In 2009, the Government of India launched a project to assign a 12-digit verifiable number to each citizen, known as the Aadhaar number. Aadhaar links each resident’s identity through multiple factors, including demographic information, biometric data (photograph, fingerprints, and iris scans), and unique identifiers.
Since its launch, Aadhaar has been linked to mobile phone accounts, bank accounts, tax filings, scholarships, pensions, ration programs, school admissions, and health records. Aadhaar is considered the world’s largest biometric identification system, storing records for approximately 90% of India’s population—roughly 1.22 billion people.
The Indian government has publicly praised the technology and security controls implemented within the Aadhaar program, at times describing the system as “unbreachable.” However, numerous disclosures over time have revealed repeated data breaches of varying scale, highlighting significant gaps in security controls protecting this critical database.
Timeline of Breaches
- February 2017: Aadhaar information belonging to approximately 500,000–600,000 children was leaked through a government agency in the state of Telangana.
- March 2017: The Ministries of Drinking Water and Sanitation and Human Resource Development publicly exposed an unknown number of Aadhaar records.
- April 2017: Multiple reports surfaced describing new data leaks from government and industry websites, exposing millions of Aadhaar-linked personal records.
- May 2017: Approximately 130–135 million Aadhaar numbers and 100 million bank account records were exposed across four government websites supporting social assistance, employment, payments, and insurance programs.
- August 2017: A Punjab government housing website leaked 20,100 Aadhaar records belonging to applicants for low-cost housing.
- October 2017: A medical college in Punjab exposed Aadhaar details for 12,200 students.
- January 4, 2018: A local newspaper reported that complete Aadhaar records could be accessed and searched for as little as $8 via WhatsApp intermediaries, with data reportedly sold for as little as 2–7 cents per record.
- March 2018: A faulty Aadhaar software patch granted elevated access privileges, allowing users to bypass iris scans and GPS verification, potentially exposing the entire database of approximately 1.2 billion records.
- April 26, 2018: Aadhaar data for 8.9 million workers was leaked through a government employment assistance website maintained by a third-party IT contractor.
- April 27, 2018: A previously reported school data leak expanded from 500,000–600,000 records to approximately 6.7 million children’s Aadhaar records.
- April 30, 2018: A government website exposed roughly 2 million Aadhaar records of pregnant women, including reproductive history, health risk status, and infant vaccination data.
- February 15, 2019: A misconfigured government website operated by state-owned oil and gas company Indane exposed approximately 6.7 million Aadhaar records due to a lack of authentication on a dealer portal.
Government Response
The Indian government has consistently defended the security of the Aadhaar system, dismissing claims of systemic vulnerabilities and asserting the integrity and confidentiality of the database. However, the frequency and scale of reported breaches contradict these assurances.
Investigations by India’s Tribune newspaper reported that journalists were able to gain administrative access to Aadhaar systems for approximately $95, allowing the creation of new user accounts with elevated privileges. In another instance, full database search access was reportedly obtained for as little as $8 via WhatsApp transactions. If accurate, such access undermines database integrity and enables large-scale identity fraud.
The Unique Identification Authority of India (UIDAI), which administers Aadhaar, has repeatedly denied vulnerability claims and stated that “Aadhaar data is fully safe and secure and has robust, uncompromising security.” UIDAI has also pursued legal action against journalists and researchers who publicly challenged these claims.
What Could Have Been Done?
Absolute security does not exist. Protecting large-scale systems requires continuous monitoring, regular security assessments, and well-documented operational controls. These include network diagrams, access management policies, defined roles and responsibilities, incident response procedures, and effective communication plans.
Aadhaar reportedly failed to communicate known vulnerabilities and prior breaches to integration partners. Additionally, multiple security researchers reported discovering vulnerabilities but refrained from disclosure due to fear of legal repercussions or harassment.
As systems become increasingly interconnected and data availability demands grow, security risks also increase. While accessibility and availability are essential, the protection of sensitive information must not be underestimated. Industry standards, frameworks, and best practices exist to guide organizations in managing cybersecurity risk.
Security assessments provide organizations with a clear understanding of their overall security posture, identify weaknesses, measure compliance gaps, and highlight deficiencies in existing security controls. These assessments are critical to preventing large-scale data exposures like those experienced by Aadhaar.