The Notification That Shook My Morning
It started like any other routine workday. An email pinged in my inbox with a casual subject line: 'Your File is Ready to Download.'
I clicked the notification expecting to see an asset from our ongoing client projects. Instead, my dashboard showed high-resolution renders being generated for a production titled 'Nigerian Webseries'. A project I never created. A team I never hired. Prompts I had never typed in my life.
I opened my banking app. My stomach dropped.
There were five unauthorized debits sitting in my billing statements between September 28 and September 30, 2026. One charge of ₹2,076.80, followed by four brutal, back-to-back charges of ₹69,030 each. In less than forty-eight hours, exactly ₹2,78,196.80 had been siphoned through my saved billing credentials.
How the Exploit Worked: The API Credit Trap
When I inspected the account settings, the anatomy of the breach became crystal clear:
- Account Compromise: An unauthorized third party gained access to my Magnific account session.
- Rogue API Key Generation: Without requiring two-factor confirmation (2FA) or email re-authentication, the intruder created multiple active API keys under my profile.
- Automated 1-Million Credit Purchases: The attacker wrote a script that repeatedly bought 'Magnific Extra Credits 1M - Premium+ Annual' packs at ₹69,030 per pop, charging my saved card automatically without triggering a single One-Time Password (OTP) prompt.
- Asset Harvesting: The attacker used those millions of stolen credits to mass-generate AI-upscaled video and image assets for their external production, leaving me with the financial wreckage.
The Silence from Customer Support
Being a loyal customer for two years counts for nothing when platform security fails. I submitted emergency tickets through official support channels explaining the unauthorized breach and attaching bank transaction references.
Days have passed. Zero response. No acknowledgment. No temporary freeze on the compromised account.
Further research across creator forums revealed a troubling reality: I am not the only one. Multiple creators and design agencies have reported similar instances where saved card details on Magnific were drained through rapid API credit purchases without basic fraud detection kicking in.
The 3 Critical Security Failures Freepik Magnific Must Fix
Software platforms processing enterprise payments have a fundamental duty of care. Magnific and Freepik failed on three elementary security standards:
Any basic payment gateway should immediately flag an account that suddenly charges ₹2.76 Lakh within twenty-four hours after months of baseline usage. Magnific processed four identical ₹69,030 transactions back-to-back without batting an eye.
Creating an API key that has permission to trigger automated purchases should strictly require biometric verification, an authenticator app code, or SMS confirmation. It did not.
When a login happens from a completely different geographic IP address, modern services alert the user or kill stale sessions. The attacker operated in parallel with my account undetected.
What Every Creator and Agency Must Do Today
If you use Freepik, Magnific, Midjourney, RunWay, or any generative platform with a credit card on file, protect yourself before this happens to your business:
- Never Leave Credit Cards Saved on AI Platforms: Remove your primary business debit or credit card from subscription dashboards. Use virtual single-use cards or prepaid cards with a strict spending ceiling (e.g. ₹5,000 maximum balance).
- Audit Your API Keys Right Now: Open your account settings under the API tab. If you see keys you did not personally generate, delete them immediately and rotate your account password.
- Set Up Daily Bank Limits: Log into your net banking app and set an explicit domestic and international transaction limit. Cap daily online transactions to an amount that won't ruin your business if breached.
- File Bank Disputes Within 72 Hours: If unauthorized debits hit your account, call your issuing bank immediately. Demand an official transaction dispute form and file a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in or helpline 1930 in India). Prompt reporting is legally vital for chargeback recovery.
A Direct Message to the Freepik & Magnific Team
This is not an isolated bug; it is an active vulnerability costing loyal creators hundreds of thousands of rupees. We urge Freepik and Magnific leadership to investigate these unauthorized transaction reference IDs, refund the stolen funds, and implement mandatory multi-factor authentication for API generation and credit auto-refills immediately.
0 Comments