Trending

CERT-In Warns NBFCs and Fintech Firms of Cyberattacks Targeting Fintech Payment Infrastructure

The advisory flags attacks exploiting payment and disbursement APIs to facilitate unauthorised fund transfers, putting digital lending platforms, payment service providers and wallet operators on alert.

NDM News Network

India’s cybersecurity agency, the Indian Computer Emergency Response Team (CERT-In), has warned non-banking financial companies (NBFCs), fintech firms and digital payment service providers about cyberattack campaigns targeting payment and disbursement application programming interfaces (APIs). The attacks reportedly exploit these interfaces to carry out unauthorised fund transfers, highlighting security risks across India’s expanding digital financial ecosystem.

According to the advisory issued on October 9, 2026, the warning covers NBFCs, digital lending platforms, payment service providers and wallet operators. These organisations rely on APIs to connect applications, process transactions and facilitate the movement of funds, making the security of these interfaces critical to financial operations.

The warning underscores the need for financial technology businesses to strengthen API security and review the controls protecting payment processing and disbursement systems.

Payment and Disbursement APIs Under the Scanner

APIs enable different software systems to communicate and exchange information. In financial services, they support functions such as payment initiation, loan disbursement, account integration and digital wallet transactions.

However, poorly secured APIs or weaknesses in access controls can expose financial systems to misuse. If attackers exploit these weaknesses, they may attempt to initiate transactions without proper authorisation or manipulate payment workflows.

For NBFCs and digital lending platforms, disbursement APIs are particularly important because they facilitate the transfer of approved loan amounts. Payment service providers and wallet operators also depend on secure interfaces to process transactions and maintain the integrity of their platforms.

The CERT-In warning puts the security of these connected systems in focus, particularly as financial services increasingly depend on automated, API-driven operations.

Why Fintech Firms Need Stronger API Security

API-related risks can extend beyond individual applications because these interfaces often connect multiple services, systems and third-party platforms. A weakness in one integration may create opportunities for unauthorised access or transaction abuse elsewhere in the payment chain.

Financial organisations need to ensure that sensitive operations are accessible only to authorised users and systems. This includes reviewing authentication mechanisms, enforcing transaction-level authorisation and monitoring API activity for unusual patterns.

Businesses should also assess whether their payment and disbursement workflows have adequate safeguards against unauthorised requests, repeated transaction attempts and suspicious changes in transaction behaviour.

Regular security assessments, timely patching and continuous monitoring can help organisations identify weaknesses before they are exploited. Third-party integrations also require scrutiny, as external services may form part of critical payment workflows.

Digital Financial Services Face Growing Security Demands

India’s digital finance ecosystem includes a wide range of businesses, from established NBFCs and payment providers to digital lenders and wallet operators. As these organisations expand their services and integrate more systems, securing APIs becomes an essential part of protecting transactions and customer trust.

An incident involving unauthorised fund transfers can have financial and operational consequences, potentially requiring investigations, transaction reviews and additional security measures. It can also raise concerns about the reliability of digital payment infrastructure.

For financial institutions, API security therefore needs to be treated as an operational priority rather than a standalone technical requirement. Security teams must work closely with product, engineering and payment operations teams to ensure that controls remain effective as services evolve.

CERT-In’s advisory serves as a reminder for NBFCs and fintech businesses to review their exposure to API-based attacks and strengthen protections around payment and disbursement systems. With digital financial services becoming increasingly interconnected, effective access controls, transaction monitoring and proactive vulnerability management remain critical to reducing the risk of unauthorised fund transfers.

𝐒𝐭𝐚𝐲 𝐢𝐧𝐟𝐨𝐫𝐦𝐞𝐝 𝐰𝐢𝐭𝐡 𝐨𝐮𝐫 𝐥𝐚𝐭𝐞𝐬𝐭 𝐮𝐩𝐝𝐚𝐭𝐞𝐬 𝐛𝐲 𝐣𝐨𝐢𝐧𝐢𝐧𝐠 𝐭𝐡𝐞 WhatsApp Channel now! 👈📲

𝑭𝒐𝒍𝒍𝒐𝒘 𝑶𝒖𝒓 𝑺𝒐𝒄𝒊𝒂𝒍 𝑴𝒆𝒅𝒊𝒂 𝑷𝒂𝒈𝒆𝐬 👉 Facebook, LinkedIn, Twitter, Instagram