• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Major Security Flaw Exposes Millions in India’s Income Tax E-Filing Portal
Share
  • bitcoinBitcoin(BTC)$78,258.00
  • ethereumEthereum(ETH)$2,306.98
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.39
  • binancecoinBNB(BNB)$616.23
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$83.87
  • tronTRON(TRX)$0.330460
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.04
  • dogecoinDogecoin(DOGE)$0.107949
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Company

Major Security Flaw Exposes Millions in India’s Income Tax E-Filing Portal

News Desk
Last updated: October 13, 2025 11:23 pm
News Desk
Published: October 13, 2025
Share
security 5043368 1280

Earlier this month, a significant security vulnerability was discovered in India’s Income Tax e-filing portal, which serves over 135 million users. While the government has addressed this issue, concerns remain that sensitive personal data of millions, including corporations filing tax returns, may have been compromised.

Security researchers Akshay CS and Viral detected the flaw while filing their taxes. They noticed that by simply altering their PAN details upon logging in, they were able to access the financial information of other users. The portal, which requests PAN details to load a user’s personal profile, was mishandling this data due to a lack of sufficient verification by the backend server.

The specific vulnerability identified is known as insecure direct object reference (IDOR). This severe access control flaw allows unauthorized users to access and potentially exfiltrate another user’s data with relative ease. The Indian Computer Emergency Response Team (CERT-In) has classified this weakness as a high-severity risk, emphasizing the challenge in detecting such vulnerabilities, even though exploiting them is straightforward. At the time of this report, CERT-In had not responded to inquiries for additional comments.

This incident is emblematic of a broader security landscape in India, where organizations reportedly face more than 3,200 cyberattacks weekly. Sectors like education, government, and consumer goods are among the most frequently targeted. In a related development, several coordinated cyberattacks occurred in August, reportedly involving threat actors linked to countries like China and Pakistan, especially following India’s military response to a terrorist incident.

Previous security breaches in India have led to extensive personal data leaks, with instances including defense personnel information being sold online and sensitive health records compromised in earlier cyber incidents.

Experts like Rajesh Pant, Chairman of the Cybersecurity Association of India, warn that cybercriminals are increasingly utilizing artificial intelligence to enhance their attacks, complicating defensive measures. While corporations can deploy AI to bolster their security, human error remains a significant vulnerability.

To mitigate risk, Vinayak Godse, CEO of the Data Security Council of India, suggests that organizations need to proactively assess and manage their interactions with third-party services that may expose them to security risks. This can involve monitoring third-party components, conducting threat hunting exercises, and continuously evaluating potential compromises.

Despite increased governmental spending on cybersecurity, experts identify persistent gaps in security frameworks. The recent budget allocation of ₹1,900 crore for cybersecurity aims to improve infrastructure, but the overall effectiveness of such efforts is still questioned. Emphasizing enhanced collaboration across various governmental departments is suggested as a way to strengthen the nation’s cybersecurity posture.

Moreover, initiatives like the Guidelines for Indian Government Websites (GIGW) outline essential security protocols, including encryption and multi-factor authentication. However, CERT-In lacks public bug bounty programs similar to those in the private sector and international counterparts, which could incentivize the discovery of vulnerabilities.

Lastly, while modernization efforts are underway—like the Railway Ministry’s overhaul of its passenger reservation system to incorporate Aadhaar-based authentication—legacy systems and a lack of cyber awareness among government employees still pose significant challenges. Continuous monitoring and enhanced collaboration are seen as crucial steps in securing India’s digital landscape moving forward.

Supermasks Mint Launch Promises New Opportunities for NFT Trading and MATIC Token
Bitget Launches AI Trading Agent with New Autonomous Account Structure
Stop Blaming Ripple for XRP Price – Community Fires Back as CTO Debunks Secret Government Deal
The New Ripple Employee Who Did Not Recognize Chris Larsen
American Bitcoin Soars on NASDAQ Debut, Plans to Raise $2.1 Billion
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article https3A2F2Fd1e00ek4ebabms.cloudfront.net2Fproduction2Fbb8c191a 5f1e 42a7 a379 f7e72ff4bce2 Taiwan’s Chip Industry Thrives Amid Geopolitical Tensions
Next Article Bitcoin chart 1 gID 7 Bitcoin Plummets Following Trump’s Tariff Announcement, Triggering Historic $19 Billion Liquidation
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
dcee7ac42317c1b33f2a132ff2df7064
Top Stock Market Highlights of the Week: US Federal Reserve, Boustead Singapore, Nanofilm Technologies and CapitaLand Integrated Commercial Trust
108301156 1777741139273 IMG 9263
Spirit Airlines Ceases Operations After 34 Years Amid Financial Turmoil
1760632538 news story
Analyst Warns Bitcoin May Face Major Correction, Highlights Best Time to Sell
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?