Skip to main content

Security Flaw in India's Income Tax Portal Exposes Sensitive Taxpayer Data


A major security vulnerability in India's income tax filing portal has been fixed, TechCrunch reported. The flaw, discovered by security researchers Akshay CS and "Viral" in September, allowed logged-in users to access real-time personal and financial information of other taxpayers. This included sensitive details such as full names, home addresses, email addresses, dates of birth, phone numbers and bank account information.

Exposed Aadhaar numbers of individuals

The security flaw in the income tax filing portal also exposed Aadhaar numbers, a unique government-issued identification number used for identity verification and accessing government services. TechCrunch verified the data by allowing researchers to search its records on the portal. The researchers confirmed on October 2 that the vulnerability had been patched. Discovery process

Researchers found bug while filing tax returns

The researchers found the security flaw while filing their recent income tax return on the government website. They discovered that by logging into the portal with their Permanent Account Number (PAN), they could view anyone else's sensitive financial data by replacing their PAN with another in a network request as the page loads. This could be done using publicly available tools like Postman or Burp Suite and knowledge of someone else's PAN. Exploitation details

Vulnerability was easily exploitable by anyone logged into tax portal

The vulnerability was exploitable by anyone logged into the tax portal because the Income Tax Department's back-end servers were not properly checking who could access a person's sensitive data. This type of vulnerability is known as an insecure direct object reference (IDOR), a common flaw that governments have warned can be easily exploited and lead to large-scale data breaches.

Bug also exposed data of individuals who didn't file taxes

Along with individual data, the bug also exposed information related to companies registered with the e-Filing portal. TechCrunch verified that the bug even exposed data of individuals who had not filed their income tax returns for the current year. This was confirmed by asking an individual yet to file their tax returns for permission to let researchers look up their information using this portal bug.


Popular posts from this blog

Instagram Security Risk

Recently, attackers took over high-profile Instagram accounts, including the official Obama’s White House account and a United States Space Force chief officer. The attacker didn't break any Instagram code or crack passwords. They convinced Meta's own AI support chatbot to hand over the accounts. Meta uses an AI-powered support chatbot to help users recover locked accounts, change recovery emails, and handle account issues. The chatbot is trained to verify identity through questions and decide whether a request looks legitimate. Attackers figured out how to manipulate that decision making process. Video Credit-  x.com/chetaslua The attack consists of four main steps. Step 1: The attacker contacts Meta's AI support chatbot claiming to be the legitimate owner of a target account. They simply use Instagram's help interface and start an account recovery conversation. For high-profile targets, attackers use publicly available information such as display names, profile bios, ...

LinkedIn Rolls Out AI Slop Reporting button

                                         LinkedIn is trying to get a handle on the massive amounts of AI slop on the platform. To do that, the company is testing a new reporting tool that let users flag potential slop and removing the "rewrite with AI" button it once promoted on every post. With the new reporting tool, users will have the ability to flag posts as "seems like AI slop." Doing so will "privately flag" via the site's analytics dashboard that others "feel your post may have come off as inauthentic or heavy use of AI," LinkedIn's Chief Product Officer Hari Srinivasan wrote in an update. The move follows an earlier update that aimed to reduce the reach of AI-generated posts on the platform. The company has since done further work to improve its detection systems, Srinivasan said, which should lead to people seeing fewer AI-generated posts recommended in their feeds. Pos...

A Simple PDF Tool Outpaced Giants by doing the basics faster, cleaner, and better than anyone else.

  I am going to break down the story of a tool that I'm willing to bet you've used, but whose incredible business journey you probably know nothing about. Honestly, this is a master class for any founder looking to build something valuable from scratch. I am calling it the Bootstrapper’s Playbook. A Wild Reality Check Let’s just start with a wild fact. There's a website out there, a deceptively simple one, that in places like India pulls in more traffic than Amazon. I'm serious. Millions and millions of people rely on it every single day. Any guesses? It's iLovePDF. If you've ever needed to quickly merge, split, or compress a PDF file, you've almost definitely landed on this site. But what most people have no idea about is how this massive global platform was built. And that is where the real story begins. Born from Frustration So, let's go all the way back to the beginning. Because this whole thing wasn't born from some grand business plan or a fanc...