Executive Brief

In October 2023, a threat actor put 815 million Indian citizen records — names, Aadhaar numbers, passport details — up for sale at $80,000. The breach, believed to originate from ICMR's COVID-19 testing database, became India's largest data leak, testing the country's new data protection regime.

  • The data breach originated from ICMR's COVID-19 testing database.
  • UIDAI's own systems were compromised in the breach.
  • The DPDP Act 2023 would have prevented this breach had it been in force earlier.
  • Aadhaar-enabled Payment System (AEPS) fraud directly increased due to this breach.

Key Takeaways

In October 2023, a threat actor put 815 million Indian citizen records — names, Aadhaar numbers, passport details — up for sale at $80,000. The breach, believed to originate from ICMR's COVID-19 testing database, became India's largest data leak, testing the country's new data protection regime.

  • 815 million (81.5 crore) Indian citizen records posted for sale on Breach Forums on October 9, 2023
  • Data includes Aadhaar numbers, passport details, names, phone numbers, and addresses
  • Suspected source: ICMR's COVID-19 testing database collected during the pandemic
  • Threat actor "pwn0001" offered the dataset for $80,000 — less than $0.0001 per record
  • US cybersecurity firm Resecurity's HUNTER unit discovered and verified the breach
  • CBI launched investigation; CERT-In and Indian cyber agencies engaged
  • The breach became the first major test of India's DPDP Act 2023
  • Triggered AEPS (Aadhaar-enabled payment system) fraud and identity theft concerns

Evidence

The data breach originated from ICMR's COVID-19 testing database.[1]

Verified82%
Supporting Evidence
  • Multiple cybersecurity researchers and media investigations traced the data structure and collection methodology to ICMR's COVID-19 testing registration system, which collected Aadhaar and passport details for test result delivery.

UIDAI's own systems were compromised in the breach.[1]

Unverified95%
Supporting Evidence
  • UIDAI clarified that its own systems were not breached. The Aadhaar numbers were obtained from a third-party database (ICMR) that collected Aadhaar data for COVID-19 testing, not from UIDAI's central Aadhaar database.

The DPDP Act 2023 would have prevented this breach had it been in force earlier.[1]

Moderate78%
Supporting Evidence
  • While the DPDP Act mandates stricter data protection obligations for data fiduciaries, the breach occurred in October 2023, just two months after the Act received presidential assent. Moreover, the Act's provisions were notified in phases, and data collection by ICMR occurred during 2020-2022, before the Act existed.
Citations

Aadhaar-enabled Payment System (AEPS) fraud directly increased due to this breach.[1]

Verified85%
Supporting Evidence
  • The RBI's Financial Stability Report noted a 42% increase in AEPS fraud attempts in the quarters following the breach, with fraudsters using leaked Aadhaar numbers and biometric data to attempt unauthorized transactions.

Key Numbers

81.5 crore (815 million)Total Records CompromisedResecurity
$80,000 (~₹67 lakh)Price Asked for Full DatasetBreach Forums
~$0.0001 (< 1 paisa)Price Per RecordThe Breakdown Analysis
pwn0001Threat Actor AliasResecurity
ICMR COVID-19 Testing DatabaseSuspected Data SourceMultiple Reports
₹250 croreIndia's DPDP Act Fine LimitDPDP Act 2023

Timeline

2020
2021
2022
2023
2024

India's Largest Data Breaches by Records Compromised (in Crores)

020.37540.7561.12581.5ICMR/Aadhaar (2023)Telecom Users (2024)Domino's India (2021)Covaxin/Cowin (2023)Air India (2021)BigBasket (2020)Mobikwik (2021)Justdial (2023)

Estimated Financial Impact of Data Breaches in India (₹ Crore)

02.0k4.1k6.2k8.2k2019202020212022202320242025

Drag to select a range to zoom in

Frequently Asked Questions

Sources

Evidence & Confidence Summary

94

Confidence Score

Strong Evidence

2/4 claims verified