Toofan Loan, an app operated by Satisfaction Commercial Pvt Ltd, wanted its money back. So it wrote to roughly 269 borrowers at once - and put every single one of their email addresses in the To and Cc fields instead of Bcc. In that moment each of those 269 people learned the identity of the other 268. Not as strangers. As named individuals behind on a loan.
What the email did to 269 people
Consider what a borrower actually received. Not just a demand for money, but a list: hundreds of real email addresses, many carrying full names, every one belonging to somebody in the same financial trouble. A borrower who had told nobody they had taken this loan was now on a roster that hundreds of strangers held a permanent copy of.
That roster does not expire. It can be saved, forwarded, scraped and sold. It is a ready-made target list of people who are short of money, already being chased, and unlikely to complain loudly - which is precisely the profile that recovery agents, and anyone running a follow-on scam, look for. The exposure did not end when the inbox was closed.
The law is not ambiguous here
Under the Digital Personal Data Protection Act, 2023, a company holding personal data is a Data Fiduciary and owes duties it cannot contract out of.
- Section 8(5) requires reasonable security safeguards to prevent a personal data breach. The Schedule to the Act sets the penalty for failing that duty at up to Rs 250 crore.
- Section 8(6) requires the Data Fiduciary to notify both the Data Protection Board and every affected person when a breach occurs. Failing to notify carries up to Rs 200 crore.
Putting 269 recipients in Cc rather than Bcc is not a sophisticated compromise by an outside attacker. It is a single field in an email client. Whether that meets the standard of a reasonable security safeguard is a question for the Data Protection Board, and the Board decides the actual penalty on the facts - the number of people affected is one of the things it weighs.
We have found no public notification of this breach by Satisfaction Commercial Pvt Ltd, and no indication that the 269 affected borrowers were told they had been exposed. If the company did notify the Board or those borrowers, we will publish that evidence in full on request.
If you were one of the 269
You do not need a lawyer to act on this, and none of these routes cost anything.
- Keep the email. Do not delete it. Screenshot the header showing the To and Cc fields, and save the original message - it is the evidence, and it is evidence you already hold.
- Report the data breach. File at cybercrime.gov.in or call 1930. Describe it plainly: a lender disclosed your personal data to hundreds of third parties without consent.
- Complain to the RBI. Use cms.rbi.org.in. Recovery conduct by or on behalf of a regulated lender falls within the RBI's remit, and its Fair Practices Code bars practices that humiliate or breach a borrower's privacy.
- Check who actually lent to you. An app is not a lender. Look up the NBFC named in your loan agreement on the RBI's register at sachet.rbi.org.in. If no registered entity is named anywhere in your paperwork, that itself is worth reporting.
- Do not pay to make it stop. Paying an inflated or disputed demand to end the pressure does not remove your data from 269 inboxes, and it confirms you respond to pressure.
Why we are naming the company
Everything above comes from the email itself and from the text of the DPDP Act - not from an allegation, and not from a complaint we cannot see. We name Satisfaction Commercial Pvt Ltd because a person searching the name of this app before they borrow deserves to find this. We do not link to the app, and we will not: sending a reader who is already short of money one click closer to it would defeat the only purpose this article has.
Right of reply: Satisfaction Commercial Pvt Ltd has a standing invitation to respond. Any correction, evidence of breach notification, or statement will be published in full and unedited alongside this piece. Write to editor@oquilia.com.
Evidence · redacted copy to be published
Toofan Loan recovery email addressed to roughly 269 borrowers with every recipient's address visible in the To and Cc fields
Your rights, and how to report
The lenders in this series are RBI-registered NBFCs, bound by the RBI's Fair Practices Code: no recovery calls before 8 am or after 7 pm, no contacting your employer, family or references to pressure you, no abuse or threats, and the all-in APR must be disclosed in the Key Facts Statement. Read the full plain-English guide on Oquilia's loan-harassment help page.
To report a lender: start at RBI Sachet, escalate unresolved complaints to the RBI Ombudsman (CMS) after 30 days, and report threats, harassment or data misuse at the National Cyber Crime portal or on 1930. Keep every screenshot, email and call log - that record is your evidence.
More from this investigation
- Subhlakshmi Finance: ~190 borrowers exposed in CC
- PaisaOnSalary: the alleged emails to a borrower's colleagues
- Qualoan: the alleged 'employment verification' email
Frequently asked questions
Is what Toofan Loan did legal?
Toofan Loan is operated by Satisfaction Commercial Pvt Ltd. Lending is one question; exposing roughly 269 borrowers' addresses to each other in a single email is a separate one. Section 8(5) of the Digital Personal Data Protection Act, 2023 requires reasonable security safeguards against exactly this, and the Schedule sets a penalty of up to Rs 250 crore for failing that duty. Section 8(6) separately requires the company to notify the Data Protection Board and every affected borrower. If your address was exposed, keep the email as evidence, report it at cybercrime.gov.in or 1930, and complain to the RBI at cms.rbi.org.in.
Can a loan app call my office or family?
No. Under the RBI Fair Practices Code, recovery agents may not contact your employer, family or references to pressure you, may not call before 8 am or after 7 pm, and may not use abuse or threats. Approaching your workplace or contacts to shame you over a loan falls outside lawful recovery, whatever an app's agreement says.
How do I report a loan app to the RBI?
Start at RBI Sachet (sachet.rbi.org.in). If the NBFC does not resolve your complaint within 30 days, escalate to the RBI Ombudsman through the Complaint Management System. For threats or data misuse, use the National Cyber Crime portal (cybercrime.gov.in) or call 1930, and keep all screenshots and statements.
Source
Lenders' own Key Facts Statements, agreements and recovery emails; RBI Register of NBFCs; documented borrower complaints