RBI(Central bank) has been filling-up for a long time for the total lack of security practices by merchants & data-privacy laws.
e.g. One can control how much money can be withdrawn from the credit/debit card per-day according to domestic/International merchants/online/physical/ATM/ etc. through net-banking with the minimum in the multiples of INR 1000. So even if the card data gets stolen, Criminals can utmost withdraw only the minimum amount in the other part of the world.
But unfortunately due to the digital-divide, Not many have access or awareness of such facilities and hence control over card data is required.
IMO the single point of failure for India's financial security is its extraordinary dependence on mobile number for 2FA, Even security conscious customers can do little against SIM jacking attacks, But for those who are not security conscious; all it requires is a social engineered SMS with ngrok URL[1] or Phone call asking for that OTP.
Please write to RBI and demand your bank to support hardware tokens (or) at least TOTP.
> 3. PayTm (One of the largest, if not the largest digital payments app in India)
Did you mean that largest digital payments company which integrated the PoS facility on the merchant's app and the customers were asked to enter their credit/debit card details manually?[2]
[1] https://twitter.com/Abishek_Muthian/status/14069649600815718...
[2] https://abishekmuthian.com/paytm-says-to-me-that-its-pos-fea...