OwlBrief

Stay informed, stay wise!

OwlBrief gives busy professionals the world’s top stories in seconds — five ultra-fast, AI-crafted briefs a day. Stay informed, stay wise, and never waste time on fluff.

Create account Log in
#Cybersecurity

Exclusive: Bug in India's income tax portal exposed taxpayers’ sensitive data

A security vulnerability in India's income tax portal allowed unauthorized access to sensitive taxpayer data. This breach raises significant concerns about data privacy and security for millions of users.
Exclusive: Bug in India's income tax portal exposed taxpayers’ sensitive data
A What happened
A serious security vulnerability in India's income tax filing portal was identified by researchers Akshay CS and 'Viral,' who discovered that logged-in users could access sensitive personal and financial data of other taxpayers. This flaw, known as an insecure direct object reference (IDOR), allowed users to manipulate their Permanent Account Number (PAN) in network requests to view others' information, including names, addresses, and bank details. The Indian Income Tax Department has since fixed the issue, but the potential exposure of data for over 135 million registered users raises significant concerns about data security. The researchers alerted India's computer emergency readiness team (CERT-In) shortly after discovering the flaw, but the timeline for the fix was unclear. The incident highlights the need for stronger security measures in government systems to protect sensitive information.

Key insights

  • 1

    Data exposure risk

    The vulnerability exposed sensitive data of millions of taxpayers.

  • 2

    Flaw type identified

    The issue was classified as an insecure direct object reference (IDOR).

  • 3

    Fix implemented

    The Indian government has addressed the security flaw after it was reported.

Takeaways

The exposure of sensitive taxpayer data through a security flaw in India's income tax portal underscores the critical need for robust cybersecurity measures in government systems to protect citizens' personal information.