HDFC Asset Management Company disclosed a cyber incident after its IT administrator detected unusual activity on 16 May and found parts of its on-premises VMware environment inaccessible, including VPN, SFTP, and antivirus management servers. The company told the Bombay High Court that it later received an email from a threat actor calling itself Morpheus, which claimed to have exfiltrated more than 680 GB of critical data; the group subsequently listed the firm as HDFC FUND on its Tor leak site, indicating an active extortion campaign. HDFC AMC said it activated incident-response measures and notified SEBI and stock exchanges after the breach.
Court filings and reporting indicate the stolen material may include customer PII, PAN details, bank account information, investment records, employee records, and proprietary investment analysis, raising risks of identity theft, fraud, and strategic business exposure. HDFC AMC warned investors about possible SIM-swap attacks that could enable OTP interception and account takeover. On 29 May, the Bombay High Court issued an ex parte interim injunction restraining Morpheus from publishing or sharing the data and directed the Union government to seek removal or blocking of related online accounts, although the practical impact may be limited against Tor-hosted infrastructure.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
The matter was scheduled for further hearing before the Bombay High Court on June 16. This followed the interim injunction issued against Morpheus over the alleged theft and threatened disclosure of HDFC AMC data.
On June 10, Morpheus listed HDFC AMC as 'HDFC FUND' on its Tor-based leak site. The posting indicated the extortion attempt had progressed beyond a private claim to public leak-site exposure.
On May 29, the Bombay High Court issued an ex parte interim injunction restraining the Morpheus ransomware group from publishing or disclosing HDFC AMC's allegedly stolen data. The court also directed the Union government to take steps to remove, block, disable, and delete online accounts associated with the stolen information.
On May 16, HDFC AMC notified the Securities and Exchange Board of India and stock exchanges about the cybersecurity incident. This was part of the company's formal response following detection of the compromise.
Also on May 16, HDFC AMC found an email from a threat actor calling itself Morpheus claiming it had exfiltrated more than 680 GB of critical company data. The claim marked the start of an apparent data-extortion campaign tied to the intrusion.
On May 16, HDFC AMC's IT administrator detected unusual activity and found parts of the company's on-premises VMware environment inaccessible, including VPN, SFTP, and antivirus management servers. The company activated its cybersecurity response protocols after discovering the disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.