Language Settings
Select Website Language

GDPR Compliance

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you accept our use of cookies, Privacy Policy, and Terms of Service.

CERT-In Warns of Cyberattacks Targeting India's Payment APIs

3 hours ago

8

0

CERT-In warns Indian fintech and lending firms of cyberattacks exploiting payment APIs and stolen credentials to enable unauthorised transfers.

By News National Editorial Team

NEW DELHI, October 12, 2026: India's national cybersecurity agency has issued a critical warning about cyberattack campaigns targeting non-banking financial companies, digital lending platforms, fintech businesses, payment service providers and digital wallet operators. The attacks exploit weaknesses in internet-facing applications and payment application programming interfaces (APIs), potentially allowing criminals to initiate unauthorised fund transfers.

The Indian Computer Emergency Response Team (CERT-In) published Advisory CIAD-2026-0046 on October 9. It describes campaigns in which attackers compromise exposed applications, steal payment gateway or partner-bank API credentials and use those credentials to call disbursement or transfer functions directly.

How attackers exploit payment systems

According to CERT-In, some attacks exploit deprecated or unauthenticated APIs, unrestricted file-upload functions, outdated middleware and credentials stored in source code or configuration files. Other identified weaknesses include long-lived static API tokens and remote services without multi-factor authentication.

After gaining access, attackers may obtain credentials used by payment aggregators, banks or lending partners. They can then attempt to initiate transfers from within infrastructure that the financial institution already trusts.

The agency said fraudulent transactions observed in these campaigns included dummy reference identifiers and transfers to attacker-controlled mule accounts. It also reported cases involving multiple high-value transactions and attempts to remove logs or tamper with endpoint security tools.

CERT-In noted possible use of AI-assisted offensive tools. That observation should not be interpreted as confirmation that artificial intelligence was used in every attack.

Why the issue matters for Indian fintech

Digital lenders and payment companies depend on connected systems to approve transactions, verify customers, check beneficiaries and process disbursements. If a transfer API accepts a valid credential without independently verifying the transaction's approval status, an attacker may exploit the gap between the application and the payment system.

A successful compromise could result in financial losses, customer disputes, regulatory scrutiny and service disruption. However, the advisory does not establish that every organisation in the affected sectors has been breached, nor does it provide a single nationwide loss figure for the campaigns.

Security measures recommended

CERT-In recommends multi-factor authentication for payment platforms, administrative portals, APIs and remote access. It also advises organisations to maintain a complete inventory of active APIs and formally disable services that are no longer required.

Financial institutions should ensure that every payout is checked against an approved transaction record. Payment-stage controls should enforce transaction limits and beneficiary verification rather than relying solely on checks performed earlier in an application workflow.

Other measures include secure management and rotation of API credentials, restricted outbound connections from production systems, centralised log retention, endpoint detection with tamper protection and regular API security testing. Companies should also reconcile payment records with bank and aggregator statements to identify discrepancies quickly.

If suspicious transfers or compromised credentials are detected, the agency advises organisations to disable affected accounts, suspend vulnerable APIs where necessary, preserve forensic evidence and report relevant incidents to CERT-In/CSIRT-Fin.

What businesses should do now

Fintech firms should review their payment APIs, privileged access and transaction-validation controls without waiting for a confirmed breach. Banks and financial institutions should also assess the security of third-party services connected to their systems.

The October 9 advisory is a warning about observed attack campaigns, not proof that all Indian payment systems are compromised. Its practical message is that payment security must extend beyond the customer-facing application to the APIs and credentials that actually authorise transfers.

Sources:

Click here to Read More
Previous Article
EU and China Discuss Electric Vehicle Trade and Tariff Changes
Next Article
CERT-In Warns of MikroTik RouterOS SSH Vulnerability

Related Cyber Security Updates:

Are you sure? You want to delete this comment..! Remove Cancel

Comments (0)

    Leave a comment