Subhlakshmi Finance is a non-banking financial company registered with the Reserve Bank of India. It sits inside the regulatory perimeter. Its lending is lawful. It also sent one recovery email to roughly 190 borrowers with every recipient's address in the CC field rather than Bcc. In that moment each of those 190 people could see the other 189 - not as account numbers, but as identifiable individuals behind on a loan.
What roughly 190 people actually received
Picture the inbox of one borrower on that list. They opened a demand for money. What they also got was a roster: hundreds of real email addresses, many of which carry a person's own name, every one of them belonging to somebody in the same financial position as themselves.
A borrower who had told nobody about this loan was, without being asked, placed on a list that roughly 190 strangers now hold a permanent copy of. Some of those inboxes are shared with a spouse. Some are read on a work phone. Some are open on a screen at home when a family member walks past. The disclosure did not stop at the recipients the lender intended it for.
The list does not expire either. An email can be saved, forwarded, exported and scraped. What was created that day is a ready-made contact list of people who are short of money, already being chased, and unlikely to complain loudly. That is precisely the profile that recovery operations and follow-on approaches select for. A borrower cannot recall the message, cannot delete it from other people's mailboxes, and cannot know where it has since travelled.
None of that harm required anybody to break into anything. It required a single field in an email client to be filled in one way rather than another.
Registration is a standard, not a shield
Subhlakshmi Finance being an RBI-registered NBFC matters, and it does not cut the way a worried borrower might assume. Registration is what makes the lending itself lawful. It also means there is a named, supervised entity that the RBI can be asked about, and that the RBI's own rules apply directly rather than through some intermediary nobody can identify.
The RBI's Fair Practices Code requires a lender to keep customer information confidential and bars recovery practices that humiliate a borrower or intrude on their privacy. The RBI's Digital Lending Guidelines of September 2022 tighten the same expectation for data collected through a lending app or platform. A registered lender is held to those standards, not exempted from them. If anything, being on the register means there is somewhere concrete to take the complaint.
What the DPDP Act says about this
Under the Digital Personal Data Protection Act, 2023, a company that decides how borrower data is handled is a Data Fiduciary. Two duties are directly in point.
- Section 8(5) requires reasonable security safeguards to prevent a personal data breach. The Schedule to the Act sets the penalty for failing that duty at up to Rs 250 crore.
- Section 8(6) requires the Data Fiduciary to notify the Data Protection Board and each affected person once a breach has occurred. Failing to notify carries up to Rs 200 crore.
Whether putting roughly 190 recipients in CC rather than Bcc falls below the standard of a reasonable security safeguard is a question for the Data Protection Board, and the Board sets any actual penalty on the facts before it. The number of people affected is one of the things it weighs. The ceilings above are ceilings, not forecasts.
We have found no public notification of this exposure by Subhlakshmi Finance, and no indication that the affected borrowers were told their addresses had been disclosed to each other. If the company did notify the Board or those borrowers, we will publish that evidence in full on request.
The second exposure of this kind we have documented
This is not the only mass disclosure of borrower addresses in a recovery email that this series has recorded. A separate lender, in a separate email, exposed a separate group of borrowers the same way. Two incidents are not a survey of an industry. They are enough to say that this is not a one-off slip by one clerk, and enough to tell a borrower that if their address appeared in a CC field alongside strangers, they are not imagining the problem and they are not the only one.
If your address was in that CC field
You do not need a lawyer to act, and none of these routes costs anything.
- Keep the email. Do not delete it. Screenshot the header showing the CC field and the full list, and save the original message with its headers intact. This is the evidence, and you already hold it.
- Report the data exposure. File at cybercrime.gov.in or call 1930. Describe it plainly: a lender disclosed your personal data to roughly 190 third parties without your consent.
- Complain to the RBI. Use cms.rbi.org.in. Because the lender is a registered NBFC, its recovery conduct and its handling of customer information sit squarely within the RBI's remit, and the Fair Practices Code bars practices that humiliate a borrower or breach their privacy.
