PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Watch out, Aadhar biometrics are an easy target for hackers

Posted on October 23, 2017June 25, 2025 by Dissent

Ankush Johar writes, in part:

The government claimed that Aadhaar is completely secure, and the data of the consumers was absolutely safe from any malicious party until a severe flaw was detected in the system. The bug allowed a malicious operator to save a user’s biometrics and simply use it to carry out transactions on the victim’s behalf via replaying the saved biometrics.

In February this year, a Youtube video showed a demo of such a replay attack. Later that month, UIDAI filed a case against an employee of  Suvidhaa Infoserve, saying that an Axis Bank’s gateway was used to carry out around 400 transactions via replaying Aadhaar information that was saved earlier.

Read more on Economic Times.

No related posts.

Category: BreachesNon-U.S.

Post navigation

← FBI couldn’t access nearly 7K devices because of encryption
NHS workers warned about consequences of snooping into patients’ medical records →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Trump administration is launching a new private health tracking system with Big Tech’s help
  • Attorney General James Takes Action to Protect Sensitive Personal Information of Tens of Millions of People
  • Searches of Your Private Data in the Cloud Amount to Illicit State Action
  • How a Tax Subpoena in Ohio Tests European Privacy Law
  • Cambodia moves to enact comprehensive data privacy law
  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com

RSS Recent Posts on DataBreaches.net

  • WA: Cyber-attacks problem for small hospitals
  • Florida prison data breach exposes visitors’ contact information to inmates
  • Experian Wins Appeal to Send Data Breach Victim to Arbitration
  • ICANN sends breach notice to domain registrar Webnic about failure to deal with DNS abuse compliants properly
  • Canadian cybercriminal sentenced to a year in prison for NFT theft scheme
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy