Aadhaar-Linked Data Leaks: What Happened in Past Incidents and What It Means for You
TL;DR: Aadhaar-linked data has been exposed in several documented incidents over the years — most notably a 2018 exposure and a large 2023 leak connected to ICMR/CoWIN data. This article walks through what's actually been confirmed by researchers and reporting, and what that history means for how you think about your own exposure today.
👉 See if your data's already leaked — free 30-second check →
Aadhaar is central to how most Indians interact with government services, banking, and increasingly private-sector verification. Its scale — over 1.4 billion enrolments since 2009 — means that when Aadhaar-linked data is exposed, the numbers involved are often described in hundreds of millions, not thousands.
The 2018 Exposure
In 2018, researchers and reporting identified vulnerabilities in poorly secured systems — including third-party utility and government-adjacent portals — that allowed unauthorised access to Aadhaar-linked records. Reports at the time estimated the scale at over a billion records, making it one of the most significant identity-database exposures reported anywhere in the world at that scale.
The 2023 ICMR / CoWIN-Linked Leak
In October 2023, a threat actor using the alias "pwn0001" advertised on a dark web forum access to what was described as approximately 815 million Indian records, reportedly linked to the Indian Council of Medical Research (ICMR). The dataset reportedly included names, phone numbers, addresses, and both Aadhaar and passport numbers — a combination that researchers noted was particularly sensitive because it paired a government identity number with contact and travel-document information in a single dataset.
This incident is frequently referenced alongside the earlier CoWIN vaccination data exposure reported in mid-2023, though researchers have noted some distinctions in scope between the two events, and official attribution has not always been definitively confirmed by government sources.
What These Incidents Actually Exposed
Across the documented incidents, the recurring pattern involves:
- Names and Aadhaar numbers
- Phone numbers and, in some cases, addresses
- In the 2023 case, passport numbers alongside Aadhaar data
It's worth being precise here: knowing someone's Aadhaar number alone does not, by itself, allow unauthorised access to their bank account or benefits — UIDAI has stated that Aadhaar authentication requires additional verification steps beyond just the number. The risk from these leaks is less about direct account takeover and more about identity-fraud enablement — using a combination of real identifiers to impersonate someone convincingly in scams, loan fraud, or SIM-swap attempts.
What This History Means for You Practically
If your Aadhaar-linked information has been part of any large-scale government or institutional dataset — which, given the scale of past incidents, includes a very large share of the population — the practical takeaway isn't panic. It's informed caution:
- Be more skeptical of unsolicited calls or messages that reference personal details as "proof" of legitimacy — leaked data makes this kind of social engineering easier, not harder to fake
- Lock your Aadhaar biometrics when not actively needed, using the UIDAI mAadhaar app or website, as an added layer against biometric-based fraud attempts
- Monitor for unfamiliar loan or account activity tied to your identity, particularly through your credit report
- Treat OTP and Aadhaar-verification requests with more scrutiny than you might have a few years ago
The Regulatory Response
The DPDP Act 2023 and its accompanying Rules, notified in November 2025, establish a framework requiring data fiduciaries to report breaches and implement security safeguards, with the Data Protection Board of India empowered to levy significant penalties. Substantive compliance obligations under the Act are set to take effect in phases, with full enforcement expected by mid-2027 — meaning the regulatory teeth around incidents like these are still being built out even as the historical incidents remain part of the public record.
Understanding your own exposure — separate from these large institutional datasets — starts with checking what's publicly findable about your phone number and email. The DPDP Act: what rights do you actually have over your personal data in India? covers what recourse exists under current law.
Scan My Shadow checks a submitted phone number and email across 1,500+ sources and returns a report — a useful way to see your own exposure picture independent of these larger institutional incidents.
Frequently Asked Questions
Does a leaked Aadhaar number alone let someone access my bank account?
No. UIDAI has stated that simply knowing an Aadhaar number does not enable unauthorised account access. Authentication requires additional verification steps as prescribed under the Aadhaar Act, 2016.
How do I check if my Aadhaar data was part of a known leak?
There's no official, centralised public tool to check this for past incidents. The most practical step is to focus on protective measures — biometric locking, monitoring credit reports, and being cautious with unsolicited verification requests — rather than searching for direct confirmation of past inclusion.
What is Aadhaar biometric locking and should I use it?
Biometric locking, available through the mAadhaar app or UIDAI's website, disables fingerprint and iris-based authentication until you unlock it. It's a reasonable precaution if you don't frequently need biometric Aadhaar authentication in daily life.
Can I hold UIDAI or the government liable if my Aadhaar data was leaked?
This is a legal question that depends on the specifics of each incident and applicable law, and isn't something to treat as settled without proper legal advice. The DPDP Act does establish breach-reporting and security obligations for data fiduciaries going forward.
Is my Aadhaar number still safe to share for KYC purposes?
Aadhaar remains a legally accepted identity document for KYC in India. The practical guidance is to share it only with legitimate, verified institutions and to be wary of informal or unverified requests for a physical or digital copy.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated