← Razorpay

2022 Razorpay — fraudulent settlement of failed transactions via manipulated authorization checks (~₹7.4 cr)

2022 Unknown records affected Share on X

Data compromised

Primarily monetary mis-settlement; not characterized in mainstream reporting as a bulk PII dump from Razorpay core databases

Technical writeup

Indian payment aggregator Razorpay publicly confirmed criminal abuse in May 2022 wherein attackers systematically cleared previously failed transactions by exploiting authorization / authentication validation gaps on older merchant integration patterns, resulting in net outflows press-rounded to about ₹7.3–7.4 crore across hundreds of abnormal settlements. The Hindu, Moneycontrol, and follow-on security trade summaries quoted the company framing impact as financial theft routed through select merchants rather than a mass PAN/database exfiltration event; technical specifics differed by merchant stack generation.

Root cause

Application-logic / integration-layer abuse permitting unauthorized reversal of failed-payment states (per Razorpay and press paraphrases)

References