Government Fixes Major Security Flaw in Income Tax Portal, Prevents Data Leak



Quick Summary
A significant security vulnerability on India's Income Tax e-filing portal has been successfully patched by the government, averting a potential large-scale leak of taxpayer data. The flaw, discovered by independent cybersecurity researchers, allowed unauthorised access to sensitive personal and financial details. The Indian Computer Emergency Response Team (CERT-In) coordinated with the Income Tax Department to implement a fix, which has been verified as effective.

In a crucial cybersecurity intervention, the Government of India has patched a serious vulnerability in the Income Tax e-filing portal, preventing what could have been a large-scale data leak of taxpayers' confidential information. Critical Vulnerability Found in Tax Portal Two independent cybersecurity researchers, Akshay C.S. and Viral, discovered the flaw while filing tax returns in September 2025. The flaw was identified as anIDOR (Insecure Direct Object Reference) vulnerability allowing a
Daily Limit Reached

You have reached your daily limit of 2 Free News

Subscribe to CCI PRO for unlimited access

Why Upgrade to CCI PRO?
  • No Ads
  • WhatsApp Community
  • Daily E-Newsletter
  • Unlimited News Access
  • Profile Visitors
  • Link Social Profiles
  • Featured Job Posts
  • Pro Badge
  • Expert GST Guidance
  • Unlimited Forum Replies
  • Download Content in PDF
1 Year PLAN
1999
(Excl. of GST ₹359)

BEST VALUE
2 Years PLAN
3499
(Excl. of GST ₹629)

View all CCI PRO benefits

Already a PRO member? Login here for an ad-free experience. 011-411-70713

FAQ :

An IDOR (Insecure Direct Object Reference) vulnerability was discovered, which allowed logged-in users to access another taxpayer's sensitive information by altering network request parameters.

The data potentially exposed included full name, address, email, phone number, date of birth, Aadhaar number, and bank account details for both individuals and registered entities.

The flaw was discovered by two independent cybersecurity researchers, Akshay C.S. and Viral.

The researchers responsibly reported the vulnerability to CERT-In, which then coordinated with the Income Tax Department to investigate and implement a fix.

Yes, CERT-In confirmed that the vulnerability has been successfully mitigated, and follow-up checks verified that unauthorized data access is no longer possible.

No, the government has not disclosed how long the flaw existed or whether any unauthorized access had occurred before it was patched.




News posted by

Finance news reporter covering taxation, GST, income tax, business compliance, and economy updates. I simplify complex financial topics into easy-to-understand articles for professionals, taxpayers, and business owners on leading finance and tax platforms.

Comments :


More »


Popular News





CCI Pro



Company
Featured 21 September 2026
Consultant - Reporting

Finrep Advisors LLP

Mumbai

CA

View Details
Company
08 September 2026
Audit Executive

Thammana & Associates

Srikakulam

B.Com

View Details
Company
08 September 2026
Semi-Qualified Assitant

Subrahmanyam & Sivudu CA Firm

Hyderabad

CA Inter

View Details
Company
30 September 2026
Senior Accounts Executive

Codeboard Technology

Chennai

MBA

View Details
Company
09 September 2026
Chartered Accountant

Aviv Global Private Limited

Ahmedabad

CA

View Details
Company
30 September 2026
Senior Accountant

Codeboard Technology

Chennai

B.Com

View Details
Company
ARTICLESHIP 07 October 2026
Article Assistant

Malhotra Rajesh & Associates

New Delhi

B.Com

View Details
Company
Featured 12 September 2026
Assistant Manager - Finance & Compliance

Naveen Fintech Pvt Ltd

Kolkata

CA Inter

View Details