Government Fixes Major Security Flaw in Income Tax Portal, Prevents Data Leak



Quick Summary
A significant security vulnerability on India's Income Tax e-filing portal has been successfully patched by the government, averting a potential large-scale leak of taxpayer data. The flaw, discovered by independent cybersecurity researchers, allowed unauthorised access to sensitive personal and financial details. The Indian Computer Emergency Response Team (CERT-In) coordinated with the Income Tax Department to implement a fix, which has been verified as effective.

In a crucial cybersecurity intervention, the Government of India has patched a serious vulnerability in the Income Tax e-filing portal, preventing what could have been a large-scale data leak of taxpayers' confidential information. Critical Vulnerability Found in Tax Portal Two independent cyberse
Daily Limit Reached

You have reached your daily limit of 2 Free News

Subscribe to CCI PRO for unlimited access

Why Upgrade to CCI PRO?
  • No Ads
  • WhatsApp Community
  • Daily E-Newsletter
  • Unlimited News Access
  • Profile Visitors
  • Link Social Profiles
  • Featured Job Posts
  • Pro Badge
  • Expert GST Guidance
  • Unlimited Forum Replies
  • Download Content in PDF
1 Year PLAN
1999
(Excl. of GST ₹359)

BEST VALUE
2 Years PLAN
3499
(Excl. of GST ₹629)

3 Months PLAN
999
(Excl. of GST ₹179)

View all CCI PRO benfits

Already a PRO member? Login here for an ad-free experience.

FAQ :

An IDOR (Insecure Direct Object Reference) vulnerability was discovered, which allowed logged-in users to access another taxpayer's sensitive information by altering network request parameters.

The data potentially exposed included full name, address, email, phone number, date of birth, Aadhaar number, and bank account details for both individuals and registered entities.

The flaw was discovered by two independent cybersecurity researchers, Akshay C.S. and Viral.

The researchers responsibly reported the vulnerability to CERT-In, which then coordinated with the Income Tax Department to investigate and implement a fix.

Yes, CERT-In confirmed that the vulnerability has been successfully mitigated, and follow-up checks verified that unauthorized data access is no longer possible.

No, the government has not disclosed how long the flaw existed or whether any unauthorized access had occurred before it was patched.




News posted by

Finance news reporter covering taxation, GST, income tax, business compliance, and economy updates. I simplify complex financial topics into easy-to-understand articles for professionals, taxpayers, and business owners on leading finance and tax platforms.

Comments :


More »


Popular News





CCI Pro



Company
24 August 2026
Semi-Qualified CA/CA Finalist - Tax, GST, Audit & Accounts

Bharat Shah & Associates

Mumbai

CA Inter

View Details
Company
ARTICLESHIP 24 August 2026
Article Assistant

M/s.S.G.Salecha & Co.

Mumbai

CA Inter

View Details
Company
27 August 2026
ACCOUNTANT

CHARUPREETI & CO

Noida

Graduate (Any)

View Details
Company
ARTICLESHIP 26 August 2026
CA Article Assistant/CA Drop Out/Accounts Executive

PARV & Co.

New Delhi

CA Inter

View Details
Company
08 September 2026
Semi-Qualified Assitant

Subrahmanyam & Sivudu CA Firm

Hyderabad

CA Inter

View Details
Company
ARTICLESHIP 17 August 2026
CA Article Trainee

ASC Group

Noida

CA Inter

View Details
Company
ARTICLESHIP 24 August 2026
Chartered Accountant Articles

Rohit KC Jain & Co

New Delhi

CA Inter

View Details
Company
08 September 2026
Audit Executive

Thammana & Associates

Srikakulam

B.Com

View Details