• About
  • Advertise
  • Jobs
Friday, June 19, 2026
No Result
View All Result
KashmirPEN
  • Home
  • Latest NewsLive
  • State News
  • COVID-19
  • Kashmir
  • National
  • International
  • Education
  • Sports
  • Entertainment
  • Technology
  • Weekly
    • Perception
    • Perspective
    • Narrative
    • Concern
    • Nostalgia
    • Tribute
    • Viewpoint
    • Outlook
    • Opinion
    • Sufi Saints of Kashmir
    • Personality
    • Musing
    • Society
    • Editorial
    • Analysis
    • Culture
    • Cover Story
    • Book Review
    • Heritage
    • Art & Poetry
  • Home
  • Latest NewsLive
  • State News
  • COVID-19
  • Kashmir
  • National
  • International
  • Education
  • Sports
  • Entertainment
  • Technology
  • Weekly
    • Perception
    • Perspective
    • Narrative
    • Concern
    • Nostalgia
    • Tribute
    • Viewpoint
    • Outlook
    • Opinion
    • Sufi Saints of Kashmir
    • Personality
    • Musing
    • Society
    • Editorial
    • Analysis
    • Culture
    • Cover Story
    • Book Review
    • Heritage
    • Art & Poetry
KashmirPEN
No Result
View All Result
ADVERTISEMENT
Home State News

Data Breach: Aadhaar Details up for Grabs for Just Rs 500

Kashmir Pen by Kashmir Pen
8 years ago
in State News
Reading Time: 4 mins read
Data Breach: Aadhaar Details up for Grabs for Just Rs 500
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

The Wire  RACHNA KHAIRA ON 06/01/2018

It was only last November that the UIDAI asserted that “Aadhaar data is fully safe and secure and there has been no data leak or breach at UIDAI”. On Wednesday, The Tribune “purchased” a service being offered by anonymous sellers over WhatsApp that provided unrestricted access to details for any of the more than one billion Aadhaar numbers created in India thus far.

It took just Rs 500, paid through Paytm, and ten minutes in which an “agent” of the group running the racket created a “gateway” for this correspondent and gave a login ID and password. Lo and behold, you could enter any Aadhaar number in the portal, and instantly get all particulars that an individual may have submitted to the UIDAI (Unique Identification Authority of India), including name, address, postal code (PIN), photo, phone number and email.

What is more, The Tribune team paid another Rs 300, for which the agent provided “software” that could facilitate the printing of the Aadhaar card after entering the Aadhaar number of any individual.

When contacted, UIDAI officials in Chandigarh expressed shock over the full data being accessed, and admitted it seemed to be a major national security breach. They immediately took up the matter with the UIDAI technical consultants in Bangaluru. Sanjay Jindal, additional director-general, UIDAI regional centre, Chandigarh, accepting that this was a lapse, told The Tribune: “Except the director-general and I, no third person in Punjab should have a login access to our official portal. Anyone else having access is illegal, and is a major national security breach.”

One lakh illegal users

ADVERTISEMENT

Investigations by The Tribune reveal that the racket may have started around six months ago, when some anonymous groups were created on WhatsApp. These groups targeted over three lakh village-level enterprise (VLE) operators hired by the Ministry of Electronics and Information Technology (ME&IT) under the Common Service Centres Scheme (CSCS) across India, offering them access to UIDAI data.

CSCS operators, who were initially entrusted with the task of making Aadhaar cards across India, were rendered idle after the job was withdrawn from them. The service was restricted to post offices and designated banks to avoid any security breach in November last year.

Spotting an opportunity to make a quick buck, more than one lakh VLEs are now suspected to have gained this illegal access to UIDAI data to provide “Aadhaar services” to common people for a charge, including the printing of Aadhaar cards. However, in the wrong hands, this access could provide an opportunity for gross misuse of the data.

The hackers seemed to have gained access to the website of the government of Rajasthan, as the “software” provided access to “aadhaar.rajasthan.gov.in”, through which one could access and print Aadhaar cards of any Indian citizen. However, it could not be ascertained whether the “portals” were genuinely of Rajasthan, or it was mentioned just to mislead.

Jindal said all of this could be confirmed only after a technical investigation was conducted by the UIDAI.

