Aadhaar Data, Including Bank Information, Exposed by State-Owned Utility Provider: Report

Advertisement
By Gadgets 360 Staff | Updated: 13 July 2018 15:47 IST
Highlights
  • The report says it informed the Indian government of the vulnerability
  • Despite this, the government has reportedly not fixed the leak
  • Aadhaar information is being leaked due to a unsecure API

Aadhaar details of all registered users are exposed online by the vulnerable system of a state-owned utility service provider, according to a new report. The report claims this issue was brought to the notice of the Indian government over a month ago, but no action has been taken yet to fix the issue. The data vulnerable to the leak includes personal information of users, Aadhaar number, as well as the names of banks in which they have accounts. Worryingly, it is not only consumers registered with the utility service that are reported to be at risk, but all Aadhaar users.

According to a ZDNet report, the endpoint vulnerability was discovered by Delhi-based security researcher Karan Saini. The report does not mention the name of the utility service provider, and only mentions it is a state-owned entity. It has reportedly not secured the API, which can expose the Aadhaar details of all citizens.

Advertisement

The report says, “The API's endpoint - a URL that we are not publishing - has no access controls in place. The affected endpoint uses a hardcoded access token, which, when decoded, translates to ‘INDAADHAARSECURESTATUS’, allowing anyone to query Aadhaar numbers against the database without any additional authentication.”

Saini, the report claims, also discovered the API does not employ any rate limiting, which makes it vulnerable to hackers attempting to steal Aadhaar information by going through any number of permutations — potentially trillions — in order to get a successful result.

Advertisement

For example, the report quotes Saini as saying, “it would be possible to enumerate Aadhaar numbers by cycling through combinations, such as 1234 5678 0000 to 1234 5678 9999. And because there is no rate limiting, Saini said he could send thousands of requests each minute — just from one computer.”

"An attacker is bound to find some valid Aadhaar numbers there, which could then be used to find their corresponding details," Saini says in the report. The data is reportedly being updated regularly “from as early as 2014 to mid 2017”, and “it seems that everyone's information is available, with no authentication”

Advertisement

As for the information revealed by the leak, Saini was reportedly able to access the names of the Aadhaar holders, their consumer number (assigned by the utility service provider, not UIDAI), and the banks they in which they have accounts. In fact, anyone who has your Aadhaar number can check the linked bank accounts via a simple text message

The government was informed of this data leak by ZDNet over a month via email that elicited no response. The publication then reached out to the Indian Consulate in New York and Devi Prasad Misra, consul for trade and customs. Over a two-week period, emails explaining the situation and follow-up questions were exchanged, but the vulnerability was not fixed. The last email, which the publication claims to have sent at the start of the week, did not get a reply either.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Camon Slim 5G With 6.59mm Thickness Announced: See Specifications
  2. Huawei Mate XT 2 Debuts as the Company's Second-Gen Tri-Fold Phone
  3. Oppo Teases New Smartphone Launch in India
  4. Oppo Teases Find X10 and Find X10 Pro Max 200-Megapixel Cameras
  5. iQOO Z11xa 5G With the Dimensity 7400 Turbo SoC Debuts in India: See Price
  6. Samsung Galaxy S27 Ultra, Galaxy S27 Pro Reportedly Bag 3C Certification
  7. Motorola Edge 70 Neo India Launch Confirmed at IFA 2026
  1. iQOO 16 Tipped to Launch in September With Snapdragon 8 Elite Gen 6 Chip
  2. iQOO Pad Ultra Tipped to Launch With 8.8-Inch OLED Display, Snapdragon 8 Elite Gen 6 SoC, and More
  3. OnePlus 16 Tipped to Feature 9,000mAh Battery and 185Hz Display
  4. Samsung Galaxy A57, Galaxy A37 Prices Reportedly Hiked in India by Up to Rs 6,000: Here's What You Need to Know
  5. Oppo Teases New Smartphone Launch in India; Could Be F35 Pro With 10,000mAh Battery
  6. Bitcoin Slips Below $80,000 as Strong US Jobs Data Revives Fed Rate Hike Bets
  7. Huawei Mate XT 2 Ultimate Design Launched With Kirin 9050 Pro Chipset: Price, Specifications
  8. Vodafone TV Launched in UK With Live Channels, Streaming, Gaming and More
  9. Samsung Galaxy S27 Ultra, Galaxy S27 Pro Reportedly Bag 3C Certification, Charging Specifications Tipped
  10. Tecno Camon Slim 5G Announced With 6.59mm Thickness, 6,000mAh Battery: Specifications, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.