Skip to main content

135 million aadhaar details, 100 million bank accounts "leaked" from government websites: Researchers

Screenshot from a NREGA site: Researchers hide details 
Counterview Desk
A top study by the Centre for Internet and Society (CIS) has said that “estimated number of aadhaar numbers leaked” through top portals which handle aadhaar “could be around 130-135 million”. Worse, it says, the number of bank accounts numbers leaked would be “around 100 million”.
The study, carried out by researchers Amber Sinha and Srinivas Kodali, adds, “While these numbers are only from two major government programmes of pensions and rural employment schemes, other major schemes, who have also used aadhaar for direct bank transfer (DBT) could have leaked personally identifiable information (PII) similarly due to lack of information security practices.”
Pointing out that “over 23 crore beneficiaries have been brought under aadhaar programme for DBT”, the study, titled “Information Security Practices of Aadhaar (Or Lack Thereof)”, says, “Government schemes dashboard and portals demonstrate … dangers of ill-conceived data driven policies and transparency measures without proper consideration to data security measures.”
Claiming to have a closer look at the databases publicly available portals, the researchers identify four of them a pool of other government websites for examination:
A welfare programme by the Ministry of Rural Development, the National Social Assistance Programme (NSAP) portal, even as seeking to provide public assistance to its citizens in case of unemployment, old age, sickness and disablement, offers information about “job card number, bank account number, name, aadhaar number, account frozen status”, the researchers say.
Pointing out that “one of the url query parameters of website showing the masked personal details was modified from nologin to login”, they say, the “control access to login based pages were allowed providing unmasked details without the need for a password.”
Another NREGA site screenshot by researchers
In fact, they say, the Data Download Option feature “allows download of beneficiary details mentioned above such as Beneficiary No, Name, Father’s/Husband’s Name, Age, Gender, Bank or Post Office Account No for beneficiaries receiving disbursement via bank transfer and Aadhaar Numbers for each area, district and state.”
They add, “The NSAP portal lists 94,32,605 banks accounts linked with aadhaar numbers, and 14,98,919 post office accounts linked with aadhaar numbers. While the portal has 1,59,42,083 aadhaar numbers in total, not all of whom are linked to bank accounts.”
Also giving the example of the national rural job guarantee scheme, popularly called NREGA, the researchers say, its portal provides DBT reports containing “various sub-sections including one called ‘Dynamic Report on Worker Account Detail’,” with details like “Job card number, aadhaar number, bank/postal account number, number of days worked”, and so on.
“As per the NREGA portal, there were 78,74,315 post office accounts of individual workers seeded with aadhaar numbers, and 8,24,22,161 bank accounts of individual workers with aadhaar numbers. The total number of Aadhaar numbers stored by portal are at 10,96,41,502”, they add.
Providig similar instances form two other sources, the researchers insist, “The availability of large datasets of aadhaar numbers along with bank account numbers, phone numbers on the internet increases the risk of financial fraud.”
Underlining that “aadhaar data makes this process much easier for fraud and increases the risk around transactions”, they say, “In the US, the ease of getting Social Security Numbers from public databases has resulted in numerous cases of identity theft. These risks increase multifold in India due the proliferation of aadhaar numbers and other related data available.”

Comments

TRENDING

Incarceration of Prof Saibaba 'revives' the question: What is crime, who is criminal?

By Kunal Pant* In 2016, a Supreme Court Judge asked the state of Maharashtra, “Do you want to extract a pound of flesh?” The statement was directed against the state for contesting the bail plea of Delhi University Professor GN Saibaba. Saibaba was arrested in 2014, a justification for which was to prevent him from committing what the police called “anti-national activities.”

When Sardar Patel opposed reservation, asked Scheduled Castes to give up their “inferiority” complex

Jawaharlal Nehru, Sardar Patel By Dr Hari Desai* It is ironical indeed. Though Sardar Vallabhbhai Patel was opposed to any kind of reservation in the government jobs and education as well as in the legislatures (like Mahatma Gandhi), even today his name is being drawn in controversies in the present-day agitations demanding reservation in India.

Activists Akriti, Satyam Verma face NSA in Noida protest case: PUCL

By A Representative   Human rights activist Kavita Shrivastava has alleged that the Uttar Pradesh Police is invoking the National Security Act (NSA) against two activists associated with Mazdoor Bigul in connection with the Noida workers’ protest case, even as labour unrest continues to spread across industrial belts in several northern states.