BookMyForex Reports Significant Data Breach Affecting Customer Information
Market Alert: BookMyForex Security Breach
A significant data security incident has compromised the **BookMyForex** platform, leading to widespread reports of unauthorized transactions on prepaid forex cards. As of late **February 2026**, thousands of users have reported fraudulent activity, primarily involving international transactions in **USD** and **AED**.
Affected customers have noted a surge in debit alerts for transactions they did not authorize. Many of these attempts were successfully processed, while others were declined only after multiple failed security entries. Current reports suggest that the breach has impacted the core card management infrastructure, making immediate mitigation difficult for users.
Operational Disruptions
The platform's mobile application and customer support channels are currently facing severe outages. Users report being stuck at "Reset App PIN" screens or encountering blank error popups when attempting to access card controls.
With the app largely unresponsive, many travelers find themselves unable to lock their cards or modify spending limits while abroad. This has left a significant number of cardholders without access to their primary travel funds, a situation compounded by the high volume of calls overwhelming the company’s support team.
Mitigation and Recovery
BookMyForex has officially escalated the crisis to its banking partner, **Yes Bank**, to initiate chargeback proceedings. The company is directing users to its web-based card management portal as the primary method for securing accounts.
* **Locking Cards:** Users are advised to log in via the website to immediately disable all transaction types.
* **Dispute Filing:** Victims are being instructed to email specific dispute desks at both BookMyForex and Yes Bank.
* **Insurance Claims:** Most cards issued through the platform include insurance coverage for internet fraud, which may offer a secondary route for fund recovery.
Sector Context
This incident occurs at a time of heightened digital risk for the Indian fintech sector. Recent industry data indicates that **51%** of senior leaders now cite cybersecurity as the top threat to organizational performance in **2026**.
The breach also coincides with recent regulatory shifts. Under the **Union Budget 2026**, Tax Collected at Source (TCS) for foreign remittances was recently adjusted, with education and medical remittances reduced from **5%** to **2%** for amounts exceeding **₹10 lakh**.
For those currently affected, the focus remains on securing a formal acknowledgment from the **National Cybercrime Portal** to support pending insurance and chargeback claims. Experts emphasize that until the platform restores full app functionality, manual card locking via the web remains the only reliable safeguard for remaining balances.