LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Moneycontrol Data Breach (2017)

CRITICAL severityConfirmedHow we verify

Moneycontrol Data Breach (2017): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 7, 2017
Moneycontrol Data Breach (2017)

Reported September 7, 2017. Approximately 763K people affected.

CRITICAL
Severity
763K
People affected
5
Data types exposed
September 7, 2017
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Moneycontrol Data Breach (2017) (reported September 7, 2017) exposed Email addresses, Genders, Geographic locations and Passwords belonging to roughly 763K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Plaintext passwords exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Moneycontrol Data Breach (2017) breach?
763K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Data incidents involving online financial platforms continue to surface years after the underlying events, reflecting the extended lifespan of stolen records in underground markets. The Moneycontrol case centers on a data set created in September 2017 that later appeared for sale in April 2021, containing records for 763,000 unique email addresses along with additional user details. Moneycontrol has described the material as an old data set, while the exact timing and circumstances of the original compromise remain undisclosed in public reporting.

Breaking down the breach

The records were first noted publicly when they were offered for sale in April 2021. The file itself carries a creation date of September 2017. The reported scale is 763,000 unique email addresses, presented as a subset of a larger claimed collection. Moneycontrol has not confirmed the method or date of the initial access. No further technical details about the intrusion have been released by the company or independent investigators.

How a breach like this happens

Incidents affecting web platforms often begin with the exploitation of application vulnerabilities, compromised administrator credentials, or misconfigured databases that allow unauthorized extraction of user tables. Once obtained, the data may remain in the possession of the initial actors for months or years before being packaged and offered on forums or marketplaces. Plain-text passwords in the data set indicate that the stored credentials were not protected by contemporary hashing standards at the time of the event.

About Moneycontrol

Moneycontrol operates as an Indian online financial information and services platform, providing market data, portfolio tools, and user accounts for tracking investments. Organizations in this sector routinely collect account identifiers, contact information, and authentication credentials to support registered users. A breach at such a service can expose details that intersect with users' broader financial activities, increasing the potential for targeted follow-on activity.

The information in question

The exposed fields reported in connection with the 763,000 records include email addresses, genders, geographic locations, phone numbers, and passwords stored in plain text. Dates of birth are mentioned in some summaries of the same data offering. The precise scope of any larger collection and the full list of fields remain unconfirmed beyond these categories.

Why it matters

Plain-text passwords combined with contact details allow straightforward attempts at account takeover on other services where users may have reused credentials. Geographic and demographic fields can support more precise phishing or social-engineering campaigns. For the organization, the incident underscores the long-term reputational and operational costs that arise when older data sets reappear in public circulation.

If your data was in this breach

Individuals can begin by changing passwords on Moneycontrol and any other accounts that share the same credentials. Enabling multi-factor authentication where available reduces the value of exposed passwords. Monitoring financial accounts and email for unusual activity provides an early indicator of misuse.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

CompanyMoneycontrol security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Moneycontrol’s full breach history →

More recent breaches

The Fly on the Wall Data Breach (2017)December 31, 2017HoundDawgs Data Breach (2017)December 30, 2017Lyrics Mania Data Breach (2017)December 21, 20172fast4u Data Breach (2017)December 20, 2017

Latest breaches

Read GalaxyWarden’s full analysis of the Moneycontrol Data Breach (2017) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram