Breach tracker

Breach report

UMANG flaws exposed UANs, LPG bookings and plaintext Aadhaar numbers, researchers say

ConfirmedDisclosed IndiaGovernmentBy Vivek Kumar
Records UnknownCause Vulnerability
Conceptual illustration: An anonymous smartphone with abstract civic-services tiles connected to generic identity and benefits documents. Headline: UMANG DATA EXPOSURE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

Researchers found weaknesses in services linked through the UMANG government app. MeitY says the affected APIs are now encrypted and its logs showed nothing suspicious.

What happened

Independent security researchers reported flaws in UMANG, the government services app, to the Ministry of Electronics and Information Technology (MeitY) and CERT-In. MediaNama reported on 14 July 2026 that the weaknesses exposed EPFO Universal Account Numbers (UANs), LPG cylinder booking details, and Aadhaar numbers that several linked services held in plaintext. The researchers said the problems came from how the platform was built rather than from a single service.

Confirmed vs. claimed

Confirmed: MeitY told MediaNama its teams had examined the findings and were taking corrective steps, and that plaintext data in the concerned APIs had been encrypted. It said a review of three months of API logs showed no suspicious transaction volumes. UMANG's own Aadhaar module was not found vulnerable, according to The Hans India.

Disputed: the researchers said the first fixes were inadequate and could be worked around. No one has shown that the data was bulk-copied; an independent reviewer said rate limits made large-scale scraping unlikely, though abuse was possible.

Who is affected

UMANG users of the linked services, especially EPFO, which The Hans India said handled about 40 crore transactions in three months, and LPG booking. The number of people whose records were actually viewed is not known.

What to do

  • Lock your Aadhaar biometrics in the mAadhaar app or on the UIDAI site, and check your Aadhaar authentication history.
  • Treat calls or messages that quote your UAN, PF balance or gas booking as suspect. EPFO and oil companies do not ask for OTPs or PINs.
  • Check your EPFO passbook for claims you did not make.
  • If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
  • Full checklist: our Aadhaar and PAN leak guide.

Sources

More breaches in India