CSIDB logo
Incident

HDFC Fund

Incident posture

Attack window
Jun 2026
Location
India
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 22:12

Linked entities

Victim
HDFC Fund
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

HDFC Fund was identified as a victim of a ransomware attack carried out by the Morpheus group. The organization, which operates as an asset management company, reported annual revenue of about $427.8 million, and its website hdfcfund.com was compromised. No further details about data exfiltration or ransom demand have been disclosed publicly.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The incident involving HDFC appears in the ransomware.live listing of recent victims, where HDFC Fund is identified as HDFC Asset Management Company Limited. The entry indicates that the organization was discovered as a victim of the Morpheus ransomware strain on 2026-06-10, approximately eight hours before the article’s timestamp. The associated website is noted as hdfcfund.com and the reported revenue is $427.8 million. These are the only descriptive fields provided for this particular victim in the source.

The ransomware.live entry does not include any icons or annotations that would indicate additional details such as screenshot availability, infostealer data presence, victim denial, known ransom amount, known leak size, duplicate claim detection, or press coverage. Consequently, the source does not disclose which systems were affected, what data may have been exfiltrated or encrypted, whether a ransom demand was communicated, or what size of data leak, if any, resulted from the incident. Likewise, the article provides no information about how the compromise was detected, what containment or eradication steps were undertaken, or any public statements issued by HDFC Asset Management Company Limited regarding the event. All such specifics remain absent from the presented listing.

Because the available source material limits the narrative to the discovery date, threat actor name, website, and revenue figure, any further description of the incident’s timeline, impact, or response would require information from other reports or disclosures. The known facts therefore remain confined to what is explicitly presented in the ransomware.live listing for HDFC Fund. No further elaboration can be made without additional verified sources.

Sources

Sources available to members: 1 source.

CSIDB