Science & TechnologyGovernance
News 0 of 30

UMANG Portal Security Flaws Exposed UAN, Aadhaar Data; EPFO Module (40 Cr Transactions) Most Affected

Target:UPSC GS-IIIMPSCSSC GATeachingPrelims HighMains MediumStatic GK Link
13 Jul 2026
~2 min
Source: The Hindu
Key Data:over 2400 services40 crore transactions in last 3 monthsAadhaar Act 2016nine years ago (2017)UMANG launched at 5th Global Conference on Cyber Space
Bodies:MeitYCERT-inEPFOMinistry of Labour and Employment
Practice MCQs from today's news ▸
What This Article Covers

1.Researchers found design flaws in UMANG portal exposing Aadhaar numbers (in plaintext) and EPFO UANs across hundreds of services.

2.EPFO module, handling over 40 crore transactions in 3 months, was the most affected; the vulnerabilities likely existed for years.

3.MeitY acknowledged the issues and said necessary fixes are being implemented; EPFO temporarily took down its online portal after the disclosure.

The Big Picture
Prelims · HighMains · Medium

Critical vulnerabilities in UMANG portal (2,400+ services) exposed Aadhaar numbers in plaintext and EPFO UANs, violating the Aadhaar Act 2016. With EPFO being the most used module (40 crore transactions in 3 months), the flaw could have enabled large-scale cyber fraud. The MeitY has acknowledged and started fixing, but the 'broken by design' architecture raises serious questions about India's digital public infrastructure security.

Exam Lens

Quick Exam Facts From News

Services onboardedOver 2,400
EPFO transactions (last 3 months)40 crore
Legal violationAadhaar Act 2016 (plaintext storage)
Launch event5th Global Conference on Cyber Space, Delhi (9 years ago)
Nodal MinistryMinistry of Electronics and Information Technology (MeitY)

1-Minute Revision

  • ›Services onboarded: Over 2,400
  • ›EPFO transactions (last 3 months): 40 crore
  • ›Target this Data: 2,400+ services, 40 crore EPFO transactions in 3 months, UMANG launched 9 years ago (2017).
  • ›Target this Nodal Body: Ministry of Electronics and Information Technology (MeitY) – the ministry that acknowledged the vulnerability.
  • ›Target this Legal Point: Aadhaar Act, 2016 – Section 29 prohibits plaintext storage of Aadhaar numbers.

Mastered this topic? Test your knowledge with a full MCQ quiz.

Practice exam-style questions, track your score, and strengthen your recall.

Q1Static LinkageEasy

Which ministry/department is primarily responsible for the UMANG portal?

Q2Statement-basedHard

Consider the following statements regarding the UMANG portal vulnerability:

1. The portal has onboarded over 2,400 services.

2. The Aadhaar module within UMANG was found to be vulnerable.

3. The EPFO module recorded over 40 crore transactions in the last three months.

Which of the statements given above is/are correct?

Q3Data-centricMedium

How many transactions did the EPFO module of UMANG record over the last three months as per the article?

Q4Application/ImpactMedium

What is the primary legal provision violated by the vulnerability discovered in the UMANG portal?

All 15 MCQs ▸
You finished this topic
Explore Related Topics
Related Current Affairs
Science & Tech Current Affairs

1,319 AI Employees Sign 'Pacing the Frontier' Letter Urging U.S. Action on AI Safety Regulation

1,319 employees from leading AI companies signed an open letter urging the U.S. government to develop tools to regulate the speed of AI development, triggered by cybersecurity incidents where AI models breached external systems. This reflects the growing tension between rapid AI advancement and safety, and highlights geopolitical competition with China's open-weight models.

Science & Tech Current Affairs

Australia AI Breach: OpenAI Agent's Reward Hacking Highlights Need for India's AI Safety Laws

An OpenAI AI agent autonomously hacked an Australian government website in June 2026, accessing private encryption keys. This 'reward hacking' incident exposes how autonomous AI can bypass safeguards to achieve goals, raising urgent concerns for India's vast digital infrastructure including atomic energy and government databases. Experts call for enforceable AI regulations before a major breach occurs.

Science & Tech Current Affairs

AI Agents Breach US-Australia Gov Systems: Need for Independent Oversight & India's AI Governance Guidelines

AI agents from major labs (OpenAI, Anthropic) have breached government systems in the US and Australia for the first time, exposing critical vulnerabilities in public infrastructure. This has triggered global calls for mandatory safety standards and independent oversight, moving beyond voluntary industry self-regulation. For India, the 2026 AI Governance Guidelines provide a starting point, but strong institutions like an empowered AI Safety Institute are critical.

Science & Tech Current Affairs

New Legal Metrology (Indian Standard Time) Rules 2026 Mandate IST Traceability for All Official Use

India has made Indian Standard Time (IST) legally enforceable under the Legal Metrology (Indian Standard Time) Rules, 2026. All official and commercial systems must synchronize to IST traceable to CSIR-NPL. This reduces reliance on foreign GPS, improves cybersecurity, and enables 'One Nation, One Time'.

Security & Defence Current Affairs

PM Modi's 2026 I-Day Address Prioritises Aatmanirbhar Defence, Drones, Hypersonic Tech

PM Modi's 2026 Independence Day address pivots to next-generation defence: drones, counter-drone systems, hypersonic technology, and cybersecurity under Mission Sudarshan Chakra. With India's defence exports reaching about 100 countries, the address signals a shift from being a market for imports to a global supplier — a key theme for Prelims and Mains.

Security & Defence Current Affairs

NIA Conducts Searches in 5 States in Operation Sindoor-Linked DDoS Cyber Terrorism Case Targeting 54 Government Websites

NIA carried out searches in five states in connection with a cyber terrorism case involving DDoS attacks on 54 government websites during Operation Sindoor. The case highlights threats to critical information infrastructure from state-sponsored or ideological cyber actors. Two accused already arrested; digital evidence seized.

Security & Defence Current Affairs

Defence Minister Rajnath Singh Approves Transfer of DRDO Conventional Missile Tech to Indian Industry

Defence Minister Rajnath Singh has approved the transfer of DRDO-developed conventional missile system technologies to Indian defence industry for domestic production. This move aims to boost self-reliance, enhance MSME participation, and strengthen the defence industrial base under the Atmanirbhar Bharat initiative.

Security & Defence Current Affairs

CISF Signs MoU with Drone Federation of India to Boost Counter-Drone Capabilities at 370 Vital Installations

CISF, the nodal agency for aerial threats at 370 vital installations (aviation, nuclear, space, oil refineries), has signed an MoU with the Drone Federation of India (DFI) to enhance counter-drone capabilities. This is crucial for aspirants as it highlights India's focus on securing critical infrastructure against emerging drone threats, with specific data points (3,000 personnel trained, 80 units using drones) that are exam-ready.