The record
Written from the 1 report below. Nothing here is unsourced.
- A 21-year-old student in Bihar has claimed to have found a significant security bug in the Bihar Mahadalit Vikas Mission (BMVM) website, which could have exposed Aadhaar numbers, pension records, and data linked to other government schemes.
- The student says he first reported the flaw responsibly to officials and CERT-In, but felt the complaint was not taken seriously initially, after which he raised it on social media.
- There is no official evidence yet that any attacker actually misused the vulnerability or accessed the data.
- The incident has renewed questions about the security of government websites, with experts calling for regular security audits, timely updates, and proper channels for reporting bugs.
What to watch next
- Whether authorities or CERT-In formally confirm and fix the reported vulnerability
- Whether any evidence emerges that the exposed Aadhaar or pension data was actually misused
- Whether the government sets up clearer mechanisms for handling responsible bug reports
Coverage1
1 report
Indian-language1
All filed from India
Named India · Bihar Government · Bihar Mahadalit Vikas Mission · CERT-In
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
