Breach tracker

Breach report

HDFC AMC reports cyber incident; Bombay HC bars use of data Morpheus claims to hold

ConfirmedDisclosed Updated IndiaFinanceBy Vivek Kumar
Records UnknownCause UnknownAttributed / claimed Morpheus (claimed)
Conceptual illustration: An investment-fund portfolio folder, glass rupee symbol and secure workstation under investigation. Headline: HDFC AMC CYBER INCIDENT.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The fund house told exchanges on 18 May of an incident found two days earlier. The Morpheus ransomware group claims 680 GB; the Bombay High Court restrained its publication.

What happened

HDFC Asset Management Company, which runs HDFC Mutual Fund, told BSE and NSE on 18 May 2026 that on 16 May it received a message from an anonymous source claiming access to parts of its IT infrastructure. The company said it activated containment and incident response, hired a specialist firm, and that its early assessment showed the incident was unlikely to disrupt operations.

Confirmed vs. claimed

Confirmed: the incident and the court order. ETV Bharat reported that the Bombay High Court granted an interim injunction on 29 May restraining the ransomware group Morpheus from distributing or disclosing the data, and directed the Union government to block accounts sharing it. The same report says the company had informed SEBI.

Claimed: Morpheus says it took more than 680 GB. According to the court report, the data allegedly includes investors' names, addresses, ID documents, PAN, bank details and holdings. HDFC AMC's exchange filing did not confirm any investor data loss, and the contents have not been independently verified.

Who is affected

Potentially HDFC Mutual Fund investors. The company has not said how many, if any, were affected.

What to do

  • Check your folios through the official HDFC Mutual Fund app or CAMS/KFintech statements, not links in messages.
  • Expect calls or emails quoting your folio, PAN or holdings and pushing "KYC updates", redemptions or trading tips. Hang up.
  • Never share OTPs; bank and fund staff do not need them.
  • If your PAN may be exposed, check your credit report and Form 26AS; see our Aadhaar and PAN leak guide.
  • If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.

Sources

More breaches in India