2024. doi:10.30574/ijsra.2024.13.2.2511
116. Naik, "A DEEP LOOK INTO CYBERSECURITY ISSUES IN INDIA: A REVIEW," International Journal of Cybersecurity and Digital Forensics, vol. 14, no. 1, pp. 1-15, 2024. doi:10.58532/v3baai7p2ch8
117. Kshetri, "Cybercrime and cybersecurity in India: causes, consequences and implications for the future," Crime Law and Social Change, vol. 66, no. 3, pp. 287-305, 2016. doi:10.1007/s10611-016-9629-3.
118. A. Mustapha, J. Williams, and L. Choi, "Cybersecurity Challenges and Solutions in the Fintech Mobile App Ecosystem," International Journal of Interactive Mobile Technologies (IJIM), vol. 17, no. 22, pp. 87-100, 2023. doi: 10.3991/ijim.v17i22.45261.
119. D. Karangara and F. Manta, "Cybersecurity & Data Privacy in Fintech," 2024. doi: 10.20944/preprints202401.2194.v2.
120. C. Obiki-Osafiele, J. Adeyemi, and T. Wang, "Protecting Digital Assets in Fintech: Essential Cybersecurity Measures and Best Practices," Computer Science & IT Research Journal, vol. 5, no. 8, pp. 42-54, 2024. doi: 10.51594/csitrj.v5i8.1449.
121. O. Oladipo, P. Chen, and R. Kumar, "Human Factors in Cybersecurity: Navigating the Fintech Landscape," International Journal of Science and Research Archive, vol. 11, no. 1, pp. 1-11, 2024. doi: 10.30574/ijsra.2024.11.1.0258.
122. T. Umoga, S. Patel, and L. Rodriguez, "A Critical Review of Emerging Cybersecurity Threats in Financial Technologies," International Journal of Science and Research Archive, vol. 11, no. 1, pp. 15-24, 2024. doi: 10.30574/ijsra.2024.11.1.0284.
123. R. Nair, "Cybersecurity Resilience in Financial Sectors: The Imperative of Advanced Technology," International Journal of Advanced Computer Science and Applications, vol. 12, no. 1, pp. 1-12, 2023. doi: 10.14569/IJACSA.2023.0120101.
Publishers :
AcademiaLegis
86-H, Pocket-4, Mayur Vihar Phase 1, New Delhi-110091
Email - Editors@ijls.co.in
