• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Major Security Flaw Exposes Millions in India’s Income Tax E-Filing Portal
Share
  • bitcoinBitcoin(BTC)$113,482.00
  • ethereumEthereum(ETH)$4,142.24
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$1,218.19
  • rippleXRP(XRP)$2.51
  • solanaSolana(SOL)$202.65
  • usd-coinUSDC(USDC)$1.00
  • staked-etherLido Staked Ether(STETH)$4,138.09
  • dogecoinDogecoin(DOGE)$0.204862
  • tronTRON(TRX)$0.316890
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Company

Major Security Flaw Exposes Millions in India’s Income Tax E-Filing Portal

News Desk
Last updated: October 13, 2025 11:23 pm
News Desk
Published: October 13, 2025
Share
security 5043368 1280

Earlier this month, a significant security vulnerability was discovered in India’s Income Tax e-filing portal, which serves over 135 million users. While the government has addressed this issue, concerns remain that sensitive personal data of millions, including corporations filing tax returns, may have been compromised.

Security researchers Akshay CS and Viral detected the flaw while filing their taxes. They noticed that by simply altering their PAN details upon logging in, they were able to access the financial information of other users. The portal, which requests PAN details to load a user’s personal profile, was mishandling this data due to a lack of sufficient verification by the backend server.

The specific vulnerability identified is known as insecure direct object reference (IDOR). This severe access control flaw allows unauthorized users to access and potentially exfiltrate another user’s data with relative ease. The Indian Computer Emergency Response Team (CERT-In) has classified this weakness as a high-severity risk, emphasizing the challenge in detecting such vulnerabilities, even though exploiting them is straightforward. At the time of this report, CERT-In had not responded to inquiries for additional comments.

This incident is emblematic of a broader security landscape in India, where organizations reportedly face more than 3,200 cyberattacks weekly. Sectors like education, government, and consumer goods are among the most frequently targeted. In a related development, several coordinated cyberattacks occurred in August, reportedly involving threat actors linked to countries like China and Pakistan, especially following India’s military response to a terrorist incident.

Previous security breaches in India have led to extensive personal data leaks, with instances including defense personnel information being sold online and sensitive health records compromised in earlier cyber incidents.

Experts like Rajesh Pant, Chairman of the Cybersecurity Association of India, warn that cybercriminals are increasingly utilizing artificial intelligence to enhance their attacks, complicating defensive measures. While corporations can deploy AI to bolster their security, human error remains a significant vulnerability.

To mitigate risk, Vinayak Godse, CEO of the Data Security Council of India, suggests that organizations need to proactively assess and manage their interactions with third-party services that may expose them to security risks. This can involve monitoring third-party components, conducting threat hunting exercises, and continuously evaluating potential compromises.

Despite increased governmental spending on cybersecurity, experts identify persistent gaps in security frameworks. The recent budget allocation of ₹1,900 crore for cybersecurity aims to improve infrastructure, but the overall effectiveness of such efforts is still questioned. Emphasizing enhanced collaboration across various governmental departments is suggested as a way to strengthen the nation’s cybersecurity posture.

Moreover, initiatives like the Guidelines for Indian Government Websites (GIGW) outline essential security protocols, including encryption and multi-factor authentication. However, CERT-In lacks public bug bounty programs similar to those in the private sector and international counterparts, which could incentivize the discovery of vulnerabilities.

Lastly, while modernization efforts are underway—like the Railway Ministry’s overhaul of its passenger reservation system to incorporate Aadhaar-based authentication—legacy systems and a lack of cyber awareness among government employees still pose significant challenges. Continuous monitoring and enhanced collaboration are seen as crucial steps in securing India’s digital landscape moving forward.

Chainlink Launches Digital Transfer Agent Standard for Tokenized Assets
MoonPay Introduces MoonTags for Effortless Crypto Transfers
Bitget Wallet Partners with Mercuryo for Instant Crypto Purchases Using Multiple Payment Methods
Coinbase Asks DOJ to Address State-Level Crypto Enforcement Amid Ongoing Legal Battles
Chainlink’s $LINK Poised for Price Surge, Analysts Eye $47 Target Following Swift Partnership
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article https3A2F2Fd1e00ek4ebabms.cloudfront.net2Fproduction2Fbb8c191a 5f1e 42a7 a379 f7e72ff4bce2 Taiwan’s Chip Industry Thrives Amid Geopolitical Tensions
Next Article Bitcoin chart 1 gID 7 Bitcoin Plummets Following Trump’s Tariff Announcement, Triggering Historic $19 Billion Liquidation
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
89f20ec95cd7757872eeb90fd89eb815
Bitcoin and Ether Tumble Amid Rising U.S.-China Trade Tensions
108211257 1760365113822 gettyimages 2240774552 anotherday126718488 i6omlpiv
U.S. Stock Futures Steady Amid Ongoing Trade War Tensions
bitcoin romance pig butchering scam 1152x648
Federal prosecutors seize $15 billion from alleged kingpin behind forced labor investment scams
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • Company
  • News
  • Bitcoin
  • Stocks
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?