A significant security vulnerability on India's Income Tax e-filing portal has been successfully patched by the government, averting a potential large-scale leak of taxpayer data. The flaw, discovered by independent cybersecurity researchers, allowed unauthorised access to sensitive personal and financial details. The Indian Computer Emergency Response Team (CERT-In) coordinated with the Income Tax Department to implement a fix, which has been verified as effective.
In a crucial cybersecurity intervention, the Government of India has patched a serious vulnerability in the Income Tax e-filing portal, preventing what could have been a large-scale data leak of taxpayers' confidential information.
Critical Vulnerability Found in Tax Portal
Two independent cyberse
Daily Limit Reached
You have reached your daily limit of 2 Free News
Subscribe to
CCI PRO
for unlimited access
Why Upgrade to
CCI PRO?
-
No Ads
-
WhatsApp Broadcasts
-
Daily E-Newsletter
-
Unlimited News Access
BEST VALUE
2 YEAR PLAN
3,499
(Inclusive of GST)
1 YEAR PLAN
1,999
(Inclusive of GST)
Buy CCI PRO Now
Already a PRO member?
Login here
for an ad-free experience.
FAQ :
An IDOR (Insecure Direct Object Reference) vulnerability was discovered, which allowed logged-in users to access another taxpayer's sensitive information by altering network request parameters.
The data potentially exposed included full name, address, email, phone number, date of birth, Aadhaar number, and bank account details for both individuals and registered entities.
The flaw was discovered by two independent cybersecurity researchers, Akshay C.S. and Viral.
The researchers responsibly reported the vulnerability to CERT-In, which then coordinated with the Income Tax Department to investigate and implement a fix.
Yes, CERT-In confirmed that the vulnerability has been successfully mitigated, and follow-up checks verified that unauthorized data access is no longer possible.
No, the government has not disclosed how long the flaw existed or whether any unauthorized access had occurred before it was patched.