Skip to main content
Mallory
Back to intelligence
breach-disclosure-notificationunderground-data-leakfinancial-sector-threatoperational-disruption

Morpheus Claims 680 GB Theft From HDFC AMC After VMware Systems Disruption

Updated 2d agoFirst seen Jun 14, 20262 sources

HDFC Asset Management Company disclosed a cyber incident after its IT administrator detected unusual activity on 16 May and found parts of its on-premises VMware environment inaccessible, including VPN, SFTP, and antivirus management servers. The company told the Bombay High Court that it later received an email from a threat actor calling itself Morpheus, which claimed to have exfiltrated more than 680 GB of critical data; the group subsequently listed the firm as HDFC FUND on its Tor leak site, indicating an active extortion campaign. HDFC AMC said it activated incident-response measures and notified SEBI and stock exchanges after the breach.

Court filings and reporting indicate the stolen material may include customer PII, PAN details, bank account information, investment records, employee records, and proprietary investment analysis, raising risks of identity theft, fraud, and strategic business exposure. HDFC AMC warned investors about possible SIM-swap attacks that could enable OTP interception and account takeover. On 29 May, the Bombay High Court issued an ex parte interim injunction restraining Morpheus from publishing or sharing the data and directed the Union government to seek removal or blocking of related online accounts, although the practical impact may be limited against Tor-hosted infrastructure.

Share:
Morpheus Claims 680 GB Theft From HDFC AMC After VMware Systems Disruption
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 16, 20261d ago

Bombay High Court schedules further hearing in HDFC AMC case

The matter was scheduled for further hearing before the Bombay High Court on June 16. This followed the interim injunction issued against Morpheus over the alleged theft and threatened disclosure of HDFC AMC data.

Bombay High Court Restrains ‘Morpheus’ Ransomware Group From Sharing HDFC AMC’s Stolen Data - CySecurity News - Latest Information Security and Hacking Incidents
Jun 10, 20267d ago

Morpheus lists HDFC AMC on its leak site as 'HDFC FUND'

On June 10, Morpheus listed HDFC AMC as 'HDFC FUND' on its Tor-based leak site. The posting indicated the extortion attempt had progressed beyond a private claim to public leak-site exposure.

HDFC AMC Data Breach 2026: Morpheus, 680 GB & What It Means | The CyberSec Guru
May 29, 202619d ago

Bombay High Court issues interim injunction against Morpheus

On May 29, the Bombay High Court issued an ex parte interim injunction restraining the Morpheus ransomware group from publishing or disclosing HDFC AMC's allegedly stolen data. The court also directed the Union government to take steps to remove, block, disable, and delete online accounts associated with the stolen information.

HDFC AMC Data Breach 2026: Morpheus, 680 GB & What It Means | The CyberSec Guru
May 16, 20261mo ago

HDFC AMC notifies SEBI and stock exchanges about the incident

On May 16, HDFC AMC notified the Securities and Exchange Board of India and stock exchanges about the cybersecurity incident. This was part of the company's formal response following detection of the compromise.

HDFC AMC Data Breach 2026: Morpheus, 680 GB & What It Means | The CyberSec Guru

Morpheus claims exfiltration of more than 680 GB from HDFC AMC

Also on May 16, HDFC AMC found an email from a threat actor calling itself Morpheus claiming it had exfiltrated more than 680 GB of critical company data. The claim marked the start of an apparent data-extortion campaign tied to the intrusion.

HDFC AMC Data Breach 2026: Morpheus, 680 GB & What It Means | The CyberSec Guru

HDFC AMC detects unusual activity and inaccessible VMware systems

On May 16, HDFC AMC's IT administrator detected unusual activity and found parts of the company's on-premises VMware environment inaccessible, including VPN, SFTP, and antivirus management servers. The company activated its cybersecurity response protocols after discovering the disruption.

HDFC AMC Data Breach 2026: Morpheus, 680 GB & What It Means | The CyberSec Guru
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Affected products
2 linked
Vmware EsxiVmware Vcenter Server
Organizations
11 linked
MegaBharti AirtelBroadcomRedPacket SecurityReliance Jio InfocommVodafone IdeaNational Securities Depository LimitedHDFC Asset Management CompanyCentral Depository Services LimitedMF CentralHDFC Asset Management Company Limited
Breaches
1 linked
HDFCASSETMANAGEMENTCOMPANYLIMITED-2026-05
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.