Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Security flaw in India’s income-tax portal exposed sensitive taxpayer data

Researchers found an IDOR flaw in India’s Income Tax e-Filing portal that reportedly exposed sensitive taxpayer and company data. The issue was reported fixed, but the number of records accessed and any criminal exploitation remain unknown.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—the vulnerability was real. Researchers found an access-control flaw in India’s Income Tax Department e-Filing portal that reportedly allowed a logged-in user who knew another taxpayer’s PAN to retrieve that person’s information. Reported exposed data included identity, contact, Aadhaar, PAN-linked, bank-account, filing and company-related details.

The researchers said the flaw was fixed by October 2, 2025. However, the public reporting does not establish how long it existed, how many records were accessed, whether criminals exploited it, or whether the department completed a forensic review. This is a confirmed security exposure—not proof that millions of taxpayers’ data was stolen.

As an Amazon Associate I earn from qualifying purchases.

What happened?

Two security researchers, Akshay CS and “Viral,” discovered the issue in September 2025 while filing their own returns. They found that a request made by the portal included a taxpayer reference that could be changed. The system reportedly failed to verify whether the logged-in user was authorized to access the corresponding record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

They reported the vulnerability to CERT-In. According to TechCrunch’s October 7, 2025 report:

  • CERT-In said on September 30 that the Income Tax Department was working on a fix.
  • The researchers said the flaw could no longer be exploited by October 2.
  • TechCrunch published its report only after the researchers confirmed that the vulnerability had been fixed.

The public record does not include a formal patch identifier, detailed technical remediation report or government postmortem.

What is an IDOR vulnerability?

The flaw was an insecure direct object reference, commonly called IDOR. In plain language, the application accepted a reference to a record and returned it without independently checking whether the requester was entitled to see that record.

A simple analogy is a building where a person is allowed through the front door, but can open any office merely by changing the room number on a request. Being authenticated—being logged in—is not the same as being authorized to view every record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This type of weakness is primarily an authorization failure. It is not, by itself, evidence of stolen passwords, malware, ransomware or a complete takeover of the tax portal. Reporting indicated that the user needed to be logged in and know another taxpayer’s PAN; it did not describe an anonymous visitor freely browsing the database.

What information was reportedly exposed?

TechCrunch said researchers verified access to records containing some combination of:

  • full names;
  • residential addresses;
  • email addresses and telephone numbers;
  • dates of birth;
  • PAN-linked taxpayer information;
  • Aadhaar numbers;
  • bank-account details;
  • filing-related information; and
  • information connected to registered companies.

These categories should not be read as meaning that every affected record contained every field. The report also does not establish that online-banking passwords, transaction credentials or one-time passwords were exposed.

Could people who had not filed a return be affected?

Possibly. TechCrunch reported verifying access to information belonging to at least one person who had not yet filed an income-tax return for that year. That suggests the portal contained broader taxpayer records than only current-year submitted returns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It does not show that every registered user’s complete record was accessible, or that every person who had not filed a return was affected.

How large was the potential exposure?

The portal publicly listed more than 135 million registered users and more than 76 million income-tax returns filed in financial year 2024–25, according to the incident report.

Those figures describe the possible scale of the system, not the number of victims. The number of records that were exposed, viewed, copied or misused remains unknown. It is therefore inaccurate to call this “135 million victims” or claim that millions of records were stolen without further evidence.

What is confirmed—and what is not?

Question What the public reporting supports
Was there a real flaw? Yes. Researchers demonstrated unauthorized access to other taxpayers’ records.
Was login required? Yes, according to the report. The issue was not described as anonymous public access.
Was a PAN needed? Researchers said knowledge of another taxpayer’s PAN was required.
Was sensitive information exposed? Yes. Reported categories included identity, address, Aadhaar, PAN-linked, banking, filing and company data.
Was mass criminal exploitation confirmed? No. The public report does not establish bulk scraping, criminal resale or identity theft.
How many records were affected? Unknown.
Was the specific flaw fixed? The researchers said it was fixed by October 2, 2025.
Is the entire portal proven secure? No. Fixing one vulnerability does not prove that every other endpoint or control is secure.

