'Largest KYC leak ever': Data of 10 crore Indians exposed at MobiKwik

darkweb
(Image credit: Archive)

It has already been termed as the largest KYC leak ever. Independent cyber security researchers have claimed that a database containing KYC details of nearly 3.5 million users of Indian payment app MobiKwik, in addition to  personal and payments data of about 99,224,559 users, is up for sale on the Dark Web.

First tweeted by the independent cyber security researcher, Rajshekhar Rajaharia, and then confirmed by the French researcher Elliot Alderson, (who termed it the largest KYC leak), the alleged breach is pegged at 8.2TB data containing users’ phone numbers, emails, passwords, addresses, bank accounts and Aadhaar card details.

Mobikwik has denied the breach.

But a link from the dark web is available online, and several users on twitter have claimed seeing their personal details in it.

Some of them even posted screenshots of the alleged MobiKwik user data, which was reportedly up for sale for 1.5 bitcoin or about $86,000 (Rs 69 lakh) on a popular hacker forum.

"A media-crazed so-called security researcher has repeatedly over the last week presented concocted files wasting precious time of our organization while desperately trying to grab media attention. We thoroughly investigated his allegations and did not find any security lapses," MobiKwik tweeted from its official handle.

Our user and company data is completely safe and secure. The various sample text files that he has been showcasing prove nothing. Anyone can create such text files to falsely harass any company, it added.

MobiKwik also said that its legal team will pursue action against the researcher.

Seller says data can be used to raise loans

Screenshot of what the seller at hacker forum claims to have in possession

Screenshot of what the seller at hacker forum claims to have in possession. (Image credit: TechNadu)

The denial does not square with the fact that the seller at the hacker forum has also calimed the the source to be MobiKwik. The samples of leaked data, in any case, contain images of MobiKwik QR codes.

As per a report in TechNadu, "for the set price of 1.5 BTC ($84k), a buyer can get the entire database and have the dark web portal taken offline, keeping everything exclusive."

The seller of the data also claimed that the merchant entries can be used to raise loans by posing as the merchant.

"The seller claims that each of the merchant entries in the database can be used to raise $500-$1,000 loans in Indian currency, so the investment of the 1.5 BTC could supposedly yield up to three billion USD," the TechNadu report added.

The data dump is said to contain 350GB of MySQL dumps or 500 databases, 99 million email, phone, passwords, physical addresses, IP address, GPS location and device related data, as well as 40 million records of card numbers, expiry dates, card hashes (SHA256 encrypted).

Further, it also has 7.5TB of merchant KYC data pertaining to 3.5 million merchants. Details of passports, Aadhaar cards, PAN cards, selfies, other photograph proof and other information that MobiKwik used to furnish loans to these customers. 

For the record, MobiKwik had last week raised $7.2 million in a funding round prior to the listing on the stock exchange.

Balakumar K
Senior Editor

Over three decades as a journalist covering current affairs, politics, sports and now technology. Former Editor of News Today, writer of humour columns across publications and a hardcore cricket and cinema enthusiast. He writes about technology trends and suggest movies and shows to watch on OTT platforms. 

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Security padlock and circuit board to protect data
Mexican fintech company Miio exposed millions of files of sensitive customer data
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Businessman holding a magnifier and searching for a hacker within a business team.
Top Mexican fintech firm leaks details on 1.6 million customers
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
The Meta Quest Pro on its charging pad on a desk, in front of a window with the curtain closed
Samsung, Apple and Meta want to use OLED in their next VR headsets – but only Meta has a plan to make it cheap
AMD Ryzen 9000 3D chips
AMD officially announces price and release date for Ryzen 9 9900X3D and 9950X3D processors
Google Pixel 9
There's something strange going on with Google Pixel phone vibrations after the latest update
A masculine hand holding the Nvidia GeForce RTX 5070 Ti
Budget gamers rejoice as Nvidia RTX 5050 and RTX 5060 are rumored to launch in April
The Asus ROG Ally handheld gaming PC
AMD's new driver adds AFMF 2.1 support for improved frame generation - and it could be a game-changer for handheld gaming PCs
Victrola Stream Carbon turntable playing David Bowie, with the tonearm being operated
Victrola putting Bluetooth in its Sonos-only turntables is the hi-fi equivalent of ‘I think we should see other people’