Skip to main content

135 million aadhaar details, 100 million bank accounts "leaked" from government websites: Researchers

Screenshot from a NREGA site: Researchers hide details 
Counterview Desk
A top study by the Centre for Internet and Society (CIS) has said that “estimated number of aadhaar numbers leaked” through top portals which handle aadhaar “could be around 130-135 million”. Worse, it says, the number of bank accounts numbers leaked would be “around 100 million”.
The study, carried out by researchers Amber Sinha and Srinivas Kodali, adds, “While these numbers are only from two major government programmes of pensions and rural employment schemes, other major schemes, who have also used aadhaar for direct bank transfer (DBT) could have leaked personally identifiable information (PII) similarly due to lack of information security practices.”
Pointing out that “over 23 crore beneficiaries have been brought under aadhaar programme for DBT”, the study, titled “Information Security Practices of Aadhaar (Or Lack Thereof)”, says, “Government schemes dashboard and portals demonstrate … dangers of ill-conceived data driven policies and transparency measures without proper consideration to data security measures.”
Claiming to have a closer look at the databases publicly available portals, the researchers identify four of them a pool of other government websites for examination:
A welfare programme by the Ministry of Rural Development, the National Social Assistance Programme (NSAP) portal, even as seeking to provide public assistance to its citizens in case of unemployment, old age, sickness and disablement, offers information about “job card number, bank account number, name, aadhaar number, account frozen status”, the researchers say.
Pointing out that “one of the url query parameters of website showing the masked personal details was modified from nologin to login”, they say, the “control access to login based pages were allowed providing unmasked details without the need for a password.”
Another NREGA site screenshot by researchers
In fact, they say, the Data Download Option feature “allows download of beneficiary details mentioned above such as Beneficiary No, Name, Father’s/Husband’s Name, Age, Gender, Bank or Post Office Account No for beneficiaries receiving disbursement via bank transfer and Aadhaar Numbers for each area, district and state.”
They add, “The NSAP portal lists 94,32,605 banks accounts linked with aadhaar numbers, and 14,98,919 post office accounts linked with aadhaar numbers. While the portal has 1,59,42,083 aadhaar numbers in total, not all of whom are linked to bank accounts.”
Also giving the example of the national rural job guarantee scheme, popularly called NREGA, the researchers say, its portal provides DBT reports containing “various sub-sections including one called ‘Dynamic Report on Worker Account Detail’,” with details like “Job card number, aadhaar number, bank/postal account number, number of days worked”, and so on.
“As per the NREGA portal, there were 78,74,315 post office accounts of individual workers seeded with aadhaar numbers, and 8,24,22,161 bank accounts of individual workers with aadhaar numbers. The total number of Aadhaar numbers stored by portal are at 10,96,41,502”, they add.
Providig similar instances form two other sources, the researchers insist, “The availability of large datasets of aadhaar numbers along with bank account numbers, phone numbers on the internet increases the risk of financial fraud.”
Underlining that “aadhaar data makes this process much easier for fraud and increases the risk around transactions”, they say, “In the US, the ease of getting Social Security Numbers from public databases has resulted in numerous cases of identity theft. These risks increase multifold in India due the proliferation of aadhaar numbers and other related data available.”

Comments

TRENDING

Covishield controversy: How India ignored a warning voice during the pandemic

Dr Amitav Banerjee, MD *  It is a matter of pride for us that a person of Indian origin, presently Director of National Institute of Health, USA, is poised to take over one of the most powerful roles in public health. Professor Jay Bhattacharya, an Indian origin physician and a health economist, from Stanford University, USA, will be assuming the appointment of acting head of the Centre for Disease Control and Prevention (CDC), USA. Bhattacharya would be leading two apex institutions in the field of public health which not only shape American health policies but act as bellwether globally.

Growth without justice: The politics of wealth and the economics of hunger

By Vikas Meshram*  In modern history, few periods have displayed such a grotesque and contradictory picture of wealth as the present. On one side, a handful of individuals accumulate in a single year more wealth than the annual income of entire nations. On the other, nearly every fourth person in the world goes to bed hungry or half-fed.

