Breach report
HDFC AMC reports cyber incident; Bombay HC bars use of data Morpheus claims to hold

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The fund house told exchanges on 18 May of an incident found two days earlier. The Morpheus ransomware group claims 680 GB; the Bombay High Court restrained its publication.
What happened
HDFC Asset Management Company, which runs HDFC Mutual Fund, told BSE and NSE on 18 May 2026 that on 16 May it received a message from an anonymous source claiming access to parts of its IT infrastructure. The company said it activated containment and incident response, hired a specialist firm, and that its early assessment showed the incident was unlikely to disrupt operations.
Confirmed vs. claimed
Confirmed: the incident and the court order. ETV Bharat reported that the Bombay High Court granted an interim injunction on 29 May restraining the ransomware group Morpheus from distributing or disclosing the data, and directed the Union government to block accounts sharing it. The same report says the company had informed SEBI.
Claimed: Morpheus says it took more than 680 GB. According to the court report, the data allegedly includes investors' names, addresses, ID documents, PAN, bank details and holdings. HDFC AMC's exchange filing did not confirm any investor data loss, and the contents have not been independently verified.
Who is affected
Potentially HDFC Mutual Fund investors. The company has not said how many, if any, were affected.
What to do
- Check your folios through the official HDFC Mutual Fund app or CAMS/KFintech statements, not links in messages.
- Expect calls or emails quoting your folio, PAN or holdings and pushing "KYC updates", redemptions or trading tips. Hang up.
- Never share OTPs; bank and fund staff do not need them.
- If your PAN may be exposed, check your credit report and Form 26AS; see our Aadhaar and PAN leak guide.
- If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
Sources
More breaches in India
- Dodo Payments — 17 Aug 2026
- Bank of Baroda — 28 Jul 2026
- Reliance Infrastructure (Kudankulam project data) — 16 Jul 2026
- UMANG (MeitY government services app) — 14 Jul 2026
- National Testing Agency (CUET-UG 2026 candidate data) — 08 Jul 2026