3.5 million MobiKwik users' data up for sale, company denies claim

The leak was first reported in February by security researcher Rajshekhar Rajaharia, which the company had denied at the time

MobiKwik
If the breach has indeed occurred, there is very little users can do except demand accountability from the company, a security researcher who did not wish to be named, said | Photo: Bloomberg
Neha Alawadhi New Delhi
3 min read Last Updated : Mar 29 2021 | 11:43 PM IST
Payment app MobiKwik on Monday came under fire for an alleged data leak that has exposed close to 8.2 terabytes (TB) of data, including know-you-customer (KYC) details, addresses, phone numbers, Aadhaar card data of its users on the dark web. 

According to reports, data of close to 3.5 million users was at risk.

The company, however, denied the breach. 

The leak was first reported in February by security researcher Rajshekhar Rajaharia, which the company had denied at the time.

However, on Monday, a link from the dark web began circulating online, and several users confirmed seeing their personal details in it. 

Many people also posted screenshots of the alleged MobiKwik user data, which, according to sources, was up for sale for 1.5 bitcoin or about $86,000. 

While the passwords were encrypted on masked in the data, the other personal details were not. 

“Some media-crazed so-called security researchers have repeatedly attempted to present concocted files wasting precious time of our organisation as well as members of the media. We thoroughly investigated and did not find any security lapses. Our user and company data is completely safe and secure,” a MobiKwik spokesperson said. 

The researcher, Rajaharia, had tweeted details of the leak on February 26: “11 crore Indian cardholders’ card data, including personal details and KYC soft copy (PAN, Aadhar, etc) allegedly leaked from a company’s server in India. 6 TB of KYC data and 350 GB of compressed mysql dump”. 

He followed his tweets by subsequently naming MobiKwik, which, he said, had removed an old post about a previous data breach from 2010. 

MobiKwik said the blog post was never removed and continues to be up.

French hacker Robert Baptiste, who goes by the pseudonym Elliot Alderson on Twitter, also tweeted on Monday, “Probably the largest KYC data leak in history. Congrats Mobikwik...”, and posted a screenshot of the leaked data. 

If the breach has indeed occurred, there is very little users can do except demand accountability from the company, said a security researcher who did not wish to be named. 

“Given the large data set, there is a big chance that scammers will be able to scam people and sound more authentic. Even though the passwords seem encrypted in the data, all the other details like PAN card, Aadhaar card etc have not been masked. This makes anyone listed in the database vulnerable to fraud. The details include phone number and email IDs too, so it gives scammers an easy way to reach out to the users,” said independent security researcher Indrajeet Bhuyan. 

MobiKwik had last week raised $7.2 million in a funding round prior to the listing on the stock exchange. 

According to Entrackr, Mobikwik’s post-money valuation currently stands at $493 million with the latest funding round.


One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Dark WebMobiKwikData breachHackingUser data informationpayments appKYC for Payments appcyber security

Next Story