HomeTechnologySecurity flaw in Income Tax website exposed bank, Aadhaar details of Indian taxpayers

Security flaw in Income Tax website exposed bank, Aadhaar details of Indian taxpayers

A major bug in India’s Income Tax portal exposed taxpayers’ bank, Aadhaar, and personal details before it was fixed by the government.

October 08, 2025 / 10:16 IST
Story continues below Advertisement
Income tax
Income tax

India’s income tax e-filing portal used by more than 135 million people had a major security flaw that exposed taxpayers’ private information, including bank details and Aadhaar numbers, according to a TechCrunch report. The government has since fixed the issue, but not before sensitive data of countless users was potentially left vulnerable.

The flaw, discovered in September by two security researchers, Akshay CS and “Viral,” made it alarmingly easy for anyone logged into the tax portal to access another person’s financial records. All it took was swapping out one PAN (Permanent Account Number) for another in a simple network request. Using everyday tools like Postman or even browser developer tools, anyone could view another taxpayer’s name, address, date of birth, phone number, bank account details, and Aadhaar number — all without authorization.

Story continues below Advertisement

“This is an extremely low-hanging thing, but one that has a very severe consequence,” the researchers told TechCrunch.

Essentially, the system failed to verify who was allowed to access what data a basic security check known as “access control.” Because of this oversight, the portal left both individuals’ and companies’ sensitive data exposed. The vulnerability was confirmed by TechCrunch and later verified to have been fixed on October 2, after which the report was made public.