ADVERTISEMENT

UIDAI Dismisses Report Of Data Leak; Says Aadhaar Remains Safe

ZDNet today reported that a state-owned utility firm was allegedly leaking information on Aadhaar holders.



An Aadhaar biometric identity card, issued by the Unique Identification Authority of India (UIDAI). (Photographer: Dhiraj Singh/Bloomberg)
An Aadhaar biometric identity card, issued by the Unique Identification Authority of India (UIDAI). (Photographer: Dhiraj Singh/Bloomberg)

The Unique Identification Authority of India today refuted reports about a fresh data leak of Aadhaar holders, and asserted that there has been “absolutely no breach” of its database.

The statement comes after ZDNet, a technology news portal cited a security researcher's claim to state that a system of state-owned utility firm was allegedly leaking information on Aadhaar holders.

In a statement, UIDAI, the Aadhaar-issuing body, said, “There is no truth in this story as there has been absolutely no breach of UIDAI’s Aadhaar database. Aadhaar remains safe and secure.” It termed the data breach claims as “totally baseless, false and irresponsible”.

UIDAI today has refuted reports in a certain section of media sourced from the news website ZDNet which has quoted a person purportedly claiming to be a security researcher that a state-owned utility company has vulnerability which can be used to access a huge amount of Aadhaar data including banking details.
UIDAI Statement

The ZDNet report had claimed that "a data leak on a system run by a state-owned utility company can allow anyone to download private information on all Aadhaar holders, exposing their names, their unique 12-digit identity numbers, and information about services they are connected to, such as their bank details and other private information." The report of the alleged security lapse comes at a time when a Constitutional bench of the Supreme Court is hearing a clutch of petitions challenging the Aadhaar Act and the use of biometric identifier in various government and non-government services.

The Aadhaar-issuing body has argued that even if the claims made by the report were taken to be true, the security-related concerns should be around the database of utility company in question. It has “nothing to do with security of UIDAI’s Aadhaar database,” it said.

Going by the report, since the utility company’s database also had bank account numbers of its customers, would bank databases also be considered to have been breached, UIDAI questioned. "The answer would obviously be in negative," it added.

UIDAI argued that mere availability of Aadhaar number with a third person “will not be a security threat to the Aadhaar holder” nor will it lead to financial or other fraud. This is because a transaction is contingent upon a successful authentication through fingerprint, Iris or OTP of the Aadhaar holder, it added.

Earlier this week, UIDAI CEO Ajay Bhushan Pandey had made a powerpoint presentation in the Supreme Court to defend the government’s ambitious Aadhaar scheme. He had said that breaking Aadhaar encryption may take "more than the age of the universe for the fastest computer on earth."