PhonePe told merchant partners to rotate dashboard passwords and re-enroll devices on its business console after security teams detected a credential-stuffing wave that compromised a "limited subset" of payout accounts during Ganesh festival settlement windows, according to a merchant advisory reviewed by InfoHandle and corroborated by two sponsor banks that saw elevated NPCI dispute filings. The company said core UPI switches were not breached; attackers logged in with reused passwords harvested from older third-party leaks, then redirected settlement batches to mule accounts before shop owners returned from holiday hours.
What broke
Incident responders described automated login attempts against PhonePe's merchant SSO front door, throttled but not blocked for every IP because aggressive lockouts would have frozen legitimate kirana logins during peak QR traffic. Accounts without hardware or app-based second factors were the primary victims. In several cases, fraudsters changed notification mobile numbers so chargeback SMS never reached owners until bank statements arrived.
PhonePe has not published victim counts; sponsor banks in Maharashtra and Gujarat reported double-digit dispute tickets tied to PhonePe merchant IDs in the week after visarjan, without confirming overlap with this wave. CERT-In was notified under existing payment-sector timelines, according to a person briefed on the filing who spoke on condition of anonymity because the notice is not public.
What PhonePe changed
The advisory mandates WebAuthn or app push approval for any user who can alter settlement accounts, disables parallel browser sessions on admin roles, and forces logout of dormant SSO tokens issued before September 1. API keys for bulk payout integrations must be reissued; older keys stop working at month-end. PhonePe's status page carried a yellow banner for twelve hours; merchant support queues lengthened as franchise chains reset thousands of sub-accounts.
Rival aggregators used the moment to market their own MFA features, but RBI supervisors note the sector-wide pattern: merchant dashboards remain softer targets than consumer UPI PIN flows.
Who is liable
Merchant agreements generally require owners to safeguard credentials, yet consumer protection teams argue platforms enabling instant payout changes without cooling-off periods share blame. NPCI's zero-liability framework focuses on customer-to-merchant UPI scams, not merchant-to-bank pool theft, leaving gaps where shopkeepers discover losses after aggregator support tickets close. Banks that sponsor PhonePe settlements are reconciling which losses sit in pooled accounts versus insured cyber limits.
Police cyber cells in Pune and Surat opened preliminary inquiries after local trader associations filed complaints; no named arrests were announced by Friday.
What merchants should verify now
Owners should confirm settlement bank accounts inside the app using a known-good device, revoke unknown sub-users, and compare NPCI transaction IDs against physical ledgers—not just daily SMS totals, which attackers silenced. Franchise headquarters must audit SSO tied to accounting vendors; several stuffing lists in this wave matched leaked credentials from unrelated logistics portals reused by finance clerks.
Technical limits
Credential stuffing cannot be solved by CAPTCHA alone without blocking festival traffic. PhonePe said it is piloting risk scores on login geography and device age but declined to share false-positive rates. Shared tablets in markets remain a weak point when shop staff stay logged in across shifts.
Regulatory context
The wave lands as CERT-In tightens breach clocks for aggregators and RBI scrutiny intensifies on digital lending apps—not identical products, but the same festival-season fraud tempo. DSSC workshops this month highlight merchant-console hygiene as the underfunded sibling of consumer awareness ads.
For readers running a single outlet, the lesson is blunt: treat your payout dashboard like a bank vault, not a marketing login. PhonePe's patches close the easiest door, but reused passwords will find the next aggregator that moves slower during the next long weekend.
What is still unknown
PhonePe has not identified which external breach corpora powered the stuffing lists, and no court has tested liability splits for pooled-account losses. Until RBI issues harmonized merchant-protection rules, festival reconciliations will remain the real incident report.
Trader associations in tier-two markets said they will publish shared checklists for franchise staff—separate logins for cashiers versus finance leads, mandatory logout at close, and weekly spot checks on settlement account numbers. Those habits cost less than cyber insurance riders and matter more when stuffing kits update faster than vendor press releases.








