A significant development that has rocked India’s fintech sector is the discovery by Gurugram Police of a huge ₹40 crore scam involving a serious technical defect in the well-known digital payments platform MobiKwik. Funds were illegally transferred into over 2,500 bank accounts as a result of the scam, which took advantage of an app bug. Authorities launched a major crackdown on financial cybercrime when they detained six of the scheme’s masterminds.
This essay will examine the police investigation, the fraud’s execution, and its wider ramifications for the security of digital payments.

Credits: Indian Express
How the Scam Unfolded: The Glitch that Cost Crores
MobiKwik, a widely used fintech platform in India, offers services ranging from retail payments and merchant transactions to bill settlements. The fraud came to light during an internal audit conducted by MobiKwik on September 12, 2025, which flagged multiple suspicious transactions.
Investigations revealed that the accused exploited a technical glitch in the app that falsely recorded failed transactions as successful ones. In effect, the system allowed payments to appear complete even when the customer’s wallet had insufficient balance or the wrong password was entered. This glitch enabled fraudulent beneficiaries—including some registered MobiKwik merchants and unknown persons—to receive illegitimate funds.
According to a police spokesperson, around 2,500 bank accounts were identified as recipients of the fraudulent transactions. To date, ₹8 crore has been recovered from these frozen accounts as authorities scrambled to contain the financial damage.
The Arrests: Six Accused in Judicial Custody
On Monday, the Gurugram Police arrested six individuals in connection with the scam. Their names have been revealed as Rehan, Mohammad Sakil, Wakar Yunus, Wasim Akram, Mohammad Amir, and Mohammad Ansar. The accused were presented before a local court and sent to judicial custody as investigations deepened.
During police interrogations, the accused admitted to deliberately exploiting the technical loophole in the MobiKwik app to carry out the fraudulent transactions. Their calculated strategy not only allowed them to siphon off significant amounts of money but also put a spotlight on vulnerabilities within fintech platforms operating at scale.
FIR and Ongoing Investigation
The case was registered at Sector 53 Police Station in Gurgaon under Sections 318(4) (cheating of valuable security) and 314 (dishonest misappropriation of property) of the Bharatiya Nyaya Sanhita (BNS). The matter was officially flagged after MobiKwik’s authorized representative filed a complaint on September 13, 2025.
A dedicated police team meticulously gathered details of the suspect beneficiaries and their bank accounts. So far, ₹8 crore has been recovered, but the police have indicated that the fraud’s total scale may grow as the investigation unfolds.
“The police are continuing their efforts to trace and apprehend other individuals who might be involved in this fraudulent scheme,” the spokesperson confirmed, hinting that more arrests and recoveries could be imminent.
Similar Past Frauds Raise Concerns Over Fintech Security
This case is not isolated. Just last month, Policybazaar Insurance Brokers Private Limited filed a complaint with the Gurugram Police, alleging a scam where impersonators forged documents, misused the company’s credentials, and duped customers. In that instance, 11 customers were tricked into paying amounts ranging from ₹8,510 to ₹35,000 to fake platforms, totaling ₹2.08 lakh in fraudulent payments.
These recurring incidents reflect a larger challenge for India’s digital finance ecosystem, where security flaws can cause massive financial damage and erode consumer trust.

Credits: Free Press Journal
The Road Ahead: Strengthening Fintech Security
This ₹40 crore scam is a clear reminder of the urgent need for stronger security measures as India’s digital payments industry continues to grow. To protect customer data and cash, fintech organizations need to invest in real-time anomaly detection technologies, rigorous code testing, and improved auditing procedures.
Although MobiKwik acted quickly to freeze the impacted accounts and notify law enforcement, the sector as a whole still has a responsibility to strengthen its defenses against such sophisticated cybercrimes.




