
HDFC Asset Management Company has confirmed a cybersecurity incident affecting parts of its IT systems. According to reports from Mint, the breach originated on 16 May 2026 when the company received communication from an anonymous source claiming access to portions of its IT infrastructure. HDFC AMC activated its internal containment and incident response protocols and engaged a specialist firm to assess the extent of potential impact. The fund house, which manages approximately ₹7.6 lakh crore in assets, making it India's second-largest AMC by AUM, wrote directly to investors on 12 June 2026 to share precautionary steps.
HDFC AMC has reported the breach to all relevant financial regulators and obtained judicial protection over the affected data. As reported by Mint, the company notified SEBI, CERT-In, NSE, and BSE within the required six-hour timeline under SEBI's Cybersecurity and Cyber Resilience Framework for AMCs introduced in June 2023. The fund house also obtained an order from the Hon'ble Bombay High Court restraining anyone from publishing, circulating, or misusing the affected data. The company confirmed that its systems have been secured and the investigation is ongoing.
HDFC AMC has explicitly stated that investor funds and portfolio values remain completely unaffected by the breach. According to reports from Mint, the company confirmed that "your investments, units, and the value of your holdings have not been affected. This incident relates to data, not to your money or your portfolio." The structural architecture of India's mutual fund system ensures units are stored in electronic form at depositories CDSL or NSDL, with CAMS or KFintech maintaining the unit registry independently. Any redemption requires authentication through registered mobile numbers, email OTP, or MPIN, all operating independently of the AMC's internal systems.
The breach has potentially exposed investor identity and financial data, including PAN, bank account details, address, investment history, SIP amounts, and nominee information. As reported by Mint, this combination constitutes a sensitive data profile sufficient to facilitate SIM-swap fraud, targeted phishing, or account-takeover attempts. HDFC AMC advises investors to reset account credentials using strong passwords, avoid clicking unknown links or attachments, and watch for unexpected mobile signal loss or inability to receive calls and SMS, which could indicate SIM-swap attempts.
The incident arrives amid a sharp acceleration in financial cybercrime across India, with high-value cyber fraud cases surging more than fourfold in fiscal 2024, generating losses of approximately $20 million. According to official data cited in a Reuters report, incidents involving amounts of ₹1 lakh or more climbed to 29,082 from 6,699 in the preceding year. SEBI's June 2023 Cybersecurity and Cyber Resilience Framework places substantial obligations on AMCs above threshold AUM levels, including designated Chief Information Security Officer, mandatory annual audits, and business continuity plans tested annually.