Umang portal: Researchers flag several flaws in the app, is your Aadhaar or EPFO data at risk?
Two cybersecurity researchers have reported vulnerabilities in the government's Umang portal that they claim could expose sensitive information, including Aadhaar numbers and EPFO details. The government says it has begun fixing the issues. Here's what the researchers found, how officials responded and what it means for users.

Two independent cybersecurity researchers have raised concerns over the security of the government's Umang platform, claiming they discovered vulnerabilities that could potentially expose sensitive citizen data, including Aadhaar numbers and Employees' Provident Fund Organisation (EPFO) details.
The findings, first reported by The Hindu, have prompted the Ministry of Electronics and Information Technology (MeitY) to acknowledge the reported issues and begin implementing security fixes. While the government says corrective measures are underway, the researchers argue that some vulnerabilities remain insufficiently addressed.
Here is what the reported flaws are, the data they may have affected, and what users should know.
Launched in November 2017 during the fifth Global Conference on Cyberspace in New Delhi, Umang serves as a single gateway for thousands of government services.
The platform integrates more than 2,400 services offered by the Centre and state governments, allowing citizens to access facilities such as EPFO accounts, pension services, healthcare, certificates, utility services and other public schemes through one application.
Because it acts as a central access point for multiple government departments, any security issue affecting the platform has the potential to impact a large number of users.
What vulnerabilities did the researchers report?
Security researchers Akshay CS and Viral Vaghela told The Hindu they had identified multiple weaknesses affecting several services available through Umang.
According to the report, Aadhaar numbers were allegedly visible in plain text across a number of integrated services where user identities were stored, despite such storage not being permitted under the Aadhaar Act, 2016. The researchers clarified that Umang's dedicated Aadhaar module itself was not affected.
They also claimed the flaws exposed information linked to EPFO Universal Account Numbers (UANs) and LPG booking records associated with at least one major oil marketing company.
The researchers have deliberately withheld technical details because they believe some of the vulnerabilities remain active. They warned that, in theory, cybercriminals possessing UAN details could potentially alter linked bank account information and initiate withdrawals. However, there is no evidence that the vulnerabilities were exploited or that any user funds were stolen.
The EPFO service is particularly significant because it is Umang's most frequently used module, processing more than 40 crore transactions over the past three months.
How has the government responded?
After discovering the alleged flaws, the researchers reported them to MeitY, the Indian Computer Emergency Response Team (CERT-In) and EPFO.
Shortly afterwards, EPFO temporarily took parts of its online portal offline for what it described as a system migration. Although the organisation did not explicitly connect the downtime to the researchers' findings, they believe the timing was linked to their disclosure.
MeitY has acknowledged the reported vulnerabilities and said its development and security teams are implementing corrective and preventive measures.
According to the Ministry, information that had previously appeared in plain text through certain application programming interfaces (APIs) has now been encrypted. It also said it reviewed API transaction logs covering the previous three months and found no unusual activity, while continuing to monitor the platform.
The researchers, however, contend that the encryption introduced by the Ministry remains insufficient, arguing that it can still be bypassed using relatively simple methods.
Why is this significant?
The disclosure comes as cybersecurity risks surrounding government digital infrastructure are receiving greater attention. As more public services move online, protecting sensitive personal information—including identity documents, financial records and welfare data—has become increasingly important.
The episode also coincides with growing concerns over the role of advanced artificial intelligence in cybersecurity. Frontier AI models are becoming capable of identifying software vulnerabilities far more efficiently than traditional methods. While this can help organisations detect weaknesses faster, experts also warn that the same capabilities could be misused by malicious actors to discover exploitable flaws.
Reflecting these concerns, IT Secretary S Krishnan recently revealed that CERT-In has established a dedicated "war room" to audit critical government software using locally hosted open-source AI models. He said these systems currently possess around 60-70 per cent of the capabilities of Anthropic's advanced Mythos model, while confirming that India is also seeking access to more powerful frontier AI systems through discussions with US authorities and technology companies.
Although the government says it is addressing the reported vulnerabilities, the incident highlights the importance of continuous security testing, responsible vulnerability disclosure and rapid remediation as India's digital public infrastructure continues to expand.
Tags

Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
US accuses China's Moonshot AI of using Anthropic's Fable to build K3 model
Apple's biggest Mac refresh in years could bring 11 new models: Report
Amazon lays off employees in its Artificial General Intelligence (AGI) division
