The encyclopedia · Legal & Compliance · Legal decision · 2021
MobiKwik met an alleged 110M-user data leak with denial and a legal threat
A researcher said ~110M MobiKwik users' data was for sale online in 2021. MobiKwik denied it and threatened legal action; the RBI ordered a forensic audit.
MobiKwik · 2021-03
What happened
MobiKwik is one of India's largest mobile-payment wallets, holding the identity documents that Indian rules require customers to submit — KYC details, Aadhaar identity numbers, card and phone data. In early March 2021 a security researcher reported that a dataset said to belong to MobiKwik, covering roughly 110 million users, had appeared for sale on a dark-web forum.
MobiKwik's response was immediate denial. On 4 March it said it had found no security lapse, and its legal team said it would take strict action against the researcher. When users began checking and reported that some of the leaked data looked genuine, the story only grew. India's computer emergency team, CERT-In, shared a sample of the data with MobiKwik; the company said the sample was not its data.
The denial did not contain the crisis. With the allegation now public and contested, the Reserve Bank of India ordered MobiKwik to undergo a forensic audit of its systems by a CERT-In-certified auditor. A payments company that handles identity data had turned a security allegation into a regulatory examination.
The case is now cited for its crisis response rather than the breach itself, which MobiKwik continued to dispute. When a company holding sensitive data is told it has leaked, denying it and threatening the messenger invites users, researchers and the regulator to verify — and the regulator's audit, not the company's denial, becomes the story.
Why it happened
- MobiKwik held the identity documents Indian rules require — KYC and Aadhaar data — so any alleged leak was automatically a high-stakes, high-attention event.
- Its first response was denial and a legal threat against the researcher, before any transparent investigation, which made the story bigger rather than smaller.
- Once users and CERT-In tested the claim, the denial looked evasive; the company lost control of the narrative to whoever could verify the data.
- Turning a security allegation into a fight with the messenger drew in the Reserve Bank of India, which ordered a forensic audit the company would now have to pass.
The lesson
When you hold sensitive data and are told it has leaked, denial and a legal threat backfire. Users, researchers and the regulator will verify it — and the audit, not the denial, becomes the story.
Aftermath
MobiKwik maintained that its systems were not breached and cooperated with the audit ordered by the RBI. The episode became a widely taught example in India of how not to handle a data-security allegation: for a company entrusted with identity data, the response to a leak claim is itself a test of trust, and a defensive denial can cost more than the original allegation.
Sources
- MobiKwik denies data breach on dark web amid user backlash on social media — Mint
- MobiKwik investigating data breach after 100M user records found online — TechCrunch
- RBI orders forensic audit of MobiKwik after alleged data breach — MediaNama
- Mobikwik data breach: RBI orders forensic audit of systems by certified auditor — DNA India
spotted an error? The club wants to know.
More like this
PNB let SWIFT run outside its core banking system — and missed $2B over six years
HP India rigged government tenders through its resellers — ₹142.37 crore CCI fine
WhatsApp's take-it-or-leave-it data policy — ₹213.14 crore CCI fine
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.