MobiKwik Denies Alleged Data Leak of Millions of Users on Dark Web

MobiKwik said that it will get a third party to conduct a forensic data security audit to provide clarity on the matter.

Advertisement
By Jagmeet Singh and Roobina Mongia | Updated: 30 March 2021 17:48 IST
Highlights
  • MobiKwik has so far denied the data breach
  • Security researchers have provided references around the leak
  • The leaked data is purportedly accessible through the dark Web

MobiKwik data leak was first reported by a security researcher in February

Photo Credit: Pexels

MobiKwik's user data has allegedly been breached and is purportedly available for access by hackers through a dedicated search engine. The Gurugram-based digital wallet company is denying the data breach. However, independent security researchers have claimed that the data — over 8.2TB in size — has been put on sale on the dark Web for quite some time now. Gadgets 360 was first informed about the alleged data breach in February. The hackers group, that allegedly had access to the data for months, has now made it accessible through a search engine that suggests some of the leaked data elements — including the names, phone numbers, and email IDs of millions of affected users.

Denying the claims of any sensitive data leaks, MobiKwik said that it did not find any evidence of a breach.

Advertisement

“As a regulated entity, the company takes its data security very seriously and is fully compliant with applicable data security laws. The company is subjected to stringent compliance measures under its PCI-DSS and ISO Certifications which includes annual security audits and quarterly penetration tests to ensure security of its platform,” a MobiKwik spokesperson said in an emailed statement.

The spokesperson added that the company was closely “working with requisite authorities” on the matter and will get a third party to conduct a forensic data security audit, considering the seriousness of the allegations.

Advertisement

“For its users, the company reiterates that all MobiKwik accounts and balances are completely safe,” the spokesperson said.

Cyber-security researcher Rajshekhar Rajaharia first informed Gadgets 360 about the data breach on February 25. He had said that credit and debit card details, names, email addresses, and other details of more than 100 million users were leaked on the dark Web. The researcher also stated that apart from the details in text, know-your-customer (KYC) information that included scanned documents such as Permanent Account Number (PAN) and Aadhar cards as well as bank statements of over five crore users were put on sale by the hackers group that is known by pseudonym “ninja_storm.”

Advertisement

The researcher had shared some sample files that included a table structure with a reference about MobiKwik's payment gateway Zaakpay.

Shortly after receiving the details from the researcher, Gadgets 360 reached out to MobiKwik co-founders Bipin Preet Singh and Upasana Taku. The executives, however, didn't provide any clarity on the breach at that time. An email sent to CERT-In also didn't receive any correspondence.

Advertisement

MobiKwik on March 4 publicly denied its role in the data breach and called the researcher “media-crazed”, without naming Rajashekar explicitly. The company also alleged that the researcher in question presented “concocted files” to “grab media attention”.

However on Monday, French security researcher Robert Baptiste, who's known as Elliot Alderson on Twitter, posted the details about the alleged data breach. He also provided the details about the search engine that was purportedly created by the hackers group on the dark Web and included some user details.

Several users on social media posted that they were able to find their details from that search engine.

 

However, Gadgets 360 wasn't able to independently verify whether the available details were related to the alleged MobiKwik data breach.


Orbital, the Gadgets 360 podcast, has a double bill this week: the OnePlus 9 series, and Justice League Snyder Cut (starting at 25:32). Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Realme 16 Series and OnePlus 15R Become More Expensive in India
  2. How to Claim PF Online Without Employer Approval Under New EPFO Rules
  3. Apple to Upgrade Genmoji in iOS 27 With Smarter Emoji Suggestions:Gurman
  1. SpaceX Dragon Capsule Reaches ISS Carrying 6,500 Pounds of Supplies
  2. YouTube’s Likeness Detection Tool Is Now Available to All Adult Creators
  3. Vi Postpaid Users in India Can Choose New International Roaming Plans From Rs 649
  4. Red Magic 11S Pro, Red Magic 11S Pro+ Launched With Snapdragon 8 Elite Gen 5 Leading Edition SoC: Price, Specifications
  5. Satrangi: Badle Ka Khel OTT Release Date Revealed: Know Everything About Plot, Cast, and More
  6. Prasanth Pandiyaraj’s Warrant OTT Release Details Revealed: Know When and Where to Watch it Online
  7. Realme 16T 5G Camera Specifications Confirmed Ahead of May 22 India Launch
  8. Realme 16 Series Gets Price Hike in India; OnePlus, Poco and Lava Also Revise Rates
  9. Verus Ethereum Bridge Reportedly Suffers from $11.5 Million DeFi Hack
  10. The Travellers Now Streaming on Netflix: Know Everything About This Australian Drama Film
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.