← Case Files · The Breach Files

2021 · India · Disputed

MobiKwik, 2021: the breach that was denied while people searched their own KYC files

Case file · 4 min read · Published 14 September 2026

People affected
Alleged 99 million users and 8.2 TB of data — never confirmed by the company
When it happened
Reported from January 2021; the sale portal appeared in March 2021
Made public
Never formally disclosed by the company
How they got in
Not established publicly
Attributed to
An unidentified seller advertising the data; no attribution was ever made
What it cost
The Reserve Bank of India ordered a third-party forensic audit; no public penalty followed

What was exposed: Phone numbers · Email addresses · Hashed passwords · Addresses · Alleged KYC documents including Aadhaar and PAN card images

In March 2021, a portal appeared on a dark web site that let anyone type in a phone number and see what it returned. Indian journalists typed in their own. Several reported getting back their own addresses, their own card details in part, and images of their own Aadhaar and PAN cards. MobiKwik, the payments company the data was attributed to, said no breach had occurred. It has never said otherwise.

What is documented, and what is not

This case file is written differently from the others on this site, because the usual materials do not exist. There is no regulatory penalty notice, no court judgment, no company disclosure setting out a timeline. What follows separates what the public record establishes from what was claimed.

Established: a dataset advertised as containing MobiKwik user data was offered for sale in early 2021. A searchable interface was made available by the seller in late March, and multiple identifiable people — including working journalists who wrote about it under their own names — reported retrieving accurate personal records about themselves from it, including identity document images. MobiKwik publicly and repeatedly denied that its systems had been breached. The Reserve Bank of India directed the company to commission a third-party forensic audit. The sale portal was withdrawn by the seller at the end of March 2021.

Claimed but not independently established: the figures of 8.2 terabytes and 99 million users, which came from the seller and from researchers examining the advertisement rather than from any verified count. The method of compromise, which was never described by anyone in a position to know. Any attribution of the seller.

Never published: the findings of the forensic audit.

Why a denial is a strategic decision, not just a factual claim. For a regulated financial company preparing for a public listing, confirming a breach of identity documents triggers obligations, invites regulatory action and lands in the offer document. Denying costs nothing immediately. The asymmetry is the problem: in a jurisdiction without a mandatory breach notification regime carrying real penalties — which India substantially lacked in 2021 — the incentive structure points one way, and the people whose Aadhaar images are in circulation carry the consequence either way. India's Digital Personal Data Protection Act, passed in 2023, changes that calculation, which is precisely why it was needed.

The researcher problem

The alarm was raised by an independent security researcher, Rajshekhar Rajaharia, who had been publicising the dataset since January. The company's response characterised him in dismissive terms rather than engaging with the technical claim.

This is a pattern with real consequences. Independent researchers are, in practice, a substantial part of how breaches involving Indian companies come to light, because there is no obligation on a company to find or report one. If the reliable outcome of reporting a finding is public hostility and legal exposure, researchers stop reporting — or report anonymously to journalists instead of privately to the company, which is worse for everybody including the company.

The countries that have handled this better did so by establishing safe harbour: a documented vulnerability disclosure policy, a contact address that reaches security rather than legal, and a commitment not to pursue good-faith researchers. It costs very little and it changes which way information flows.

The timeline

  1. January 2021 — A researcher publicly flags a dataset advertised as MobiKwik user data.
  2. February 2021 — MobiKwik states that an investigation found no evidence of a breach and describes the reports as false.
  3. Late March 2021 — A searchable portal appears; users and journalists report finding their own records, including KYC document images.
  4. End of March 2021 — The Reserve Bank of India directs MobiKwik to commission a third-party forensic audit; the company says it will do so.
  5. 31 March 2021 — The seller withdraws the portal.
  6. Afterwards — No audit findings are published, no regulatory penalty is announced, and no confirmation or retraction follows.

What it changed

It became a reference point in the argument for India's data protection law. The Digital Personal Data Protection Act 2023 introduced breach notification duties and a regulator with penalty powers. The gap this case exposed — a large alleged exposure of identity documents with no obligation to confirm, notify or explain — is exactly the gap that legislation was written to close.

It sharpened scrutiny of KYC data retention in Indian fintech. The underlying question the case raised is why full identity document images were retained in a form that could be exfiltrated in bulk at all, years after onboarding. Tokenised verification and reference-only storage have gained ground since.

It demonstrated the limits of denial in the era of searchable dumps. A company can dispute a researcher's analysis. It cannot easily dispute a journalist who has retrieved their own Aadhaar card from a portal and written about it. The availability of self-service verification changed the dynamics of breach denial permanently.

It remains unresolved, and this page will say so until that changes. Marking a case as disputed rather than picking the more satisfying version of it is the only honest option when the evidence stops where this evidence stops.

What to do if you were a user

  1. Lock your Aadhaar biometrics. UIDAI provides biometric locking through its portal and the mAadhaar app. It blocks authentication attempts using your biometrics while locked, and it takes a couple of minutes.
  2. Use a Virtual ID instead of your Aadhaar number. A VID is a revocable 16-digit substitute that services can verify without receiving the underlying number.
  3. Check your credit report for accounts you did not open. Credit bureaus in India provide a free report annually. Identity documents leaked in 2021 are still being used to obtain credit today.
  4. Change any password you reused, and assume the phone number is on every list. The persistent cost of these exposures is not the account — it is the targeted call that already knows who you bank with.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Was MobiKwik actually breached?

This has never been publicly resolved, and this page does not resolve it either. What is documented: a large dataset was offered for sale, a searchable portal briefly allowed people to look themselves up, multiple users and journalists reported finding their own accurate records including identity documents, and the company consistently denied that its systems had been compromised. The Reserve Bank of India ordered a forensic audit; its findings were not published. Both possibilities — a breach that was denied, and a dataset assembled from other sources — remain consistent with the public record, though the reported presence of accurate KYC images is difficult to explain under the second.

What is KYC data and why is it worse than a password leak?

Know Your Customer records are the identity documents a regulated financial service must collect: in India typically Aadhaar and PAN card images, plus address proof. A password can be changed in seconds. A scanned government identity document cannot be reissued in any practical sense, and it is precisely what is needed to open accounts, obtain credit or pass verification in someone else's name.

What did the company say?

MobiKwik described the reports as false and baseless, said that a thorough investigation had found no security breach, and characterised the researcher raising the alarm in dismissive terms. It later said it would appoint a third-party forensic auditor. The tone of that initial response drew significant criticism from the Indian security community, and it is the part of this case that has had the most lasting effect on how such disclosures are handled.

What should Indian users take from this?

That the practical protection available to an individual is limited and worth using anyway: lock your Aadhaar biometrics through the UIDAI portal, use a Virtual ID rather than the Aadhaar number where a service accepts one, and check your credit report periodically for accounts you did not open. None of this undoes an exposure. It makes the exposure harder to convert into a loan in your name.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →