UMANG App Security Flaw Exposes Sensitive Government Data Raising Privacy Concerns Across India
Security researchers found vulnerabilities in UMANG exposing sensitive government service data including EPFO details and Aadhaar related information while authorities begin corrective security measures

A major security concern has emerged around the Indian government’s UMANG platform after researchers reported vulnerabilities that could have exposed sensitive user information linked to various government services. The issue reportedly involved data related to EPFO accounts, LPG booking details, and Aadhaar information stored through connected services.
The Ministry of Electronics and Information Technology has acknowledged the reported security gaps and confirmed that corrective actions are being taken. According to the ministry, security teams investigated the concerns and steps have been initiated to strengthen the platform’s protection systems.
Cybersecurity researchers Akshay C.S. and Viral Vaghela reportedly identified the vulnerabilities and claimed that the issue was linked to weaknesses in the overall architecture of the UMANG platform rather than a single government service. They suggested that some flaws may have existed for several years due to the way different services were integrated.
However, researchers have not confirmed any large scale theft or misuse of the exposed information. The concern mainly revolves around the possibility that unauthorized access could have allowed sensitive details from connected government databases to become visible.
The reported exposed information included EPFO Universal Account Numbers, LPG cylinder booking records from at least one major oil marketing company, and Aadhaar numbers linked with certain government services. Researchers also raised concerns that some Aadhaar details were reportedly stored in plain text format, which could create privacy risks. They clarified that the Aadhaar module of UMANG itself was not directly affected by the reported issue.
Launched nearly nine years ago, UMANG was designed as a single digital platform where citizens could access services from central and state government departments. The platform currently offers more than 2,400 government services and is used by millions of people across the country, making any security weakness a matter of serious concern.
Among the most frequently used services on UMANG is the EPFO section. The module has recorded more than 40 crore transactions in the last three months, highlighting the scale of data handled through the platform. Security experts warned that any unauthorized access to such information could potentially affect a large number of users.
Independent cybersecurity expert Karan Saini described the issue as significant but noted that copying the entire EPFO database would not have been simple due to existing protections such as rate limiting. However, he warned that attackers with access to specific UAN numbers could potentially misuse account related information for activities such as attempting unauthorized changes or financial transactions.
Following the disclosure, researchers shared details of the vulnerabilities with CERT In, MeitY, and EPFO. Reports also suggested that EPFO temporarily suspended its online portal for migration activities after the findings came to light, although an official connection between the two events has not been confirmed.
The government has stated that sensitive plain text data found in certain APIs has now been encrypted. Security teams have also reviewed API logs from the previous three months to identify any unusual activity. Officials said no suspicious transaction patterns have been detected so far and confirmed that continuous monitoring of the UMANG platform is underway.
The incident has once again highlighted the growing importance of strong cybersecurity measures as government digital platforms handle increasing amounts of personal and financial information belonging to citizens across India.



