Key Takeaways
- Buyers that discover a breach during due diligence should pause integration activity, preserve evidence and verify the incident independently.
- CERT-In’s six-hour reporting requirement can create immediate obligations, while DPDP notification provisions remain subject to their transition schedule.
- Deal documents can allocate legacy liability through specific representations, cooperation duties, escrow and tailored indemnities.
A ransomware demand, a dark-web listing or an unfamiliar administrator account can transform fintech acquisition due diligence into an incident-response exercise within hours. The transaction may still proceed, but valuation work and integration planning should take a back seat until the parties understand what happened.
A seller’s reassurance that an incident is “contained” is not the same as verified containment. Buyers should consider an immediate standstill covering system access, data migration, credential sharing and planned integrations. Relevant logs, endpoint images, cloud records, emails and security alerts should be preserved before routine remediation erases useful evidence.
Independent investigation matters because buyers and sellers have different incentives. The seller wants transaction certainty. The buyer needs a defensible assessment of compromised systems, exposed personal data, attacker persistence and potential regulatory liability. Outside counsel and incident-response specialists, potentially including providers such as Mandiant or CrowdStrike, can help establish scope while maintaining disciplined reporting and evidence-handling processes.
The first regulatory clock may be shorter than many deal teams expect. India’s CERT-In Directions require covered cyber incidents, including data breaches and unauthorised access, to be reported within six hours of the organisation noticing or being informed of them. Discovery through a buyer’s diligence team can therefore create a difficult question: when did the seller become “informed,” and who is responsible for filing?
That issue should be escalated quickly rather than left for the next scheduled transaction call. A six-hour window leaves little room for internal debate, particularly when technical evidence is incomplete.
India’s developing privacy regime adds another layer. The Press Information Bureau said the DPDP Rules, 2025 were notified under the Digital Personal Data Protection Act, 2023. Under the breach-notification provisions, a data fiduciary is expected to notify affected individuals without delay and provide the Data Protection Board with a detailed report within 72 hours, unless an extension is permitted. Those provisions are scheduled to commence after an 18-month transition, according to Legal 500.
Timing is crucial. Deal teams should establish which obligations are currently operative, which provisions are still transitioning and whether sector-specific rules also apply. The DPDP framework permits penalties of up to ₹200 crore for failure to notify the Board or affected individuals once the applicable provisions take effect. Recent coverage from The Economic Times has also highlighted the broader implementation of India’s first dedicated personal-data protection regime.
What should a disclosure eventually contain? DPDP Rule 7 calls for an explanation of the breach’s nature, extent and timing, likely consequences, mitigation measures, recommended protective steps and a contact for questions. Producing that account requires more than a preliminary malware alert. Investigators need to determine what data was accessed or extracted, which processors were involved and whether attackers retained valid credentials.
The commercial implications can be just as significant. An uncertain breach can alter the purchase price, delay closing or justify a holdback. Acquisition agreements should address legacy liability, regulatory notifications, customer communications, remediation costs and post-closing cooperation. Specific representations can cover access controls, processors, security logs, earlier incidents and prior regulatory notices.
Generic cybersecurity warranties may offer limited comfort when an incident is already known. A special indemnity or escrow can provide clearer protection for exposure that cannot be quantified before closing. Buyers may also seek approval rights over notifications and remediation, while sellers may resist provisions that transfer open-ended liability.
Razorpay, Paytm and PhonePe illustrate the scale and regulatory sensitivity of India’s fintech market, though their mention does not imply involvement in any breach. Payment and identity data can move through banks, processors, cloud providers and outsourced support operations. That complexity makes perimeter-only reviews inadequate.
A discovered incident does not automatically end a transaction. It does, however, change the basis on which the deal should be evaluated. Verified scope, preserved evidence and clearly allocated obligations offer a stronger foundation than seller assurances delivered under closing pressure.
⬇️