Multiple vulnerabilities were discovered in the UMANG portal, exposing data of potentially millions of Indian citizens.
The flaws, identified by security researchers Akshay C.S. and Viral Vaghela, affected services including the Employees’ Provident Fund Organisation (EPFO) and Aadhaar numbers.
Exposed data included Unique Account Numbers (UAN), LPG booking details, and Aadhaar numbers stored in plain text, violating the Aadhaar Act, 2016.
The Ministry of Electronics and Information Technology acknowledged the vulnerabilities and stated that corrective measures were being implemented.
Despite initial fixes, researchers deemed the encryption "flawed and inadequate," with a simple workaround still allowing access.
Detailed Insights:
The vulnerabilities stemmed from the fundamental architecture of the UMANG portal, which aggregates over 2,400 public services.
The EPFO module is the most-used service on UMANG, recording over 40 crore transactions in three months.
Storing Aadhaar numbers in plain text is explicitly disallowed by the Aadhaar Act, 2016, raising significant privacy concerns.
Independent security researcher Karan Saini confirmed the vulnerabilities as "significant" and expressed concern over potential exploitation by cybercriminals.
The researchers reported the issues to the IT Ministry and the Computer Emergency Response Team, India (CERT-In).
Following the alerts, the EPFO temporarily took down its online portal for a "migration," suggesting a response to the reported flaws.
The inadequacy of the initial fixes highlights the challenge of securing complex digital public infrastructure.
Key Concepts Involved:
UMANG (Unified Mobile Application for New-age Governance): A mobile application developed by the Ministry of Electronics and Information Technology to provide access to various government services.
Employees’ Provident Fund Organisation (EPFO): A statutory body under the Ministry of Labour and Employment, responsible for regulating and managing provident funds in India.
Aadhaar Act, 2016: A law that provides for the legal framework for the Aadhaar unique identification number and its use in various services.
Computer Emergency Response Team, India (CERT-In): The national agency for responding to computer security incidents, issuing alerts, and providing solutions for vulnerabilities.