UMANG portal flaws exposed user data across hundreds of services, researchers find

Security researchers have identified significant design flaws in India's UMANG government portal that exposed sensitive user data, including Aadhaar numbers and EPFO account details. While the Ministry of Electronics and Information Technology claims to have implemented fixes, independent experts argue the measures are inadequate and potentially introduce new security risks.
Why it matters
The vulnerabilities pose a major risk to millions of Indian citizens, potentially allowing cybercriminals to access personal identification and siphon funds from government-managed accounts.
Multiple vulnerabilities in the Unified Mobile Application for New-age Governance (UMANG), a government portal that aggregates hundreds of public services offered by the Union and State Governments, are leaving potentially millions of Indians’ data exposed across a variety of databases, including those from the Employees’ Provident Fund Organisation (EPFO), according to two security researchers who shared their findings with The Hindu .
The vulnerabilities, which have likely existed for years, affect several services tested on the UMANG portal, which has onboarded over 2,400 services. It stems from the architecture of the portal itself, said the researchers, Akshay C.S. and Viral Vaghela. “Almost everything is broken by design,” Mr. Vaghela said.
UMANG was launched nine years ago by Prime Minister Narendra Modi at the fifth Global Conference on Cyber Space, which took place in Delhi.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in