Unprotected Jharkhand Government Site Exposes Over 100,000 Aadhaar Numbers
A lack of password protection on a state government attendance system in India exposes more than 100,000 Aadhaar numbers through easily accessible photo file names.
A major security lapse exposes over 100,000 Aadhaar numbers through an unprotected government attendance website in the Indian state of Jharkhand. The system, which tracks government workers, lacks password protection and remains openly accessible to anyone as far back as 2014. Visitor access to the site reveals worker names, job titles, and partial phone numbers for approximately 166,000 employees.
The confidential 12-digit Aadhaar numbers are easily extracted because the system uses the unique identifiers as file names for worker profile photos. While this is not a direct breach of the central database operated by the Unique Identification Authority of India (UIDAI), it highlights a significant failure in the handling of sensitive citizen information. Security researcher Baptiste Robert demonstrates that a simple Python script scrapes the entire database of photos and corresponding Aadhaar numbers in batches.
TechCrunch verifies a selection of the exposed numbers using UIDAI's own official verification tool, confirming the validity of the leaked data. The insecure site sits on a subdomain of the state government's website and is fully indexed by Google, meaning cached copies of the records remain publicly available even if the site goes offline. This incident adds to the growing list of vulnerabilities surrounding India's massive biometric identity system, which over 90 percent of the population relies on for essential services.