Advocate Rajat Kadyan & Associates · Gurugram

Fintech companies sit in an unusual position in cyber crime law: they are frequently the target of an attack, the reporting entity to a regulator when something goes wrong, and the named party in an FIR filed by an aggrieved customer, all inside the same incident. Ordinary criminal lawyers handle one of these at a time. A fintech needs all three managed together, on a clock that regulators and the criminal process both run on independently of each other.

This practice advises NBFCs, payment aggregators, lending apps, wallets and payment banks operating out of Gurugram and the NCR on cyber crime exposure, breach response, and the FIRs and summonses that follow a customer complaint, a data incident or a regulatory referral.

Where fintech companies face cyber crime exposure

  • Data breaches — customer KYC data, payment credentials or loan records accessed, leaked or sold, and the reporting obligations that follow
  • Account takeover and API-abuse fraud, where a compromise on the customer's side is alleged to be the platform's fault
  • Insider incidents — an employee or vendor with database access extracting or misusing customer data
  • Chargeback and payment-dispute FIRs, where a customer alleges cheating rather than pursuing the civil or RBI ombudsman route
  • Loan-app harassment complaints, where aggressive recovery practices by an in-house or outsourced collections team cross into a cyber crime or IT Act complaint
  • Mule-account and money-laundering exposure, where the platform's own rails are used to layer someone else's fraud
  • FIRs and Section 35(3) BNSS notices naming the company, its directors or its compliance officer personally
  • Vendor and third-party breach — a payment gateway, API partner or cloud vendor incident that becomes the fintech's liability under its own user agreement

The first seventy-two hours of an incident

What a fintech does in the first three days after discovering a breach or a serious fraud pattern usually decides how the following months go — with the regulator, with customers, and in any criminal proceeding that follows.

Three things run in parallel, not in sequence. First, containment and evidence preservation: logs, access records and the forensic image have to be secured before systems are patched or rebuilt, because the same records that support the incident report are what a defence relies on later if an FIR is filed. Second, the regulatory clock: CERT-In's reporting timeline for specified cyber incidents runs from the time of noticing the incident, not from when the investigation concludes, and RBI-regulated entities carry separate incident-reporting obligations under RBI's cyber security framework. Missing either deadline is itself a compliance failure, independent of the underlying incident. Third, what is said and to whom — customer communications, breach notifications and any statement given to police or a regulator should go through legal review before they go out, because they are read back later by all three audiences.

Regulatory reporting — CERT-In, RBI and sectoral obligations

Fintech entities carry reporting duties that ordinary businesses do not. Depending on the entity's licence and the nature of the incident, this can include:

  • Reporting specified cyber incidents to CERT-In within the prescribed window
  • Incident reporting to the RBI where the entity is a bank, NBFC, payment aggregator or payment system operator, under RBI's cyber security and IT governance framework
  • Notification obligations to affected individuals and, where applicable, to the Data Protection Board under the Digital Personal Data Protection Act, 2023, once its breach-notification provisions are in force
  • Suspicious transaction reporting to the Financial Intelligence Unit where the incident touches money laundering or a mule-account pattern

These obligations sit alongside, not instead of, any criminal complaint the company chooses to file or is named in. Advice at this stage is about sequencing all of it correctly — what gets reported where, and in what order — so that a good-faith disclosure does not later read as an admission in a criminal proceeding, and a criminal complaint does not undercut the regulatory position.

When the company is the complainant

Where the fintech itself has been defrauded or attacked — a coordinated account-takeover ring, a vendor employee who exfiltrated data, an organised loan-fraud pattern — a properly drafted complaint under the IT Act and the Bharatiya Nyaya Sanhita, filed with the right documentation, gets investigated faster and holds up better if it later needs to support a freezing order or a civil recovery. See cyber crime cases generally and, where the fraud has an organised or financial-syndicate dimension, EOW and economic offences.

When the company or its officers are named

A customer who loses money to a scam that used the platform, or whose data appears in a breach, sometimes files an FIR naming the company and its directors rather than pursuing the civil, RBI ombudsman or arbitration route the user agreement actually provides for. Where recovery-agent conduct is at issue, a loan-app harassment complaint can similarly draw in the company alongside the individual agent.

