Major Cyber Fraud: Hacker Breaches Aditya Birla Capital App, Steals ₹1.95 Crore in Digital Gold

A shocking incident of cyber fraud has emerged from Mumbai's Prabhadevi area, where an unidentified hacker infiltrated the Aditya Birla Capital Digital Limited's ABCD app. The hacker made unauthorized technical modifications and sold digital gold worth approximately ₹1.95 crore from the accounts of 435 customers, transferring the proceeds into various personal bank accounts.
The fraud was uncovered when several affected customers contacted the company's call center, reporting that their purchased digital gold had been sold without their consent. In response, Aditya Birla Capital filed a First Information Report (FIR) with the Central Region Cyber Police in Mumbai, prompting a comprehensive investigation by the cyber cell.


According to the Cyber Cell, the complaint was lodged by Ravindra Rajmal Chaudhary, the Head of Fraud Risk Management at Aditya Birla Capital Digital Limited. The company facilitates the buying and selling of digital gold through MMTC-PAMP, a government-authorized entity, with all transactions processed via Razorpay through the ABCD mobile application, which offers various financial services, including digital gold, silver, UPI, mutual funds, and insurance.
On June 9, the company's technical team discovered that an unidentified individual had hacked into the application programming interface (API) connecting the ABCD app to the company's server at digital.adityabirlacapital.com. The hacker manipulated the app's transaction protocols, successfully selling digital gold from 435 user accounts while bypassing the mandatory one-time password (OTP) verification process.


The fraud was brought to light when multiple users reported unauthorized sales of their digital gold. Following an internal review, the technology team suspended the digital gold selling feature. An investigation by the information security team confirmed that on June 9, digital gold belonging to 435 customers had been illicitly sold. The company has provided a list of affected users and detailed logs to the Cyber Cell, which is now conducting a thorough technical investigation into the breach. Further actions are underway.
- Other (43)
- Ransomware (153)
- Events and News (27)
- Features (45)
- Security (484)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (50)
- Malware Alerts (230)
- Cyber Attack (294)
- Data Backup (13)
- Data Breach (125)
- Phishing (164)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (70)
- Android Security (76)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (70)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (24)
- Uber (1)
- YouTube (1)
- Trojan (3)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (7)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (35)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (23)