What did the government confirm?

CERT-In acknowledged the issue and said the Income Tax Department was working on a fix on September 30, 2025. TechCrunch reported that the Income Tax Department acknowledged receiving its questions but did not provide substantive answers before publication. The Finance Ministry did not return the publication’s request for comment.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is not the same as a public admission of a mass breach. The available reporting does not establish whether officials:

  • determined how long the flaw had existed;
  • reviewed logs for suspicious access;
  • identified any copied or downloaded records;
  • notified affected taxpayers;
  • commissioned an independent audit; or
  • published a detailed incident report.

What risks should taxpayers consider?

Exposure of tax-profile data can make scams more convincing, particularly when several fields are combined. Potential risks include:

  • tax-themed phishing messages using a person’s PAN, address or filing details;
  • impersonation of taxpayers, tax professionals or government officials;
  • fraudulent refund or bank-account-change requests;
  • social engineering directed at businesses, employees, directors or authorized representatives; and
  • identity fraud using combinations of PAN, Aadhaar, date of birth, contact and financial information.

Exposure does not automatically cause identity theft or permit bank-account takeover. The actual risk depends on whether a particular record was accessed, which fields were obtained, whether the information was combined with data from other incidents and whether someone attempts to use it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What taxpayers should do now

Taxpayers cannot repair a server-side authorization flaw themselves. Sensible precautions are defensive and do not imply that a particular person’s record was accessed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Change reused passwords. If your e-Filing password was used on another service, change it there too. Use a unique password for the tax account.
  2. Enable available additional authentication. Turn on every multi-factor or other security control offered by the official portal.
  3. Review your account. Check profile information, bank-account details, refund information, filing records and notices for unexpected changes.
  4. Be skeptical of targeted messages. A message containing your PAN, Aadhaar, address or tax details can still be fraudulent.
  5. Never disclose OTPs or passwords. Do not provide credentials, banking information or full Aadhaar details in response to an unsolicited call, email or text.
  6. Use the official portal directly. Enter incometax.gov.in manually or use a trusted bookmark rather than clicking an unexpected link.
  7. Verify notices inside your account. Do not rely solely on an email or SMS claiming that a refund, penalty or account reactivation is pending.
  8. Contact official support if something changed. If your profile, bank details or filing information appears altered, use the support channels on the official e-Filing website.

Businesses should also review information relating to employees, directors, customers and authorized representatives that may have been present on the portal.

Why the distinction matters

There are several different events that are often collapsed into the word “breach”:

  • Exposure: a weakness made unauthorized access possible.
  • Access: researchers demonstrated that records could be retrieved.
  • Download or scraping: no public evidence cited in the report establishes mass copying.
  • Criminal exploitation: no public evidence cited in the report confirms that criminals used the flaw.
  • Identity theft: the report does not establish that taxpayers suffered identity fraud because of it.

Similarly, a fix for the reported endpoint reduces the risk from that method. It does not prove that no one copied data before the fix, that logging was complete, or that the wider portal has no other weaknesses.

Timeline

  • September 2025: Researchers discovered and reported the issue.
  • September 30, 2025: CERT-In said the Income Tax Department was working on a fix.
  • October 2, 2025: Researchers said the vulnerability had been fixed.
  • October 7, 2025: TechCrunch published its investigation.

What remains unresolved?

The incident raises accountability questions beyond the technical fix: how long the flaw was present, whether logs can identify suspicious access, how many records were retrieved, whether affected people were notified and whether critical public portals receive independent access-control testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The most accurate conclusion is narrow but serious: India’s e-Filing portal had a confirmed authorization flaw that exposed sensitive taxpayer data to an authenticated user under certain conditions. The flaw was reported fixed, but the public evidence does not establish the scale of actual access or any resulting criminal exploitation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.