Your Due Diligence Was Perfect. Three Months Ago.
Date Published

It's January. Somewhere, a merchant just got approved.
Documents checked out. Identity verified. Category confirmed. The system gave the all-clear, and attention moved to the next application.
Come back in March.
That same merchant is running a completely different business. The website has changed. Transaction patterns have shifted. The declared category is nowhere close to what is actually transacting. Nobody flagged it. Because nobody was looking.
This is not hypothetical. This is what we found when we monitored 25,000 merchant websites over the 60 days following verification, and it rewrites the risk calculus for every Payment Aggregator in India. You would have read about ICICI Bank's pushback on MCC misuse, an estimated Rs 2,500 crore annual drain on interchange income for issuing banks. That number captures the misclassification already visible in the system. It doesn't capture what is hiding in the silence after onboarding.
The onboarding check is thorough. It is also, by design, a snapshot resting on a seemingly reasonable assumption: the business that applied in January is still the same in March. That assumption is exactly where fraud goes to wait. Here is what the data shows.
One in five merchant websites observed at onboarding was no longer operational within 60 days. Gone. Dark. A further 11% of sites that remained live showed minimal activity, technically present, but with little evidence of a functioning business. A ghost with a landing page.
Most significantly, among merchants whose sites remained active, 7.3% demonstrated a complete shift in their predicted Merchant Category Code; the business on that website bore no resemblance to the business that was onboarded. At the scale of India's digital payments ecosystem, these are not edge cases. They are a structural gap.
The consequences compound quietly. Dormant and misclassified merchants drive rising chargeback rates. For Payment Aggregators carrying MCC misclassification, the exposure doesn't announce itself. It builds. The risk that onboarding was designed to catch has, in a meaningful share of cases, simply waited 60 days.
You don't get defrauded at onboarding. You get defrauded sixty days later by a merchant you already approved.
No human compliance team can watch thousands of merchants simultaneously for signs of drift. AI can cause a website to go dark, transaction volumes to shift, and a category to drift from its original declaration. Caught early, these are flags. Left unread, they become chargebacks and exposure. This demands a second question. Not just: is this merchant legitimate today? But is this still the same merchant that was onboarded?
Verification at onboarding is necessary. Increasingly, it is not sufficient. The question is no longer whether you checked. It's whether you're still watching.

Learn important payment terms in simple language. Understand UPI, BNPL, Payment Gateways, Merchant Onboarding, and more with our easy 2026 guide.
Explore the 2026 payment fraud landscape in India. Learn the most common types of payment fraud, the emerging fraud trends, and how to build a future-ready fraud prevention strategy.