2025 Moneyview (Whizdm Finance) — ~₹49 crore fraud via alleged API key misuse; Bengaluru police investigation
Data compromised
Primarily financial loss and fraudulent loan disbursements; PII categories in regulatory notifications not uniformly summarized in early press
Technical writeup
Indian press (e.g., India Today, Moneycontrol, October–November 2025 wave) reported a major fraud against the Moneyview instant-loan fintech (Whizdm Finance Pvt Ltd): attackers allegedly misused platform/API access to execute large volumes of unauthorized disbursements over a short window (public narratives cite roughly ₹47–49 crore in losses, ~1,780+ suspicious transactions, and hundreds of mule accounts). Bengaluru police described follow-on arrests and pursuit of an internationally distributed actor ecosystem (reporting cited Dubai, China, Hong Kong, Philippines). The episode is characterized in coverage as a high-impact financial crime and API/credential-abuse case rather than a classic static customer-database dump; victim counts and technical root cause were still being adjudicated in open sources at the time of summaries.
Root cause
Criminal misuse of API or authentication material enabling fraudulent fund movement (per law-enforcement and press framing); full forensic chain not uniformly public