Executive Summary:
The Ministry of Finance addressed the Lok Sabha regarding ATM theft and fraud incidents, referencing the RBI's report on banking trends. The response details the increase in reported fraud cases, clarifies the reasons for the increase, and outlines remedial measures taken by the government and RBI to enhance ATM security and combat card skimming. These measures include directives to banks and regulated entities (REs) to strengthen security protocols and adopt advanced technologies.
Key Points / Main Content:
Fraud Statistics:
* Reported fraud cases involving amounts of Rs. 1 lakh and above increased from 14,480 (Rs. 2,623 crore) in April-September 2023-24 to 18,461 (Rs. 21,367 crore) in April-September 2024-25.
* The increase is primarily due to the re-examination and fresh reporting of 59 fraud cases (Rs. 9,997 crore) from previous financial years, which were initially withdrawn due to non-compliance with a Supreme Court judgment.
* Frauds based on the date of occurrence involving Rs. 1 lakh and above decreased from 34,121 cases (Rs. 4,893 crore) in FY 2023-24 to 10,175 cases (Rs. 1,037 crore) in FY 2024-25.
ATM Security Measures:
* RBI instructed banks to enhance ATM security via circular dated 21.06.2018.
* Mandatory security measures include enabling BIOS passwords, disabling USB ports and autorun, applying OS patches, implementing terminal security solutions, time-based admin access, anti-skimming, whitelisting solutions, and OS upgrades.
* Banks must review and strengthen security at branches and ATMs, including CCTV coverage, verification and training of security guards.
* Banks are required to submit quarterly theft reports, including ATM thefts, to the RBI.
Card/Internet Fraud:
* Frauds related to digital payment card/internet decreased from 29,082 cases (Rs. 1,457 crore) in FY 2023-24 to 13,516 cases (Rs. 520 crore) in FY 2024-25.
Remedial Measures for Card/Internet Fraud:
* RBI issued guidelines for migrating from magnetic stripe cards to EMV chip and PIN-based cards.
* Banks and White Label ATM Operators (WLAOs) were required to enable EMV Chip and PIN card processing for all ATMs by September 30, 2017; new ATMs must support this from inception.
* RBI issued guidelines on Cyber Security Controls for third-party ATM Switch Application Service Providers (ASPs) on 31.12.2019.
* RBI issued Master Direction on Digital Payment Security Controls on 18.02.2021, advising banks to protect customer data confidentiality and integrity.
* Banks, ATM networks, and WLAOs may offer Interoperable Cardless Cash Withdrawal (ICCW) to reduce skimming and cloning frauds, per RBI circular dated 19.05.2022.
* Banks should display fraud awareness posters at ATMs and branches and provide 24/7 channels for reporting unauthorized transactions.
Impact Analysis:
Banks:
* Impact: Required to implement and maintain enhanced ATM and digital payment security measures, upgrade technology, comply with RBI directives, and report fraud incidents.
* Action Required: Implement required security measures, upgrade ATM infrastructure, adhere to RBI guidelines, submit regular reports, and enhance customer awareness.
RBI:
* Impact: Responsible for issuing directives, monitoring compliance, analyzing fraud data, and coordinating with state authorities on security matters.
* Action Required: Continue to issue and update security guidelines, monitor bank compliance, analyze fraud data, and collaborate with state authorities.
ATM Users:
* Impact: Benefit from increased ATM and transaction security, reduced risk of fraud, and improved channels for reporting unauthorized transactions.
* Action Required: Be aware of fraud risks, report unauthorized transactions promptly, and utilize available security features.
White Label ATM Operators (WLAOs):
* Impact: Required to comply with RBI directives on ATM security and technology upgrades.
* Action Required: Implement required security measures, upgrade ATM infrastructure to support EMV chip and PIN cards, and enable ICCW.
Key Entities Referenced
Reserve Bank of India: The central bank of India, responsible for regulating the banking sector and issuing currency.
Automated Teller Machines: Also known as ATMs, are banking outlets that allow customers to complete basic transactions without the aid of a branch representative or teller.
Shri Pankaj Chaudhary: The Minister of State in the Ministry of Finance.
Department of Supervision, RBI: The department within the Reserve Bank of India responsible for supervising banks.
Cyber Security Controls for third party ATM Switch Application Service Providers: Guidelines issued by RBI on 31.12.2019 to enhance the security of ATM transactions through third-party service providers.
Master Direction on Digital Payment Security Controls: RBI's directive issued on 18.2.2021, outlining the security controls required for digital payments.
Interoperable Cardless Cash Withdrawal: A facility that allows customers to withdraw cash from ATMs without using a physical card, to reduce card related frauds.
State Level Security Committee: Forum where data on theft including ATM theft is shared with Regional Offices of RBI, and discussed with respective State authorities.
