UIDAI Bug Bounty Programme: 20 Ethical Hackers to Reportedly Detect, Fix Aadhaar Data Security Issues

These 20 hackers will be given access to the Central Identities Data Repository.

Advertisement
By Sourabh Kulesh | Updated: 20 July 2022 16:27 IST
Highlights
  • Applicants should be listed in top 100 of bug bounty leaders
  • The hackers must sign a non-disclosure agreement
  • No information on remuneration for the exercise

CIDR stores Aadhaar data of 1.32 billion Indians

The Unique Identification Authority of India (UIDAI) has reportedly called out for 20 hackers who will be tasked to detect and fix vulnerabilities in the security system that guards the Aadhaar data of Indian citizens as a part of “bug bounty programme”. A report says that these “ethical” hackers will be given access to the UIDAI's Central Identities Data Repository (CIDR) that stores the Aadhaar data of 1.32 billion Indians. There have been instances in the past where Aadhaar details of people were leaked on the internet.

As per a report by News 18, an order was issued by the UIDAI on July 13 and it mentions that the authority has decided to run the bug bounty programme on its systems. Under this programme, these 20 hackers will be given access to the UIDAI's Central Identities Data Repository (CIDR) that stores the Aadhaar data of 1.32 billion Indians. They will find loopholes in the Aadhaar data security system and help the authority fix them.

Advertisement

In order to be selected by UIDAI, the applicants “should be listed in top 100 of the bug bounty leaders board such as HackerOne, Bugcrowd, or listed in the Bounty Programs conducted by reputable companies such as Microsoft, Google, Facebook, or Apple etc.” As per the order, “...the candidate should be active in the bug bounty community or programs and should have submitted valid bugs or received bounty in the last one year.”

Furthermore, the applicant is required to be an Indian resident and must have a valid Aadhaar number. The selected lot will also sign a non-disclosure agreement with UIDAI. If you are a current or former employee of UIDAI or one of its contracted technology support and audit organisations during the past seven years, you are not eligible for the work.

Advertisement

“In case more than 20 applications are received, then UIDAI reserves the right to evaluate and select top 20 suitable candidates…an independent committee shall be formulated to assess and verify the candidates' credentials, past bug hunting records or references and citations,” as per the order. There is no information available on whether or not these ethical hackers are paid remuneration for the exercise.

The development comes a month after it was reported that Aadhaar data of a large number of farmers was leaked by PM Kisan website, which is designed for the welfare of the agriculture sector in India. “The website provides an endpoint, which returns information about the beneficiary. This endpoint was also sending Aadhaar numbers,” Security researcher Atul Nair told Gadgets 360.

Advertisement

In 2019, the Jharkhand government reportedly exposed the unique identification numbers of its thousands of workers. State-owned liquid petroleum gas (LPG) manufacturer Indane was also reported to have exposed Aadhaar details of millions of its consumers.


Is the Nothing Phone 1 worth it beyond its design choices? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung's One UI 9 Beta Is Now Available to Test on the Galaxy S26 Series
  2. Asus Chromebook CM32 Detachable, Chromebook CM14 and CM15 Launched in India
  3. Oppo Reno 16 Series Price, Storage Variants Leak Ahead of Launch
  4. New Leak Compares All of Samsung's Foldables Expected to Launch in 2026
  5. iPhone 18 Pro Max Design and Colourways Revealed in New Leak
  6. Samsung Galaxy S25 Edge Now Listed at Half of Its Launch Price in India
  7. New OTT Releases This Week: Bhooth Bangla, Raakh, Dridam, Karuppu, and More
  8. Moto G Max 5G With a 200-Megapixel Rear Camera Arrives at This Price
  9. Vivo X Fold 6 to Debut This Custom MediaTek Chipset Designed for Folables
  1. WhatsApp Could Soon Offer Meta One Plus, Meta One Premium Subscriptions With Additional Features
  2. Honor Tipped to Launch Smartphone With 10,000-Nit Display and 10,000mAh Battery
  3. Samsung Galaxy A27 5G Listing on Czech Website Leaves Little to the Imagination Ahead of Imminent Debut
  4. Asus Chromebook CM32 Detachable With 2.5K Display Launched in India Alongside Chromebook CM14, CM15
  5. Apple's iPhone 18 Pro Max Leaks in New Hands-On Images Ahead of Anticipated September Launch Event
  6. Authorities Shut $390 Million Crypto Money-Laundering Scheme in International Sting Operation
  7. Astronomers Discover Why Massive Galaxies Died Early in the Universe
  8. Samsung Galaxy Z Fold 8, Z Fold 8 Ultra and Z Flip 8 Display Shapes Revealed via Leaked Image of Screen Protectors
  9. Nothing CEO Carl Pei Predicts Smartphones May Not Get Major Discounts During Sales Due to Ongoing Chip Shortage
  10. Samsung Galaxy S25 Edge Price in India Drops to All-Time Low: Specifications, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.