‘Privacy at risk’

“Leakage of Aadhaar data reveals that the project has failed the privacy test. At the recently concluded 11th WTO Ministerial Conference, India submitted a written position on e-commerce, opposing the demand for negotiations on e-commerce by the US and its allies. The latter were demanding access to citizens’ database for free. The revelation by The Tribune also means that the proposed data protection law will now hold no purpose, as the data has already been breached. The state governments must immediately disassociate themselves and cancel the MoU signed with UIDAI,” said Gopal Krishan, New Delhi-based convener of the Citizens Forum for Civil Liberties, who appeared before the Special Parliamentary Committee that examined the Aadhaar Bill in 2010.

A quick chat, and full access

  • 12:30 pm: This correspondent posing as ‘Anamika’ contacted a person on WhatsApp number 7610063464, who introduced himself as ‘Anil Kumar’. He was asked to create an access portal.
  • 12:32pm: Kumar asked for a name, email ID and mobile number, and also asked for Rs 500 to be credited in his Paytm No. 7610063464.
  • 12:35 pm: This correspondent created an email ID, aadharjalandhar@gmail.com, and sent mobile number ******5852 to the anonymous agent.
  • 12:48 pm: Rs 500 transferred through Paytm.
  • 12:49 pm: This correspondent received an email saying, “You have been enrolled as Enrolment Agency Administrator for ‘CSC SPV’. Your Enrolment Agency Administrator ID is ‘Anamika_6677’.” Also, it was said that a password would be sent in a separate mail, which followed shortly.
  • 12:50 pm: This correspondent had access to the Aadhaar details of every Indian citizen registered with the UIDAI.

Printing Aadhaar card

This correspondent later again approached Anil Kumar to ask for software to print Aadhaar cards. He asked for Rs 300 through Paytm No. 8107888008 (in the name of ‘Raj’). Once paid, a person identifying himself as Sunil Kumar called from mobile number 7976243548, and installed software on this correspondent’s computer by accessing it remotely through “TeamViewer”. Once the job was done, he deleted the software drivers, even from the recycle bin.

Possible misuse

This could allow getting SIM cards or bank accounts in anyone’s name. Last month, a man was arrested in Jalandhar for withdrawing money from someone’s bank account by submitting a fake Aadhaar card.

UIDAI denies report

In a statement released later on Thursday, UIDIA said, “Unique Identification Authority of India (UIDAI) has denied the media report published in The Tribune titled “Rs 500, 10 minutes, and you have access to billion Aadhaar details” and has said that it is a case of misreporting. UIDAI assured that there has not been any Aadhaar data breach. The Aadhaar data including biometric information is fully safe and secure.”

“…UIDAI maintains complete log and traceability of the facility and any misuse can be traced and appropriate action taken. The reported case appears to be instance of misuse of the grievance redressal search facility. As UIDAI maintains complete log and traceability of the facility, the legal action including lodging of FIR against the persons involved in the instant case is being done,” the statement continued. “…Claims of bypassing or duping the Aadhaar enrolment system are totally unfounded. Aadhaar data is fully safe and secure and has robust uncompromised security. The UIDAI Data Centres are infrastructure of critical importance and is protected accordingly with high technology conforming to the best standards of security and also by legal provisions.”

This article was originally published by The Tribune and is republished here with permission. The update on UIDAI denying the report was added by The Wire later.

Previous Post

Five bodies recovered from avalanche site in J-K

Next Post

Need to break vortex of violence in Kashmir: Mehbooba Mufti

Kashmir Pen

Kashmir Pen

Next Post
Jammu and Kashmir government bars employees from criticising its policies on social media

Need to break vortex of violence in Kashmir: Mehbooba Mufti

ADVERTISEMENT
Facebook Twitter Youtube RSS

©2020 KashmirPEN | Made with ❤️ by Uzair.XYZ

No Result
View All Result
  • Home
  • Latest News
  • State News
  • COVID-19
  • Kashmir
  • National
  • International
  • Education
  • Sports
  • Entertainment
  • Technology
  • Weekly
    • Perception
    • Perspective
    • Narrative
    • Concern
    • Nostalgia
    • Tribute
    • Viewpoint
    • Outlook
    • Opinion
    • Sufi Saints of Kashmir
    • Personality
    • Musing
    • Society
    • Editorial
    • Analysis
    • Culture
    • Cover Story
    • Book Review
    • Heritage
    • Art & Poetry

©2020 KashmirPEN | Made with ❤️ by Uzair.XYZ