
Tax portal glitch exposed millions of Indians’ financial data
The Indian government has fixed a serious security flaw in its online income tax filing portal that exposed the personal and financial data of millions of taxpayers. The vulnerability, discovered by two independent security researchers, could have allowed unauthorized access to sensitive details, including Aadhaar numbers and bank account information.
According to findings, security researchers Akshay CS and “Viral” identified the flaw in September while filing their own returns on the government’s e-Filing website. The issue known as an Insecure Direct Object Reference (IDOR) vulnerability allowed logged-in users to view others’ data simply by changing the Permanent Account Number (PAN) in network requests. This exposed full names, addresses, contact details, and financial data of both individuals and companies registered on the platform. The researchers promptly notified India’s Computer Emergency Response Team (CERT-In), which confirmed that the Income Tax Department was working to fix the issue. The vulnerability was fully resolved by October 2, 2025.
While the government has not confirmed how long the flaw existed or whether it was exploited, the exposure potentially affected more than 135 million registered users on the portal. Cybersecurity experts have called the bug a “low-hanging but severe” lapse that underscores the need for stronger data protection and regular audits in critical government systems. CERT-In and the Income Tax Department have not commented publicly on whether additional safeguards or notifications will be issued, but researchers and privacy advocates stress that such incidents highlight the urgent importance of secure digital infrastructure as India continues to expand its online governance initiatives.
