Data Breach on CSC BHIM Site Puts 70 Lakhs Indians' Highly Sensitive Data at Risk: Report

The vulnerability on CSC BHIM site was first detected on April 23 and it is said that the loophole was fixed on May 22.

Advertisement
By Abhik Sengupta | Updated: 1 June 2020 17:46 IST
Highlights
  • Sensitive data was reportedly found in an unsecured server
  • Exposed data includes Aadhaar card details, PAN number and more
  • Government is yet to publicly address this issue

409GB worth of data was lying unsecured on cloud storage.

Aadhaar cards, caste certificates, and other highly sensitive personal data of over 70 lakh Indians have reportedly been exposed by a government website. The CSC BHIM website, used to promote UPI payments app BHIM, reportedly suffered a massive data breach. The CSC e-Governance Service India is a program to bring digital access to villages, and the CSC BHIM project was launched to get merchants at the village level to start accepting UPI payments through QR codes. Apparently, a tremendous amount of data of Indian citizens was gathered on the site, and this information has now been breached.

According to Israeli cybersecurity company vpnMentor, 409GB of data of users in India have been exposed, which includes a huge amount of highly sensitive, personally identifiable information. The company said that the exposure of this user data is akin to a hacker gaining "access to the entire data infrastructure of a bank," along with users' account information. The vulnerability was detected first on April 23 and it is said that the loophole was fixed on May 22.

Based on the report so far, there is no evidence yet that the BHIM app itself was leaking data, or that the UPI system is insecure.

Advertisement

How was CSC BHIM data breached?

The report by vpnMentor claims that the data collected for BHIM deployment was being stored on a misconfigured Amazon Web Services S3 bucket and was "publicly accessible." This has been found to be a fairly common error that many websites make when setting up their cloud systems. As per vpnMentor, 409GB worth of sensitive data of individuals and several merchants were lying unsecured, therefore, exposing them to potential fraud, theft, and attack from hackers and cybercriminals.

Advertisement

Sensitive data of lakhs of Indians was stored in cloud storage without security protocols on the account to ensure safety.

"...the data was stored on an unsecured Amazon Web Services (AWS) S3 bucket. S3 buckets are a popular form of cloud storage across the world but require developers to set up the security protocols on their accounts. The exposed S3 bucket was labelled 'csc-bhim,' and our team was quickly able to identify the developers behind the website 'www.cscbhim.in' as the owners of the data," claim Noam Rotem and Ran Locar, cybersecurity researchers at vpnMentor.

Advertisement

What all data was compromised in the CSC BHIM breach?

According to vpnMentor, the following were some of the personal documents that were found in the exposed S3 bucket:

  • Scans of Aadhaar cards – India's national ID
  • Scans of Caste certificates
  • Photos used as proof of residence
  • Professional certificates, degrees, and diplomas
  • Screenshots taken within financial and banking apps as proof of fund transfers
  • Permanent Account Number (PAN) cards (associated with Indian income tax services)

Aside from this, the leak also included UPI VPAs (transaction IDs) of people.

Advertisement

Impact of the CSC BHIM data breach

The cybersecurity company said that the data breach exposes highly sensitive data including individual's Aadhaar card information, caste certificates, proof of residence, professional certificates and degrees, and scans of Permanent Account Number (PAN) cards.

"Based on our research, the S3 bucket also contained documents and PII [Personally identifiable information] data for minors," company said. The cybersecurity company explains that having such sensitive financial data in the public domain would make it "incredibly easy to trick, defraud, and steal from the people exposed."

"The exposure of private data may also contribute to a broader deterioration of trust between the Indian public, government bodies, and technology companies," the company added.

What has the government said over the CSC BHIM data vulnerability?

The report states that the cybersecurity company reached out to the developers of CSC BHIM site to inform about the breach, however, no contact was established. The company then reached out India's Computer Emergency Response Team (CERT-In), which deals with cybersecurity in the country on April 28 and the problem was reportedly rectified on May 22, without further response.

Gadgets 360 has also reached out to the National Payments Corporation of India, and Computer Emergency Response Team for more clarity.


Is Realme TV the best TV under Rs. 15,000 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  3. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  4. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  5. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  6. iOS 26 Releases Today: Check Out the Notable Features
  7. OnePlus 15 Leaked Image Reveals Colourways, Redesigned Camera Module
  8. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  9. Gemini Overtakes ChatGPT on App Store, Reaches the Top Spot
  10. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  1. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  2. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  3. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  4. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  5. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  6. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  7. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
  8. OnePlus 15 Leaked Image Hints at Redesigned Camera Module, Three Colourways
  9. Xiaomi 17 Pro Max Leaked Image Reveals Rear Display in a Nod to the 11 Ultra Ahead of September Debut
  10. Treasure Hunters Season 1 Now Streaming on JioHotstar: Everything You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.