No suits.
No fancy vaults.
Just 2.5 hours, 656 bank accounts, and a vulnerable API.
What Happened?
A Bengaluru-based NBFC got digitally wiped out to the tune of ₹47 crore ($5.6 million USD) in just 2.5 hours.
The masterminds?
Sanjay Patel
Plumber from Udaipur.
Ismail Rasheed Attar
Digital marketer from Belagavi.
Backed By
Hackers in Hong Kong and operatives in Dubai.
The crew used flaws in the company’s API, the digital plumbing behind fintech apps, to siphon cash into 650+ mule accounts across India.
The Kicker?
The company’s core systems weren’t even breached.
They just left the API door unlocked… and the bad guys walked right in.
How It Went Down
- Hackers rented high-speed servers in Dubai
- Launched 1,782 unauthorized transactions using foreign IPs
- Funneled money via fake firms, mule accounts, and shell companies
- The plumber even received ₹27.39 lakh straight to his bank
By the time internal audits caught on, the loot had already scattered across states, with digital footprints in Hong Kong, Lithuania, and Hyderabad.
Bengaluru’s Police Chief called it a “precision strike” by an international syndicate.
They didn’t hack the vault.
They rerouted the pipes.
Why This Matters
Fintechs are growing fast.
But their APIs?
Not so much.
These digital connectors are often:
- Poorly monitored
- Lacking anomaly detection
- Never security-audited after launch
Think of APIs as the loading docks of your digital business.
Great for speed.
Terrible if you leave the gates wide open.
And guess who’s noticing?
Not just coders.
Cybercrime syndicates.
The plumber in this case?
Just the delivery guy for a global hacking operation.
The Bigger Lesson
Attackers are increasingly targeting the business logic layer.
Not firewalls.
Not endpoints.
Not necessarily databases.
Just the systems that move money.
When APIs are trusted by default, attackers don’t need sophisticated exploits.
They simply abuse the trust already built into the application.
TL;DR
- ₹47 crore ($5.6 million USD) stolen in 2.5 hours through API abuse
- Masterminds included a plumber, a digital marketer, and foreign cybercriminals
- More than 650 mule accounts were used to disperse stolen funds
- The attackers exploited API weaknesses rather than breaching core infrastructure
- The case highlights why API security is becoming one of fintech’s biggest risks
The Cybernara View
At Cybernara, we call this a code red for fintech APIs.
Because it’s not just your backend you need to secure.
It’s the connectors too.
We help clients:
- Audit their APIs
- Add behavioral analytics to spot abuse
- Build systems that don’t trust blindly
- Implement Zero Trust principles across critical services
And yeah, maybe don’t let your API become the new ATM for global crime rings.
Want to Assess Your API Security?
If you’d like help navigating this or improving your security posture, reply to this email or reach out to Cybernara.








