Skip to Content
Join the Network with Us — Join Membership


Noida Fintech Server Hacked, 497 Transactions Made in Eight Hours

September 17, 2026

Cybercriminals allegedly hacked the server of a fintech company in Sector 65, Noida, siphoning off more than ₹2.42 crore through hundreds of unauthorised transactions carried out within a single day.

How the Attack Unfolded

According to police, 497 transactions were carried out within around eight hours, with ₹2,42,62,576 transferred to 58 bank accounts spread across 28 different banks. A case has been registered at the Cyber Crime Police Station following a complaint filed by the company's director.

The company provides fintech services including mobile recharges, bill payments, Aadhaar-enabled Payment System (AePS) cash withdrawals, and domestic money transfers. Police say unauthorised activity took place on the company's server and API portal between roughly noon and 8 pm on September 13, during which hundreds of transactions were allegedly processed without the company's authorisation.

How 497 Transactions Happened So Quickly

The preliminary investigation indicates cybercriminals allegedly used the company's API portal to rapidly transfer funds after gaining access to the payment system, completing 497 transactions within around eight hours. Investigators are examining whether automated or rapidly executed scripts were used to achieve this volume, though the exact method of intrusion and any specific technical vulnerability exploited haven't yet been established.

Why the Fraud Wasn't Caught Immediately

Company officials didn't immediately detect the unauthorised transactions as they were happening. The suspicious activity only surfaced during a routine review of financial transactions, when officials noticed a large number of entries that hadn't been authorised by the company. Following this discovery, the company examined its server and API system and found indications of alleged unauthorised access, prompting a complaint through the cybercrime reporting portal and the subsequent registration of a case.

Where the Money Went

The allegedly stolen ₹2.42 crore was spread across 58 bank accounts in 28 different banks, a deliberate fragmentation that makes tracing and freezing the funds considerably harder. Police are examining the identities of these account holders, the nature of the funds received, and what happened to the money once it landed in these accounts, alongside checking whether it was moved further into other bank accounts, digital wallets, or additional financial channels.

What Investigators Are Examining

Cyber Crime Police and technical teams are conducting a forensic examination of the company's server and API portal logs, analysing suspicious IP addresses, login activity, and API requests to determine exactly when and how the unauthorised access occurred. Investigators are also checking whether compromised credentials, a specific account, or another technical method was used to breach the system.

Was This an Inside Job?

Investigators are examining whether the attack was carried out entirely by external cybercriminals, or whether someone familiar with the company's technical infrastructure and payment system may have played a role. No conclusion on possible insider involvement has been established at this stage, digital evidence from the server, banking transactions, and other technical records is being analysed together to identify everyone allegedly involved.

Tracing the Money Trail

Police are preparing a complete transaction trail covering all 58 recipient accounts and any subsequent movement of funds, part of a broader financial investigation aimed at identifying the final beneficiaries and determining whether these accounts are connected to a wider cybercrime network rather than being isolated one-off recipients.

What This Case Reveals

This incident illustrates how quickly a compromised payment system can be exploited once attackers gain access, nearly 500 transactions completed in just eight hours before anyone noticed. For fintech companies handling large transaction volumes, continuous monitoring of unusual API activity, login patterns, and sudden transaction spikes can be genuinely critical. Early detection can make the difference between stopping suspicious activity in its tracks and allowing funds to scatter across dozens of accounts before recovery becomes possible.

FAQs

Q1. How much money was stolen, and how many transactions were involved?

₹2.42 crore was allegedly siphoned off through 497 unauthorised transactions carried out within around eight hours.

Q2. How was the fraud eventually discovered?

During a routine review of financial transactions, when company officials noticed a large number of entries that hadn't been authorised.

Q3. Where did the stolen money go?

It was transferred to 58 bank accounts spread across 28 different banks, a pattern investigators are now tracing further.

Q4. Are investigators considering the possibility of an inside job?

Yes. Investigators are examining whether the attack was carried out entirely by external actors or involved someone familiar with the company's internal systems, though no conclusion has been reached yet.

in News
Share this post
Archive