Moneyview Says API Breach Led to Rs 48.32 Crore Withdrawals
Ask Iris
Moneyview Limited, referred to as Moneyview, said a cyber incident at subsidiary Whydam Imaging Private Limited caused Rs 48.32 crore of unauthorised withdrawals between August 5 and August 7, 2025. Unknown threat actors exploited an application programming interface, or API, integrated with associated banks and bypassed the subsidiary’s authorised disbursement mechanism.
How did the Moneyview API breach lead to withdrawals?
Moneyview said unknown threat actors exploited an API connected with associated banks and initiated a substantial number of unauthorised withdrawals from Whydam Imaging Private Limited, referred to as WFPL, bank accounts. An API is a software interface that permits systems to exchange data or instructions. The withdrawals were initiated through unapproved third-party systems, circumventing WFPL’s authorised disbursement mechanism, and totalled Rs 48.32 crore over the three-day period from August 5 to August 7, 2025.
The disclosed mechanism matters because Moneyview described the incident as a bypass of the payment route authorised by WFPL, rather than as a customer credit default or ordinary portfolio-loan loss. The incident involved bank accounts and a bank-integrated API, while the transactions were routed through unapproved third-party systems. For the stated control failure not to recur, the strengthened information-technology infrastructure would need to prevent unauthorised systems from initiating transactions through the relevant bank integration.
What did the forensic investigation find about the breach?
Moneyview said an independent forensic investigation found no involvement by any WFPL or group employee or officer in the August 2025 cyber incident. On that basis, Moneyview considered the event a fraud against WFPL by outside third parties. The finding distinguishes the disclosed incident from fraud attributed to personnel within WFPL or the wider group.
Moneyview said WFPL strengthened its information-technology infrastructure using the forensic investigation’s findings and recommendations. The disclosure does not identify the individual technical changes, the controls applied to the API, or changes to the associated-bank integrations. The reported remediation is therefore a stated response to the investigation, while the scope and operation of the revised controls are not disclosed in the financial-statement note.
How much has Moneyview recovered so far?
Moneyview disclosed Rs 2.113 crore of recovery with law-enforcement assistance by March 31, 2026, followed by an additional Rs 23.2 lakh for the three months ended June 30, 2026. Cumulative disclosed recoveries therefore reached Rs 2.345 crore through June 30, 2026. That amount equals about 4.9% of the Rs 48.32 crore of unauthorised withdrawals initially reported.
The recovery position changed between the March 31, 2026 year-end and June 30, 2026. The Rs 23.2 lakh additional recovery was about 11.0% of the Rs 2.113 crore recovered by the year-end, but the disclosed cumulative recovery remained far below the original withdrawal amount. Moneyview said further recovery efforts were under way as of June 30, 2026, so any later change in the incident’s financial effect depends on those efforts.
What authorities did Moneyview notify after the cyber incident?
Moneyview said WFPL lodged a first information report, or FIR, with law-enforcement agencies in connection with the Rs 48.32 crore incident. WFPL also informed the Reserve Bank of India and the Indian Computer Emergency Response Team, known as CERT-In, about the cyber breach. These actions were disclosed alongside the recovery of Rs 2.113 crore obtained with law-enforcement assistance by March 31, 2026.
WFPL also filed an answer claim that was pending approval, according to Moneyview’s June 30, 2026 disclosure. The source does not state the amount sought under that claim or identify the approval authority. The pending status means that the disclosed Rs 2.345 crore cumulative recovery is separate from any outcome that could arise from the answer claim.
How did Moneyview account for the API breach loss?
Moneyview recorded a Rs 46.653 crore net loss associated with the cyber incident as an exceptional item for the year ended March 31, 2026. An exceptional item is an item separately presented in the statement of profit and loss because of its nature or size. Moneyview said the Rs 46.653 crore amount included incident-related subsequent amounts, while the note did not itemise each component.
The stated consequential tax impact was Rs 11.742 crore, resulting in an exceptional loss after tax of Rs 34.911 crore for the year ended March 31, 2026. The after-tax loss should not be treated as a direct subtraction of only cash recovered from the Rs 48.32 crore gross withdrawals, because Moneyview described the pre-tax figure as including subsequent incident-related amounts. The distinction separates gross unauthorised withdrawals, recoveries and the reported accounting charge.
For the three months ended June 30, 2026, the further Rs 23.2 lakh recovery produced an exceptional gain after tax of Rs 17.4 lakh. Moneyview disclosed a Rs 5.8 lakh consequential tax impact on that recovery. The quarterly gain reverses a limited part of the earlier after-tax exceptional loss, with the extent of further reversal dependent on recoveries or the pending answer claim.
Why is the Moneyview API breach financially material?
Moneyview’s API breach disclosure establishes an exposure of Rs 48.32 crore at a subsidiary and a cumulative recovery of Rs 2.345 crore through June 30, 2026. The original withdrawal amount was about 20.6 times the cumulative recovery. This difference quantifies the remaining gap between the gross amount removed from WFPL bank accounts and cash recovered as of the latest disclosed period.
Moneyview separately disclosed another exceptional item for the year ended March 31, 2026: a Rs 160 crore one-time performance-based incentive approved for the Managing Director and Chief Executive Officer on March 3, 2026. The cyber incident has a separate reported loss, tax effect, recovery record and remediation statement. Keeping the items separate is necessary because the Rs 34.911 crore after-tax cyber loss arose from the August 2025 breach, not from executive compensation.
Conclusion
Moneyview reported that outside threat actors used a bank-integrated API and unapproved third-party systems to bypass WFPL’s authorised disbursement mechanism, producing Rs 48.32 crore of unauthorised withdrawals. The forensic investigation found no WFPL or group employee or officer involvement, while the year ended March 31, 2026 included a Rs 34.911 crore exceptional loss after tax.
The next items to watch are the further recovery efforts disclosed as under way after June 30, 2026 and the pending approval of WFPL’s answer claim. Moneyview has also said it strengthened information-technology infrastructure based on forensic findings, but later disclosures would be needed to quantify any additional recoveries or describe whether the remedial controls changed the relevant bank-integrated transaction pathway.
Frequently Asked Questions
Did your stocks survive the war?
See what broke. See what stood.
Live Q1 Earnings Tracker
