A cybercrime case has come to light in Noida, where cyber fraudsters allegedly hacked the server of a fintech company in Sector 65 and siphoned off more than Rs 2.42 crore. Using the company’s API portal, the accused allegedly split the amount into multiple transactions and transferred it to several bank accounts within a few hours. According to police, a total of 497 transactions were used to transfer the money to 58 accounts across 28 different banks. After the incident came to light, an FIR was registered at the Cyber Crime Police Station on the complaint of the company’s director, and police are now tracing the entire transaction chain.
The company targeted in the incident is reportedly involved in digital and financial services. Its name has been identified as Renova Paytech, headquartered in Noida. Through its digital platform, the company helps local shopkeepers provide banking and financial services. Its platform facilitates mobile and DTH recharges, electricity, water and gas bill payments, Aadhaar-based payment services, micro-ATMs and domestic money transfers. The unauthorised access to the company’s server and API system and the subsequent execution of financial transactions have made the case a subject of investigation.
In his complaint to police, company director Rajkumar said the company’s server was tampered with between around 12 noon and 8 pm on September 13. During this period, fraudsters allegedly used the API portal to transfer Rs 2,42,65,576 from the company’s account.
Instead of transferring the entire amount to a single account in one transaction, the money was divided into hundreds of small and large transactions. Police are examining the records of all these transactions to identify the final recipients of the funds and determine whether further transfers were made.
One of the key aspects of the investigation is determining how the cybercriminals gained access to the company’s system. Investigating agencies are examining whether login ID and password information was stolen, whether a security vulnerability in the API was exploited, or whether access to the server was obtained through another method.
Police have not yet reached a final conclusion regarding the method used to hack the system. The precise manner in which the attackers breached the system’s security is expected to become clear after the technical investigation is completed.
The company has also reportedly filed around 10 complaints on the National Cyber Crime Reporting Portal. Police are linking these complaints with banking transaction records as part of the investigation.
Since the money was distributed across different accounts through 497 transactions, investigators will have to verify each transaction chain separately. This may help establish which accounts were used to receive the money directly and which accounts were used for subsequent transfers.
According to police officials, the cybercrime team is collecting information about the bank accounts that received the funds. Cyber experts are also examining the company’s digital systems and server.
Server logs, API activity, login records and related digital evidence are considered important to the investigation. These records may establish which system carried out specific activities during the incident and how the unauthorised transactions were executed.
The company reportedly remained unaware of the activity for an extended period. According to the report, 497 transactions were carried out over approximately eight hours.
The transfer of money to different bank accounts may have been an attempt to conceal the activity as normal transactions, although the actual objective and method will become clear only after the police investigation. Police are also examining whether any alert or unusual activity was recorded on the company’s system.
The money trail is a key part of the investigation. Information has emerged that Rs 2.42 crore was transferred to 58 accounts.
Police are now trying to determine who holds these accounts, the purpose for which the accounts were used, and how much money was subsequently transferred or withdrawn after reaching them. In cybercrime cases, funds are often transferred through multiple levels of different accounts, making it important for investigators to obtain records at each stage.
Police are also investigating whether only external cybercriminals were involved or whether someone familiar with the company’s systems and operations may have played a role.
According to the report, the investigation will also examine the possibility of involvement by an acquaintance, but no final conclusion has been reached regarding any individual’s role. Before assigning responsibility to any employee or acquaintance, police will need to establish the person’s role on the basis of digital and financial evidence.
Renova Paytech was established in February 2024. The company uses digital platforms and software to help retail shopkeepers access banking and financial services.
Such platforms connect multiple payment and banking services through technical systems. Therefore, a breach of the server or API can affect financial transactions. Police are consequently examining not only the bank accounts involved but also the company’s technical infrastructure.
According to cyber experts, unauthorised access to a server can be obtained through several methods, including weak passwords, stolen login credentials, unsecured APIs, outdated software or suspicious links sent to employees.
For financial service providers, APIs connect different systems and payment services. A security vulnerability in an API can therefore be used by attackers to attempt unauthorised transactions. However, the actual technical method used in the Noida case will be established only after the investigation is completed.
This is not the first case in Noida involving the hacking of a server and the transfer of financial funds. Earlier, in June 2024, around Rs 16.71 crore was transferred from the server of the Sector 62 branch of Nainital Bank to different accounts through suspicious transactions.
During the investigation into that case, it emerged that access to the RTGS channel had been obtained using the bank manager’s login ID and password. Following the new incident, investigators are also examining patterns seen in earlier cybercrime cases.
The incident has brought renewed attention to the security of digital systems used by financial companies. Fintech companies rely on multiple online systems and payment networks to provide digital services to customers and retail shopkeepers.
A breach of these systems can result in direct financial losses. Server, API, login and payment gateway security therefore require continuous monitoring.
Police have registered an FIR in the case and begun the investigation. The cybercrime team is collecting information about the bank accounts and tracing the flow of the money.
Police are trying to determine who received the Rs 2.42 crore and where the funds were transferred afterwards. Technical evidence is also being collected to identify the cybercriminals who gained access to the server.
As the investigation progresses, questioning of bank account holders, examination of digital devices and transaction-related records, and forensic examination of the server may become important. If money from the alleged fraud was transferred from one account to other accounts, police will attempt to track the entire chain. No information about the arrest of any accused has emerged so far.
The case involves alleged tampering with the server and API portal of a Noida-based fintech company and the transfer of more than Rs 2.42 crore. The money was reportedly moved through 497 transactions to 58 accounts across 28 banks, while police are using digital evidence and banking records to determine who gained access to the server, where the funds were transferred and who was involved in the cyber fraud.













