India's national computer emergency response team issued a compliance note this week requiring licensed payment aggregators and large merchant acquirers to report "significant" cybersecurity incidents within six hours and submit a fuller breach summary within seventy-two hours, with explicit examples covering credential leaks on merchant dashboards, settlement-file tampering, and API key exposure ahead of the Navratri–Diwali transaction peak. CERT-In circulated the guidance in a closed briefing with NPCI and RBI observers reviewed by InfoHandle; it does not create new criminal penalties on its own but ties late filings to existing directions that can trigger suspension reviews for entities handling festival-season UPI volume.
What broke in prior festival cycles
Security teams at two unnamed aggregators told InfoHandle that last year's post-Diwali weeks produced a cluster of merchant-portal takeovers where attackers reused passwords from unrelated breaches—classic credential stuffing—not compromises of NPCI's core switch. Settlement delays hit kirana merchants who discovered mismatched payout ledgers only after bank holidays. RBI's ombudsman dashboards later showed spikes in complaints about "money stuck in aggregator pool accounts," a pattern regulators now treat as a signal that incident clocks were missed while fraud teams chased chargebacks.
What is confirmed: CERT-In's note names payment aggregators regulated under RBI's March 2020 framework and any entity processing more than five million merchant transactions monthly. What is not: no public docket yet lists which firms filed late in 2025; those numbers sit with RBI's Department of Payment and Settlement Systems.
What must be reported, and when
The six-hour window covers discovery of unauthorized access to systems that can alter settlement instructions, exfiltrate PAN or token vaults, or push malicious firmware to point-of-sale middleware. Aggregators must notify CERT-In, RBI's cyber cell liaison, and affected acquirer banks in parallel—not sequentially through public relations. The seventy-two-hour report must include root-cause hypotheses, counts of merchants and cardholders exposed, and whether NPCI's dispute rails were used to claw back funds.
Smaller sub-aggregators routing through tier-one licenses were told they cannot hide behind parent filings; the license holder remains accountable if a downstream API partner loses keys. MeitY staff at the briefing emphasized that the direction implements portions of the 2022 CERT-In cyber directions already contested in court, but payment-sector timing was carved out after industry petitions.
Who is liable in India
RBI retains licensing leverage: repeated late CERT-In filings can factor into fit-and-proper assessments for directors. Merchant contracts typically push first-line reimbursement to aggregators when portal fraud stems from weak multi-factor authentication, but consumer courts have split on whether banks must still credit UPI victims within the NPCI zero-liability window when the aggregator missed disclosure clocks. Insurance underwriters attending an industry webinar last month said cyber policies increasingly exclude "known control failures" documented in prior RBI examination letters.
State police cyber cells get copied on severe incidents, yet attribution to domestic SIM-box rings versus offshore botnets rarely reaches public charge sheets before festival season ends. Aditya Banerjee's desk treats unnamed APT claims skeptically unless the National Critical Information Infrastructure Protection Centre signs a bulletin.
Technical limits
Six-hour reporting assumes mature security operations centers that many mid-tier aggregators staff only during Mumbai market hours. API-only merchants may not learn of dashboard takeovers until Monday morning reconciliations, blowing the clock. CERT-In acknowledged that encrypted logs on third-party cloud regions complicate evidence preservation and asked firms to pre-register forensic contacts with NPCI's fraud management unit.
The direction does not mandate full payment-system shutdown during investigations—a relief for retailers—but it does require temporary blocks on compromised merchant IDs when settlement integrity is uncertain.
What firms should do before October
Compliance officers are rehearsing tabletop exercises that include NPCI's dispute helpdesk and sponsor bank treasuries, not just IT tickets. Multi-factor authentication on merchant admin consoles, IP allow lists for settlement file uploads, and separation of marketing SSO from payout permissions are recurring themes in RBI's prior advisories; CERT-In now treats their absence as aggravating factors in breach summaries.
For shop owners, the practical signal is different: if your aggregator's status page goes quiet during a long weekend while UPI receipts stall, ask your bank for the ombudsman route immediately rather than waiting for a blog post. Festival traffic will not pause for forensic write-ups.
What remains unknown
CERT-In has not published aggregate late-filing statistics for payment licensees. Industry groups requested a sanitized holiday-season threat bulletin; MeitY said it is weighing a weekly indicator feed without naming victims. Until then, the six-hour clock is the enforceable fact—paperwork tied to the busiest digital cash week of the year, not a theoretical compliance slide.
Aggregators that treated incident reporting as a post-season audit item now face a calendar that starts when an analyst opens a ticket, not when the CEO returns from garba night. Whether that changes outcomes depends on SOC staffing, not circular typography.