The first response is the same discipline as any cyber FIR: read the sections actually invoked before responding to anything, do not let an employee give a statement to police without advice, and assess early whether the correct answer is a reply to the notice, an anticipatory bail application for named individuals, or a quashing petition under Section 528 BNSS where the FIR is, on its face, a contractual or regulatory dispute dressed as a criminal complaint. See bail and anticipatory bail for how that timeline usually runs.

ED and PMLA exposure for payment platforms

Where a fintech's rails are used to move proceeds of someone else's fraud — a common pattern with mule accounts and layered UPI transactions — the Enforcement Directorate can issue Section 50 PMLA summons to the company's compliance or nodal officer even where the company itself is not the target of investigation. Responding to a summons of this kind, and the distinction between cooperating as a reporting entity and being drawn in as a suspect, is covered at ED and PMLA matters and money laundering defence.

Frozen accounts and lien-marked settlement flows

A fintech's own settlement or nodal account can be lien-marked on a cyber cell or NCRP-linked reference tied to a single bad actor on the platform, freezing funds that belong to many unrelated customers or merchants. Release runs through the investigating officer, the Magistrate or the High Court depending on the origin of the freeze, and partial release to protect uninvolved customers' funds is often achievable ahead of full release. See frozen bank account release.

Vendor and API-partner incidents

Many fintech breaches originate outside the company's own systems — a payment gateway, a KYC verification vendor, a cloud provider. The legal exposure does not automatically follow the technical cause: user agreements, vendor contracts and RBI's outsourcing guidelines usually determine who bears reporting and liability obligations toward the end customer, and that allocation needs to be worked out early, in parallel with the incident response, not after.

Retainer and advisory work

Beyond incident response, this practice advises fintech compliance and legal teams on an ongoing basis — reviewing incident-response and breach-notification playbooks against current CERT-In and RBI requirements, advising on recovery-agent and collections-conduct policy to keep it inside the IT Act and RBI's fair-practice norms, and acting as the point of contact for law-enforcement liaison so that police requests for customer data are handled through a consistent, defensible process rather than case by case.

What to bring to a first consultation

For an incident: the timeline of discovery, any forensic or vendor report so far, the FIR or notice if one has already been received, and the relevant clauses of the user agreement or vendor contract. For an advisory engagement: current incident-response and data-retention policies, and the entity's licence category (NBFC, PA, PPI issuer, etc.), since the reporting obligations differ by licence.

Frequently asked questions

How quickly must a fintech report a data breach in India?

CERT-In's timeline for specified cyber incidents runs from when the incident is noticed, and RBI-regulated entities have separate, often shorter, reporting windows under RBI's cyber security framework. The exact obligation depends on the entity's licence and the nature of the incident, which is why the reporting pathway should be confirmed on day one, not after the internal investigation is complete.

Can our directors be personally named in a cyber crime FIR over a customer complaint?

Yes, this happens, particularly where a customer alleges the company knowingly permitted fraud on its platform or was negligent with data. Whether that exposure is genuine or is a contractual dispute mislabelled as a crime is the first thing to assess, and it shapes whether the right response is a reply to notice, anticipatory bail, or a quashing petition.

Should we report an incident to police before or after notifying the regulator?

There is no single correct order — it depends on the licence category and the nature of the incident — but the sequencing should be decided deliberately and in advance, because a disclosure made to one authority is often visible to, or relevant for, the others. This is coordinated as part of incident response, not left to whichever team acts first.

A fraud ring used our platform to launder money from an unrelated scam. Are we at risk?

Being used as a conduit does not by itself make the platform liable, but a Section 50 PMLA summons to a compliance or nodal officer is a realistic possibility once a mule-account pattern is traced back to the platform. How that summons is answered — as a cooperating reporting entity rather than as a suspect — matters considerably, and is best handled with counsel from the first notice.

Our settlement account has been frozen because of one bad actor. Can we get it released quickly for our other customers?

Often, yes, at least partially. Courts and investigating officers are generally receptive to releasing funds that demonstrably belong to unconnected customers or merchants, provided the request is backed by clear account-level documentation showing whose money is whose.

Do you advise on compliance, or only handle litigation after something has gone wrong?

Both. Retainer advisory work — reviewing breach-response playbooks, collections-conduct policy and law-enforcement liaison processes — sits alongside representation once an incident, FIR or regulatory notice is already in hand.

For a free first consultation, call +91 82954 13475 at any hour, or send the details of your matter.

Call +91 82954 13475 Free case review

Free consultation · 24×7

Every hour matters after an FIR.

Call WhatsApp Free review