An investigation by Indian newspaper The Tribune reported that access to personal details in Aadhaar, India’s biometric identity system covering more than a billion people, was being sold on WhatsApp for Rs 500.
What happened
- A reporter said she received login details within minutes of paying an anonymous seller through Paytm.
- The access reportedly allowed her to view names, addresses, postcodes, photos, phone numbers, and email addresses for any Aadhaar number entered.
- The Unique Identification Authority of India (UIDAI) denied that its biometric database had been breached and said the data had been misused through a grievance portal.
- The UIDAI filed a police complaint that named the reporter, which was widely criticised by press freedom groups.
Why it mattered
The story fuelled debate over the security of the world’s largest biometric ID system and the risks of centralising citizens’ data. India’s Supreme Court upheld the scheme later in 2018, but placed limits on its use.
Lessons for organisations
Limit access to large databases to those who need it, review access regularly, and monitor for unusual lookups. Responding openly to reported weaknesses builds more trust than denial.
Source: The Tribune
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.