WFPL cyberattack caused Rs 48.32 crore unauthorised debits
Ask Iris
WFPL said attackers exploited application programming interface, or API, vulnerabilities with banking partners between August 5, 2025 and August 7, 2025, causing Rs 48.32 crore of unauthorised debits. WFPL recorded a Rs 34.911 crore exceptional loss net of tax in Fiscal 2026 and had recovered Rs 2.345 crore by June 30, 2026.
What happened in the WFPL cyberattack?
WFPL said attackers exploited vulnerabilities in APIs connected with its banking partners and exposed credentials to initiate unauthorised transactions from outside WFPL’s infrastructure. An API is a software interface that allows separate systems to exchange data and execute functions. The incident took place over the three days from August 5, 2025 to August 7, 2025 and involved debits from WFPL’s bank account.
The unauthorised transactions aggregated Rs 48.32 crore. WFPL’s disclosure does not identify the banking partners involved, the number of individual transactions, the credentials exposed or the precise vulnerability that attackers used. It does state that WFPL integrates its information-technology systems with third-party partners through API architecture to support a large number of transactions on its platform.
WFPL notified the Reserve Bank of India, or RBI, and CERT-In on August 8, 2025 in accordance with applicable requirements. It also reported the incident to the Indian Cybercrime Coordination Centre, or I4C, and filed an FIR with the Cyber Crime Police Station in Bengaluru on August 9, 2025 following I4C’s recommendation. WFPL said it engaged a third party to conduct a detailed forensic investigation and an information-technology security audit.
How large was the WFPL cyberattack loss and recovery?
WFPL recorded a Rs 34.911 crore exceptional item loss, net of tax, in Fiscal 2026 as a result of the cyber incident. That accounting loss was lower than the Rs 48.32 crore gross value of unauthorised debits, and the disclosure treats the loss as an exceptional item rather than an ordinary operating expense. The source does not provide a reconciliation between the gross debits and the net-of-tax exceptional loss.
WFPL had recovered Rs 2.345 crore as of June 30, 2026 with assistance from law-enforcement agencies, while further recovery efforts remained ongoing. The recovered amount was Rs 45.975 crore below the gross unauthorised debits and Rs 32.566 crore below the Fiscal 2026 exceptional loss net of tax. Those differences show that recovery had not fully offset either disclosed measure by June 30, 2026.
During the three-month period ended June 30, 2026, WFPL recognised an exceptional gain of Rs 23.2 lakh relating to partial recovery of losses from the incident. That quarterly gain differs from the Rs 2.345 crore total recovered by June 30, 2026 because the disclosure does not say that all recoveries were recognised in the same period or through the same accounting treatment.
Why did banking-partner API access create this exposure?
WFPL’s banking-partner API connections created exposure because the August 2025 attack used vulnerabilities at those interfaces to initiate transactions outside WFPL’s infrastructure. WFPL said that unauthorised data revision by third parties, a failure to maintain data integrity or changes to a partner’s API architecture could materially affect or interrupt operations. The Rs 48.32 crore incident is the specific disclosed example of the risk arising from third-party system integration.
WFPL stores and processes personal, transactional, financial and other sensitive user data, and makes certain personal information available to third parties, including financial partners, to carry out obligations under its arrangements. WFPL said it uses contractual safeguards, confidentiality obligations and need-to-know access controls, but cannot assure that these protections will prevent a third-party confidentiality breach. The company also cited cyber-attacks, hacking and ransomware as possible causes of data loss or leakage from third-party cloud services.
WFPL also uses one service provider to host applications and systems including its app, loan-management system and risk-assessment engine. Its stated disaster-recovery process has a four-hour recovery time objective and a 30-minute recovery point objective for critical systems. WFPL said a prolonged outage at that sole cloud provider could disrupt loan-facilitation operations and lending, delay loan processing and disbursement, and restrict access to borrower data.
What controls did WFPL implement after the cyberattack?
WFPL said it introduced mandatory internet-protocol, or IP, whitelisting with banking partners after the August 2025 attack. IP whitelisting requires banking partners to process transactions only from pre-authorised IP addresses. The measure is intended to restrict the network origins from which transaction requests can be accepted.
WFPL also implemented periodic rotation of critical keys, enhanced system logging and stronger monitoring for unusual activity patterns. Key rotation changes critical access material at set intervals, while logs and monitoring can help identify anomalous activity. WFPL said these measures followed the findings and recommendations of the third-party forensic investigation and security audit.
Before and after the incident, WFPL described a multi-layered network-security architecture comprising segmentation, firewalls, virtual private networks and traffic controls. It also cited security audits and assessments, International Organization for Standardization certifications and Payment Card Industry Data Security Standard certification. WFPL nevertheless said it cannot assure that it will prevent all future attacks or effectively mitigate every threat if an attack occurs.
What remains unresolved after the WFPL cyberattack?
The unresolved financial issue is whether recovery will rise beyond the Rs 2.345 crore recovered by June 30, 2026. WFPL said law-enforcement-assisted recovery efforts were continuing, but did not provide a target recovery amount, expected timeline or expected accounting treatment for additional recoveries. The remaining outcome therefore depends on the ongoing investigation and recovery process.
The unresolved operational issue is whether the new controls will remain effective across WFPL’s external API connections. WFPL said third-party partners could revise data without authorisation, fail to preserve data integrity or change API architecture, any of which could affect platform operations. Except for the disclosed cyber incident, WFPL said no other technical violations had materially adversely affected its business and operations in the three-month periods ended June 30, 2026 and 2025, or Fiscal 2026, Fiscal 2025 and Fiscal 2024.
Conclusion
WFPL’s disclosure shows that an attack exploiting banking-partner APIs produced Rs 48.32 crore in unauthorised debits during August 5-7, 2025 and a Rs 34.911 crore exceptional loss net of tax in Fiscal 2026. The incident demonstrates that transaction and credential risks can arise through third-party API architecture even when attackers operate outside WFPL’s own infrastructure.
The next disclosed measures to watch are recovery progress beyond Rs 2.345 crore as of June 30, 2026 and the operation of mandatory IP whitelisting, critical-key rotation, enhanced logging and unusual-activity monitoring. WFPL has stated that recovery efforts are ongoing and that it cannot assure prevention or mitigation of every future cyberattack, leaving both recovery and control effectiveness unresolved.
Frequently Asked Questions
Did your stocks survive the war?
See what broke. See what stood.
Live Q1 Earnings Tracker
