Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
IT Grids Aadhaar data leak: UIDAI’s implicit acknowledgement of a large-scale data breach will be very welcome to anti-Aadhaar activists
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • India
  • IT Grids Aadhaar data leak: UIDAI’s implicit acknowledgement of a large-scale data breach will be very welcome to anti-Aadhaar activists

IT Grids Aadhaar data leak: UIDAI’s implicit acknowledgement of a large-scale data breach will be very welcome to anti-Aadhaar activists

Asheeta Regidi • April 16, 2019, 07:42:04 IST
Whatsapp Facebook Twitter

The breach points, yet again, to major concerns with the security of data in the Aadhaar ecosystem.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
IT Grids Aadhaar data leak: UIDAI’s implicit acknowledgement of a large-scale data breach will be very welcome to anti-Aadhaar activists

The increased focus on social media and technology as an enabler for the current elections meant that it was only a matter of time before reports of misuse of data for political purposes arose. The current report of  **finding 7.8 crore Aadhaar data records** with IT Grids (India) Pvt Ltd, which were for use in the Seva Mitra app, however, are not significant for this misuse. Instead, the significance lies in that it has, for the first time, led to the UIDAI acknowledging the possibility of a large-scale breach of the Central Identities Data Repository (CIDR) and the State Resident Data Hubs (SRDH). [caption id=“attachment_4865121” align=“alignnone” width=“1024”]Representational image. Representational image.[/caption] The breach points, yet again, to major concerns with the security of data in the Aadhaar ecosystem. The UIDAI, in fact, has also not ruled out the possibility of an internal breach by its employees. Apart from this, there is a possibility of offshore transfer of the data, leading to fears of exposure to foreign elements.

On the find of 7.8 crore data records

At present, the Hyderabad police have filed an FIR against IT Grids on a complaint by the UIDAI.  The complaint, filed by Bhavani Prasad, the Deputy Director of the UIDAI, indicates numerous violations of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the Information Technology Act, 2000, as well. As per the complaint, an investigation of IT Grids led to the suspicion of its use of stolen voter information and Aadhaar data of Andhra Pradesh and Telangana, for voter profiling, targeted campaigning and even deletion of votes. The use was through the Seva Mitra application, an application which IT Grids had developed for the Telugu Desam Party (TDP).

FIR 278/2019 by Cyberabad Police in Madhapur on the request of @UIDAI against IT Grids Pvt Ltd. First time in a #Aadhaar case there is a forensic investigation which was missing in all other UIDAI security claims. pic.twitter.com/8gDI3LmpRt

— Srinivas Kodali (@digitaldutta) April 15, 2019

Digital evidence including hard disks that were seized from the IT Grids Office were examined by the Telangana State Forensic Science Laboratory (TSFSL). This was discovered to contain over 7.8 crore records of the Aadhaar data. The fields of data included the Aadhaar number, the Aadhaar enrolment ID, the person’s name, his guardian’s name, his address and his contact details. So far there is no indication of the inclusion of biometric data, though some  reports have suggested that photographs were also present.

‘Surprisingly similar’ database to that of the UIDAI’s

The UIDAI in its complaint states that the structure and size of this database is ‘surprisingly very similar’ to the databases that were originally owned by the UIDAI. Of the numerous fields of data that were found, the complaint takes particular note of the presence of Aadhaar enrolment IDs, stating that this indicates that the data was either from the CIDR or the SRDHs. The complaint thus, for the first time, shows the UIDAI acknowledging a possible breach of the CIDR and SRDHs, as opposed to its characteristic denial.

UIDAI acknowledges possible internal breach as well as hacking

Further, the complaint lists Section 38(g) of the Aadhaar Act among those violated, a section that deals with the UIDAI or its officials revealing any identity information in contravention of the Act. This shows that the UIDAI is considering the possibility of an internal breach through its officers for the first time as well.

The UIDAI also suspects hacking, possibly in the form of the source code of the CIDR or the SRDHs being tampered with, since Section 65 of the Information Technology Act, 2000 (Tampering with computer source documents) has also been listed in the complaint.

Provisions for the breach of the database itself

Apart from these, a number of additional sections have been listed for the theft of the data in itself. These include Section 29 of the Aadhaar Act for the sharing and use of the identity information for a purpose outside the scope of the Act, Section 40 of the Aadhaar Act for the misuse of identity information by the requesting entities and Section 42 for any residuary violations. It also lists other violations of the IT Act, including Section 66B for the dishonest receipt of a stolen computer resource (i.e., the receipt and use of the Aadhaar database) and Section 72A for the disclosure of information in breach of a lawful contract. Though not listed, the breach also points to the violation of Sections 38(a) and (b) of the Aadhaar Act for access to and download of data from the CIDR.

Offshore storage of data

Another particular concern is that the data with IT Grids is suspected to have been hosted with Amazon Web Services in the US and other offshore facilities, raising questions as to the extent to which the data has been exposed to foreign elements as well. Even though the data exposed does not appear to include biometric data, it is a point of concern that the laws at present do not propose separate or heightened penalties for the disclosure of such sensitive data to foreign locations.

Penalties up to a crore and three years of imprisonment

It is clear that the UIDAI is considering violations at various levels including internally, through the requesting entities, or through any other entity in the Aadhaar ecosystem. The violations listed together draw a penalty of up to three years of imprisonment, and fines of up to Rs 10 lakhs. A more major penalty is under Section 33A of the Aadhaar and Other Laws (Amendment) Ordinance, 2019, which allows a penalty of up to Rs 1 crore for an entity failing to comply with the Aadhaar Act (the Ordinance has currently been challenged before the Delhi High Court). This section, however, has currently not been listed under the complaint.

Moving forward

The vulnerability of the Aadhaar ecosystem has long since been a major bone of contention amongst those for and against Aadhaar, and in the Aadhaar case fought last year as well. The acknowledgment of this after years of denial will be very welcome for the anti-Aadhaar activists.

Our government has been lying to us about Aadhaar.

Once they've collected this data, the exposure surface (of people involved+ with whom it is shared) is so vast, that it bound to leak.

It has been leaking: from the beginning, collection, till today, and will continue to leak. https://t.co/kcxv9YFIRg

— Nikhil Pahwa (@nixxin) April 15, 2019
More from India
PM Modi meets Manipur violence victims in first visit since 2023 unrest PM Modi meets Manipur violence victims in first visit since 2023 unrest 'Mizoram is at the forefront now': PM Modi inaugurates Bairabi-Sairang New Rail line in Aizawl 'Mizoram is at the forefront now': PM Modi inaugurates Bairabi-Sairang New Rail line in Aizawl

The acknowledgement, however, will need to be followed up with proper steps to secure the CIDR itself as well as to protect the data that has been exposed. The off-hand storage of the data overseas is a major point to be addressed as well, given the exposure it entails to foreign elements. The author is a lawyer specialising in technology, privacy, and cyber laws.

Tags
Aadhaar Telangana UIDAI Aadhaar Act Aadhaar breach CIDR TechFeature Seva Mitra App
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

NDA's CP Radhakrishnan wins vice presidential election

NDA's CP Radhakrishnan wins vice presidential election

CP Radhakrishnan of BJP-led NDA won the vice presidential election with 452 votes, defeating INDIA bloc's B Sudershan Reddy who secured 300 votes. The majority mark was 377.

More Impact Shorts

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports

QUICK LINKS

  • Mumbai Rains
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV