Breach report
GovernmentAadhaar (Unique Identification Authority of India)
Rs 500, 10 minutes, and you have access to billion Aadhaar details
A reporter bought login access to India's Aadhaar identity database for about 500 rupees via WhatsApp, revealing that personal details of more than a billion residents could be looked up by anyone willing to pay.
Reported by The Tribune
Records exposed
1.1B
More than 1 billion enrolled residents potentially exposed
Scale vs. largest on file
- When
- 2018
- How they got in
- Illicit sale of access credentials to a government enrollment portal
- Sector
- Government
On January 4, 2018, the Indian newspaper The Tribune reported that one of its journalists had purchased access to the Aadhaar system, India's national biometric identity database, from an anonymous seller on WhatsApp. For about 500 rupees, roughly $8 at the time, the reporter received a username and password within minutes that allowed her to enter any Aadhaar number and retrieve the holder's name, address, postal code, photo, phone number and email address. For a further 300 rupees, the seller offered software to print Aadhaar cards.
Aadhaar holds records on more than a billion residents and is used to access welfare benefits, bank accounts, mobile phone connections and tax filings. The Tribune found that the access appeared to stem from credentials issued to village-level enrollment operators, some of whose official roles had ended, and that the illicit service was being resold through informal networks.
The Unique Identification Authority of India denied that biometric data had been breached and described the incident as misuse of a grievance-redressal search facility. It then filed a police complaint that named the newspaper and its reporter, a move that drew widespread condemnation from press freedom groups and opposition politicians. The case reached Parliament and fed an ongoing Supreme Court challenge to Aadhaar's mandatory use. The government has consistently maintained that the core repository of fingerprints and iris scans has never been breached.
The Tribune story was one of several Aadhaar exposures that year. In March 2018, security researchers showed that a state-owned utility's system allowed anyone to query Aadhaar numbers and retrieve personal information, and government websites were repeatedly found publishing Aadhaar numbers in spreadsheets. In September 2018 the Supreme Court upheld Aadhaar's constitutionality but barred private companies from requiring it, and India later passed a broader data protection law in 2023.
The episode shows the systemic risk of national ID schemes. A single identifier linked to banking, telecom and welfare becomes enormously valuable to fraudsters, and security is only as strong as the weakest of the thousands of intermediaries granted access. For citizens, there is no practical way to change an identity number once it has been exposed.