Thali, COVID and academic credibility: All about the 2020 'pseudoscientific' Galgotias paper

By Jag Jivan   The first page image of the paper "Corona Virus Killed by Sound Vibrations Produced by Thali or Ghanti: A Potential Hypothesis" published in the Journal of Molecular Pharmaceuticals and Regulatory Affairs , Vol. 2, Issue 2 (2020), has gone viral on social media in the wake of the controversy surrounding a Chinese robot presented by the Galgotias University as its original product at the just-concluded AI summit in Delhi . The resurfacing of the 2020 publication, authored by  Dharmendra Kumar , Galgotias University, has reignited debate over academic standards and scientific credibility.

The 'glass cliff' at Galgotias: How a university’s AI crisis became a gendered blame game

By Mohd. Ziyaullah Khan*  “She was not aware of the technical origins of the product and in her enthusiasm of being on camera, gave factually incorrect information.” These were the words used in the official press release by Galgotias University following the controversy at the AI Impact Summit in Delhi. The statement came across as defensive, petty, and deeply insensitive.

'Serious violation of international law': US pressure on Mexico to stop oil shipments to Cuba

By Vijay Prashad   In January 2026, US President Donald Trump declared Cuba to be an “unusual and extraordinary threat” to US security—a designation that allows the United States government to use sweeping economic restrictions traditionally reserved for national security adversaries. The US blockade against Cuba began in the 1960s, right after the Cuban Revolution of 1959 but has tightened over the years. Without any mandate from the United Nations Security Council—which permits sanctions under strict conditions—the United States has operated an illegal, unilateral blockade that tries to force countries from around the world to stop doing basic commerce with Cuba. The new restrictions focus on oil. The United States government has threatened tariffs and sanctions on any country that sells or transports oil to Cuba.

When grief becomes grace: Kerala's quiet revolution in organ donation

By Vidya Bhushan Rawat*  Kerala is an important model for understanding India's diversity precisely because the religious and cultural plurality it has witnessed over centuries brought together traditions and good practices from across the world. Kerala had India's first communist government, was the first state where a duly elected government was dismissed, and remains the first state to achieve near-total literacy. It is also a land where Christianity and Islam took root before they spread to Europe and other parts of the world. Kerala has deep historic rationalist and secular traditions.

When a lake becomes real estate: The mismanagement of Hyderabad’s waterbodies

By Dr Mansee Bal Bhargava*  Misunderstood, misinterpreted and misguided governance and management of urban lakes in India —illustrated here through Hyderabad —demands urgent attention from Urban Local Bodies (ULBs), the political establishment, the judiciary, the builder–developer lobby, and most importantly, the citizens of Hyderabad. Fundamental misconceptions about urban lakes have shaped policies and practices that systematically misuse, abuse and ultimately erase them—often in the name of urban development.

Activists warn of gendered impact of VB-GRAMG Act, seek return to MGNREGA framework

By A Representative   The All-India Feminist Alliance (ALIFA), along with the Agrarian Alliance and Workers’ Forum of the National Alliance of People’s Movements (NAPM), has written to President Droupadi Murmu urging her to call upon Parliament to repeal the newly enacted Viksit Bharat–Guarantee for Rozgar and Ajeevika Mission (Gramin) Act, 2025 (VB-GRAMG Act) and restore and strengthen the Mahatma Gandhi National Rural Employment Guarantee Act (MGNREGA).

Stray dogs, an epsilon (ϵ) problem: Of child labour, and the art of misplaced priorities

By Bhaskaran Raman  The Greek alphabet ϵ (epsilon) is used in maths and science to denote a quantity which is not zero, but extremely small *** Since the Supreme Court's interim order on the issue of stray dogs came out on 07 Nov 2025, there have been a range of opinion pieces speaking for the voiceless. Most of them take the stance that there is a "problem" with stray dogs, but that we need a humane solution. I agree with this broadly, but I think we need new terminology to talk about this.