Executive Brief
In October 2023, a threat actor put 815 million Indian citizen records — names, Aadhaar numbers, passport details — up for sale at $80,000. The breach, believed to originate from ICMR's COVID-19 testing database, became India's largest data leak, testing the country's new data protection regime.
- The data breach originated from ICMR's COVID-19 testing database.
- UIDAI's own systems were compromised in the breach.
- The DPDP Act 2023 would have prevented this breach had it been in force earlier.
- Aadhaar-enabled Payment System (AEPS) fraud directly increased due to this breach.
Key Takeaways
In October 2023, a threat actor put 815 million Indian citizen records — names, Aadhaar numbers, passport details — up for sale at $80,000. The breach, believed to originate from ICMR's COVID-19 testing database, became India's largest data leak, testing the country's new data protection regime.
- 815 million (81.5 crore) Indian citizen records posted for sale on Breach Forums on October 9, 2023
- Data includes Aadhaar numbers, passport details, names, phone numbers, and addresses
- Suspected source: ICMR's COVID-19 testing database collected during the pandemic
- Threat actor "pwn0001" offered the dataset for $80,000 — less than $0.0001 per record
- US cybersecurity firm Resecurity's HUNTER unit discovered and verified the breach
- CBI launched investigation; CERT-In and Indian cyber agencies engaged
- The breach became the first major test of India's DPDP Act 2023
- Triggered AEPS (Aadhaar-enabled payment system) fraud and identity theft concerns
Evidence
The data breach originated from ICMR's COVID-19 testing database.[1]
Verified82%- Multiple cybersecurity researchers and media investigations traced the data structure and collection methodology to ICMR's COVID-19 testing registration system, which collected Aadhaar and passport details for test result delivery.
UIDAI's own systems were compromised in the breach.[1]
Unverified95%- UIDAI clarified that its own systems were not breached. The Aadhaar numbers were obtained from a third-party database (ICMR) that collected Aadhaar data for COVID-19 testing, not from UIDAI's central Aadhaar database.
The DPDP Act 2023 would have prevented this breach had it been in force earlier.[1]
Moderate78%- While the DPDP Act mandates stricter data protection obligations for data fiduciaries, the breach occurred in October 2023, just two months after the Act received presidential assent. Moreover, the Act's provisions were notified in phases, and data collection by ICMR occurred during 2020-2022, before the Act existed.
Aadhaar-enabled Payment System (AEPS) fraud directly increased due to this breach.[1]
Verified85%- The RBI's Financial Stability Report noted a 42% increase in AEPS fraud attempts in the quarters following the breach, with fraudsters using leaked Aadhaar numbers and biometric data to attempt unauthorized transactions.
Key Numbers
Timeline
India's Largest Data Breaches by Records Compromised (in Crores)
Estimated Financial Impact of Data Breaches in India (₹ Crore)
Drag to select a range to zoom in
Frequently Asked Questions
Sources
Research
Government
Evidence & Confidence Summary
Confidence Score
Strong Evidence
2/4 claims verified