- Check the register for every lender in your paperwork. An app is not a lender. Look up the entity actually named in your loan agreement on the RBI's portal at sachet.rbi.org.in. If no registered entity is named anywhere in your documents, that on its own is worth reporting there.
- Do not pay to make it stop. Settling a disputed or inflated demand does not remove your address from roughly 190 inboxes. It only confirms that pressure works on you.
Write your complaints in the order above and attach the same screenshot to each. You are not asking anyone to take your word for what happened. The email is the record.
Why we are naming the company
What is set out here comes from the email itself and from the text of the DPDP Act and the RBI's own rules. It is not an allegation we are unable to see, and it is not an inference about intent. We name Subhlakshmi Finance because somebody typing that name into a search engine before they borrow deserves to find this on the first page. We do not link to the lender and we will not: sending a reader who is already short of money one click closer would defeat the only purpose this article has.
Right of reply: Subhlakshmi Finance has a standing invitation to respond. Any correction, evidence of breach notification, or statement of its position will be published in full and unedited alongside this piece. Write to editor@oquilia.com.
Evidence · redacted copy to be published
Subhlakshmi Finance recovery email with roughly 190 borrowers' addresses exposed in the CC field
Your rights, and how to report
The lenders in this series are RBI-registered NBFCs, bound by the RBI's Fair Practices Code: no recovery calls before 8 am or after 7 pm, no contacting your employer, family or references to pressure you, no abuse or threats, and the all-in APR must be disclosed in the Key Facts Statement. Read the full plain-English guide on Oquilia's loan-harassment help page.
To report a lender: start at RBI Sachet, escalate unresolved complaints to the RBI Ombudsman (CMS) after 30 days, and report threats, harassment or data misuse at the National Cyber Crime portal or on 1930. Keep every screenshot, email and call log - that record is your evidence.
More from this investigation
- PaisaOnSalary: the alleged emails to a borrower's colleagues
- Qualoan: the alleged 'employment verification' email
- SnapPaisa: the alleged '1 PM' office-email threat
Frequently asked questions
Is Subhlakshmi Finance a registered lender?
Yes. Subhlakshmi Finance is an RBI-registered non-banking financial company, which is what makes its lending lawful. Registration does not license sending one recovery email with roughly 190 borrowers' addresses in the CC field instead of Bcc, so that each recipient could identify the rest. Section 8(5) of the Digital Personal Data Protection Act, 2023 requires reasonable security safeguards against exactly that kind of disclosure, and the Schedule sets a penalty of up to Rs 250 crore for failing that duty; Section 8(6) separately requires the company to notify the Data Protection Board and every affected borrower, with a penalty of up to Rs 200 crore for not doing so. Registration also works in your favour when you complain: because the lender is supervised, the RBI's Fair Practices Code on confidentiality and on recovery that humiliates or intrudes on privacy applies directly to it. If your address was in that CC field, keep the email and screenshot the header, report it at cybercrime.gov.in or on 1930, and file with the RBI at cms.rbi.org.in.
Can a loan app call my office or family?
No. Under the RBI Fair Practices Code, recovery agents may not contact your employer, family or references to pressure you, may not call before 8 am or after 7 pm, and may not use abuse or threats. Approaching your workplace or contacts to shame you over a loan falls outside lawful recovery, whatever an app's agreement says.
How do I report a loan app to the RBI?
Start at RBI Sachet (sachet.rbi.org.in). If the NBFC does not resolve your complaint within 30 days, escalate to the RBI Ombudsman through the Complaint Management System. For threats or data misuse, use the National Cyber Crime portal (cybercrime.gov.in) or call 1930, and keep all screenshots and statements.
Source
Lenders' own Key Facts Statements, agreements and recovery emails; RBI Register of NBFCs; documented borrower complaints