Aadhaar Can't Be Hacked, Vested Interests Spreading Lies: UIDAI

Advertisement
By Indo-Asian News Service | Updated: 12 September 2018 09:55 IST
Highlights
  • Such reports are "completely incorrect and irresponsible", said UIDAI
  • "Vested interests deliberately trying to create confusion among people"
  • Any person can generate Aadhaar ID using the patch for Rs. 2,500: report

The Unique Identification Authority of India (UIDAI) on Tuesday dismissed reports of hacking of Aadhaar enrolment software as "completely incorrect and irresponsible" and said some vested interests were deliberately trying to create confusion among people.

The denial came after an investigation by HuffPost India revealed that the Aadhaar database, which contains the biometrics and personal information of over one billion Indians, "had been compromised by a software patch which disables critical security features of the software used to enrol new Aadhaar users".

According to the report, any unauthorised person from anywhere in the world can generate Aadhaar ID using the patch which is freely available for Rs. 2,500.

Advertisement

The UIDAI said the claims about Aadhaar being vulnerable to tampering lacked substance and were totally baseless.

"Certain vested interests are deliberately trying to create confusion in the minds of people which is completely unwarranted," a statement issued by the organisation said.

It added that the UIDAI matches all the biometric (10 fingerprints and both iris) of a resident enrolling for Aadhaar with the biometrics of all Aadhaar holders before issuing the unique ID.

Advertisement

"UIDAI has taken all necessary safeguard measures spanning from providing standardized software that encrypts entire data even before saving to any disk, protecting data using tamper proofing, identifying every one of the operators in every enrolment, identifying every one of thousands of machines using a unique machine registration process, which ensures every encrypted packet is tracked," the statement said.

It said all measures to ensure end-to-end security of resident data were taken including full encryption of resident data at the time of capture, tamper resistance, physical security, access control, network security, stringent audit mechanism, 24x7 security and fraud management system monitoring.

Advertisement

Earlier, a report by the HuffPost said a software patch available for as little as Rs 2,500 lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers. It said the patch also disables the GPS security feature of the software allowing anyone from any location to enrol users.

UIDAI clarified that no operator can make or update Aadhaar unless resident himself gives his biometric.

Advertisement

"Any enrolment or update request is processed only after biometrics of the operator is authenticated and resident's biometrics is de-duplicated at the backend of UIDAI system," it said.

It added that as part of its "stringent" enrolment and updation process, UIDAI checks enrolment operator's biometric and other parameters before processing the enrolment or updates and only after all checks are found to be successful, enrolment or update of resident is further processed.

"Therefore it is not possible to introduce ghost entries into Aadhaar database."

UIDAI said that even in a hypothetical situation where a ghost enrolment or update packet is sent to the UIDAI by some "manipulative attempt", the same is identified by the robust back-end system and all such enrolment packets get rejected and no Aadhaar is generated.

"Also, the concerned enrolment machines and the operators are identified, blocked and blacklisted permanently from the UIDAI system. In appropriate cases, police complaints are also filed for such fraudulent attempts," it said.

UIDAI said that the reported claim of "anybody is able to create an entry into Aadhaar database, then the person can create multiple Aadhaar cards" is completely false.

"If an operator is found violating UIDAI's strict enrolment and update processes or if one indulges in any type of fraudulent or corrupt practices, UIDAI blocks and blacklists them and imposes financial penalty upto Rs. 1 lakh per instance. It is because of this stringent and robust system that as on date more than 50,000 operators have been blacklisted," UIDAI added.

It said that it keeps adding new security features in its system as required from time-to-time to thwart new security threats by unscrupulous elements.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: UIDAI, Aadhaar
Advertisement

Related Stories

Popular Mobile Brands
  1. Hackers Steal Hundreds of Gigabytes of Data from European Space Agency
  1. NASA Confirms Expedition 74 Will Continue ISS Work After Crew-11 Exit
  2. European Space Agency Hit by Cyberattacks, Hundreds of Gigabytes of Data Stolen by Hackers
  3. Ustaad Bhagat Singh OTT Release: When, Where to Watch Harish Shankar's Telugu Action Drama Film
  4. Bha Bha Ba is Now Streaming: All You Need to Know About This Malayalam Comedy Thriller Film
  5. World’s Biggest Alien Search Enters Final Stage With 100 Mystery Signals
  6. NASA Pulls Out Artemis II Rocket to Launch Pad Ahead of Historic Moon Mission
  7. Shambhala OTT Release: When, Where to Watch the Telugu Supernatural Horror Film
  8. AGS 28 OTT Release: Know Where to Watch This Tamil Entertainer Starring Arjun, Abhirami
  9. Avatar: Fire and Ash OTT Release: When, Where to Watch James Cameron’s Epic Sci-Fi Fantasy
  10. OpenAI to Begin Testing Ads in ChatGPT, Says Responses Will Not Be Influenced
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.