GOVERNMENT OF INDIA
MINISTRY OF FINANCE
DEPARTMENT OF FINANCIAL SERVICES
LOK SABHA
UNSTARRED QUESTION NO- 1195
ANSWERED ON MONDAY, JULY 28, 2025/ SRAVANA 6, 1947 (SAKA)
Incidents of ATM Theft/Fraud
1195. DR. BACHHAV SHOBHA DINESH
Will the Minister of FINANCE be pleased to state:-
(a) whether the Government has taken cognisance of Report of Reserve Bank of India on Trend and
Progress of Banking in India 2023-24 which stipulates that total frauds during April-September stood
at 18,461 involving Rs. 21,367 crore compared to 14,480 cases involving Rs. 2,623 crore in the
comparative period of last financial year;
(b) whether any remedial measures have been taken by the Government to check increasing incidents
of ATM theft;
(c) whether the Government has taken cognisance of increasing trend of ATM card skimming fraud
in which criminals use a device to steal credit or debit card information from ATM users;
(d) if so, whether the Government has taken any remedial measures in this regard and if so, the
details thereof; and
(e) whether the Government has issued any directive mandating all banks to enforce extra security
measures to prevent ATM skimming and if so, the details thereof and if not, the reasons therefor?
ANSWER
THE MINISTER OF STATE IN THE MINISTRY OF FINANCE
(SHRI PANKAJ CHAUDHARY)
(a): As per Reserve bank of India (RBI) report on Trend and Progress of Banking in India 2023-24,
frauds based on the date of reporting, involving amount Rs. 1 lakh and above, the number of fraud
cases during April-September (2024-25) stood at 18,461 involving Rs. 21,367 crore as compared to
14,480 cases involving Rs. 2,623 crore for April-September (2023-24).
The increase in frauds during the half year (April-September) 2024-25 is mainly due to re-
examination and reporting afresh 59 fraud cases involving Rs. 9,997 crore, pertaining to previous
financial years which were earlier withdrawn by banks due to non-compliance of the Hon’ble
Supreme Court judgement dated March 27, 2023, and have been re-examined and reported afresh by
banks during the current financial year after ensuring compliance with the above judgement.
As per RBI data, frauds based on the date of occurrence, involving Rs. 1 lakh and above, the number
for FY 2023-24 stood at 34,121 cases involving an amount of Rs. 4,893 crore which decreased to
10,175 cases involving an amount of Rs. 1,037 crore for FY 2024-25. Thus, there is a declining trend
in fraud occurred in the last 2 years.(b): RBI, vide the circular on “Control measures for Automated Teller Machines (ATMs) – Timeline
for compliance” dated 21.6.2018, advised banks to take various measures to strengthen security of
ATMs. These measures, inter alia include - enabling Basic Input Output System (BIOS) passwords,
disabling Universal Serial Bus (USB) ports, disabling auto-run facility, applying the latest patches of
operating system and other software, terminal security solution, time-based admin access,
implementing anti-skimming and whitelisting solution, upgrading ATMs to supported versions of
operating system, etc.
RBI has advised banks from time to time to review and strengthen the security arrangements at their
branches and ATMs to deal with instances of robbery etc. and for dealing with risk perceptions
emerging from such incidents. These include coverage of ATM sites by Closed-Circuit Televisions
(CCTVs), verification of credentials of private security guards, ensuring adequate training of security
staff posted at ATMs, etc.
Banks are required to submit a quarterly Return on theft (including ATM theft) to Department of
Supervision, RBI. The data thus collected is shared with Regional Offices of RBI, and the matter is
discussed with respective State authorities during the State Level Security Committee (SLSC)
meetings.
(c): As per RBI annual report 2024-25, frauds under the category of digital payment (card/internet)
based on the date of reporting, involving Rs. 1 lakh and above, the number for FY 2023-24 stood at
29,082 cases involving an amount of Rs. 1,457 crore which decreased to 13,516 cases involving an
amount of Rs. 520 crore for FY 2024-25. Thus, there is a declining trend in card/internet fraud
reported in the last 2 years.
(d) and (e): As a risk mitigation measure, RBI has issued guidelines to all Regulated entities (REs)
regarding migration from magnetic stripe cards to EMV chip and pin-based cards.
Banks in India and the White Label ATM operators were advised to ensure that all the existing
ATMs installed/operated by them are enabled for processing of EMV Chip and PIN cards by
September 30, 2017. All new ATMs shall necessarily be enabled for EMV Chip and PIN processing
from inception.
Comprehensive steps have been taken to enhance security of card transactions, online transactions
etc., and to reduce ATM banking frauds which include, inter alia, the following:
• RBI has issued Guidelines dated 31.12.2019 on Cyber Security Controls for third party ATM
Switch Application Service Providers (ASPs).
• RBI has issued Master Direction on Digital Payment Security Controls on 18.2.2021. As per this
direction, banks have been advised to put in place necessary controls to protect the
confidentiality and integrity of customer data, and processes associated with the digital
product/services offered by them.
• In terms of RBI circular CO.DPSS.POLC.No. S-227 / 02-10-002/ 2022-23 dated May 19, 2022,
all banks, ATM networks and White Label ATM Operators (WLAOs) may provide the option of
Interoperable Card-less Cash Withdrawal (ICCW) at their ATMs. The absence of need for a card
to initiate cash withdrawal transactions would help in containing frauds like skimming, card
cloning, device tampering, etc.
• Display of posters in bank ATMs and branches to spread awareness against frauds.
• 24x7 access through multiple channels (via website, phone banking, Short Message Service
(SMS), e-mail, Interactive Voice Response (IVR), toll-free helpline, reporting to home branch,
etc.) for reporting unauthorized transactions that have taken place and/ or loss or theft of
payment instrument, such as, card, etc.
*****