Noida Fintech Server Hacked, 497 Transactions Made in Eight Hours

The420.in Staff
5 Min Read

Cybercriminals allegedly hacked the server of a fintech company in Sector 65 and siphoned off more than ₹2.42 crore through hundreds of unauthorised transactions.

According to police, 497 transactions were carried out within around eight hours, with ₹2,42,62,576 transferred to 58 bank accounts spread across 28 banks. A case has been registered at the Cyber Crime Police Station following a complaint by the company’s director.

How Was the Server Targeted?

The company provides fintech services including mobile recharges, bill payments, Aadhaar-enabled Payment System cash withdrawals and domestic money transfers.

According to police, unauthorised activity took place on the company’s server and API portal between around noon and 8 pm on September 13.

During this period, hundreds of transactions were allegedly processed through the system without the company’s authorisation.

How Did 497 Transactions Happen?

The preliminary investigation indicates that cybercriminals allegedly used the company’s API portal to rapidly transfer funds after gaining access to the payment system.

A total of 497 transactions were completed within around eight hours.

Investigators are examining whether automated or rapidly executed transactions were used. The exact method of intrusion and any technical vulnerability involved have not yet been established.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Why Was the Fraud Not Detected Earlier?

Company officials did not immediately detect the unauthorised transactions.

The suspicious activity was discovered during a routine review of financial transactions, when officials noticed a large number of transactions that had not been authorised by the company.

The company subsequently examined its server and API system and found indications of alleged unauthorised access.

A complaint was then filed through the cybercrime reporting portal, followed by registration of a case.

Where Did the Money Go?

The allegedly stolen ₹2.42 crore was transferred to 58 bank accounts across 28 different banks.

Police are examining the identities of the account holders, the nature of the funds received and what happened after the money entered these accounts.

Investigators are also checking whether the funds were moved further into other bank accounts, digital wallets or additional financial channels.

What Are Investigators Checking?

Cyber Crime Police and technical teams are conducting a forensic examination of the company’s server and API portal logs.

Suspicious IP addresses, login activity and API requests are being analysed to determine when and how the unauthorised access occurred.

Investigators are also checking whether compromised credentials, an account or another technical method was used to enter the system.

Was Someone From Inside Involved?

Investigators are examining whether the attack was carried out entirely by external cybercriminals or whether someone familiar with the company’s technical infrastructure and payment system may have played a role.

No conclusion on possible insider involvement has been established.

Digital evidence from the server, banking transactions and other technical records is being analysed together to identify those allegedly involved.

Can the Money Trail Be Traced?

Police are preparing a complete transaction trail covering the 58 recipient accounts and any subsequent movement of the funds.

The objective is to identify the final beneficiaries and determine whether the accounts are connected to a wider cybercrime network.

The forensic examination will also seek to establish how the attackers allegedly breached the fintech system and how hundreds of transactions could be carried out within such a short period.

The case shows how quickly a compromised payment system can potentially be exploited once attackers gain access. For fintech companies handling large volumes of transactions, continuous monitoring of unusual API activity, logins and sudden transaction spikes can be critical.

Early detection can make the difference between stopping suspicious activity and allowing funds to spread across dozens of accounts.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected