Security researchers have uncovered multiple serious vulnerabilities in the UMANG portal, leaking EPFO UANs, LPG cylinder booking details, and Aadhaar numbers across dozens of services. While the government promises swift patches, experts warn the fixes are incomplete and leave users vulnerable to cyber‑crime.

मुख्य बिंदु (Key Takeaways)

  • UMANG portal vulnerabilities exposed EPFO UANs, LPG bookings, and Aadhaar data
  • Plain‑text storage violates the 2016 Aadhaar Act
  • Government patches appear superficial, leaving large‑scale cyber‑risk

The Unified Mobile Application for New‑age Governance (UMANG) was launched nine years ago by Prime Minister Narendra Modi to consolidate over 2,400 public services from both central and state governments into a single mobile platform. While the initiative promised convenience, two independent security researchers—Akshay C.S. and Viral Vaghela—have revealed that the portal’s architecture inherently leaks sensitive data in plain text.

Root Cause of the Design Flaw

According to the researchers, several APIs within UMANG transmit user information without encryption, a flaw they describe as “broken by design.” This oversight means that Unique Account Numbers (UAN) from the Employees’ Provident Fund Organisation (EPFO), LPG cylinder booking details from a major oil marketing company, and Aadhaar numbers from multiple services are exposed in readable form. Storing Aadhaar data in plain text directly contravenes the Aadhaar Act of 2016, raising legal and privacy concerns.

Why EPFO Matters Most

The EPFO module is the portal’s most heavily trafficked service, recording over 40 crore transactions in the last three months—about fifteen times more than the next busiest use case. If malicious actors obtain these UANs, they could potentially alter bank details or trigger payouts, leading to large‑scale financial theft. Independent researcher Karan Saini labeled this scenario “very concerning.”

Government Response and Patch Limitations

The Ministry of Electronics and Information Technology acknowledged the vulnerabilities in a statement to The Hindu, asserting that “development and security teams have examined the observations and are implementing corrective and preventive measures.” The ministry claimed that the affected APIs now encrypt the previously plain‑text data. However, Akshay pointed out that the encryption is “flawed and inadequate,” and a simple workaround still allows the data to be decoded.

Long‑Term Security Outlook

Experts argue that patching the UMANG gateway alone is insufficient; each downstream service must adopt robust encryption and rate‑limiting controls. Moreover, India’s push to leverage AI models—such as Anthropic’s Mythos—for code‑base auditing could help address legacy vulnerabilities that have persisted for years. The IT Secretary’s recent “war room” initiative, employing locally hosted open‑source models, signals a move toward more proactive security governance.

In sum, the UMANG data breach underscores the urgent need for a comprehensive security overhaul across government digital platforms, ensuring citizen trust is restored through transparency, continuous audits, and stringent data‑protection standards.