Critical vulnerabilities in UMANG portal (2,400+ services) exposed Aadhaar numbers in plaintext and EPFO UANs, violating the Aadhaar Act 2016. With EPFO being the most used module (40 crore transactions in 3 months), the flaw could have enabled large-scale cyber fraud. The MeitY has acknowledged and started fixing, but the 'broken by design' architecture raises serious questions about India's digital public infrastructure security.
Exam Lens
Quick Exam Facts From News
1-Minute Revision
- ›Services onboarded: Over 2,400
- ›EPFO transactions (last 3 months): 40 crore
- ›Target this Data: 2,400+ services, 40 crore EPFO transactions in 3 months, UMANG launched 9 years ago (2017).
- ›Target this Nodal Body: Ministry of Electronics and Information Technology (MeitY) – the ministry that acknowledged the vulnerability.
- ›Target this Legal Point: Aadhaar Act, 2016 – Section 29 prohibits plaintext storage of Aadhaar numbers.
Mastered this topic? Test your knowledge with a full MCQ quiz.
Practice exam-style questions, track your score, and strengthen your recall.