Income Tax e‑Filing Portal: Fix Confirmed, Reader Safety Toolkit

A serious data exposure risk within India’s income tax e‑filing portal was patched. Details, safety level, and a practical checklist are provided below.

🛡️ Status: Fixed (confirmed Oct 2, 2025) Discovered by independent cybersecurity researchers in Bengaluru (IDOR)
Pune Municipal Transport Building, Pune city, representing public infrastructure and governance systems in India.
The Pune Municipal Transport (PMT) Building is used here as a visual cue for public systems. The incident relates to the national e‑filing portal. (Photo: Wikimedia Commons / CC BY‑SA 4.0)

After discovery, the researchers reported the issue to CERT‑In. The matter pertains to the e‑Filing system of the Income Tax Department, under the Ministry of Finance, with platform development associated with the National Informatics Centre. Related reading on Karmactive: misinformation and accountability, copyright and privacy disputes, and large‑scale computing.

Feature Image Link:

Explanation & Current Safety Level

What was found: An IDOR (Insecure Direct Object Reference) permitted a logged‑in user to fetch another taxpayer’s information by altering a request with another PAN.

Data fields involved: names, addresses, phone numbers, email IDs, dates of birth, bank details, and Aadhaar numbers.

Fix status: correction confirmed by the researchers on Oct 2, 2025. The description here relates to the period before that date.

Reader safety level now: Routine precautions advised. The portal was patched; regular password hygiene, updated contact details, and monitoring of accounts remain good practice.

ScopeMore than 135 million users registered; about 76 million filed returns in FY 2024–25.
MechanismServer accepted a PAN swap in a logged‑in request, exposing another user’s record.
StatusResearchers stated the issue was resolved and the portal became safe to continue routine use.

Timeline

September 2025
Discovery during tax filing by two independent researchers.
September 30, 2025
CERT‑In noted the Income Tax Department was addressing the flaw.
October 2, 2025
Researchers confirmed the fix.

Personal Safety Toolkit

The section included the feature image, an explanation of the IDOR, the current fix status, a safety level indicator, a checklist, a timeline, an open‑source map, and working backlinks to official sources and related Karmactive coverage.
Karmactive Whatsapp group - https://www.whatsapp.com/channel/0029Vb2BWGn77qVMKpqBxg3D

Sunita Somvanshi

With over two decades of dedicated service in the state environmental ministry, this seasoned professional has cultivated a discerning perspective on the intricate interplay between environmental considerations and diverse industries. Sunita is armed with a keen eye for pivotal details, her extensive experience uniquely positions her to offer insightful commentary on topics ranging from business sustainability and global trade's environmental impact to fostering partnerships, optimizing freight and transport for ecological efficiency, and delving into the realms of thermal management, logistics, carbon credits, and energy transition. Through her writing, she not only imparts valuable knowledge but also provides a nuanced understanding of how businesses can harmonize with environmental imperatives, making her a crucial voice in the discourse on sustainable practices and the future of industry.

Leave a Reply

Your email address will not be published.

An Archer Midnight eVTOL aircraft flying over the Cleveland Clinic Abu Dhabi hospital at dusk, with the city skyline and water in the background.
Previous Story

Abu Dhabi Hospital Vertiport to Cut Hour-Long Patient Trips to Minutes with Archer’s Electric Flying Taxis

A crowd of college students at the 2007 Pittsburgh University Commencement.
Next Story

IBR Forgiveness Resumes: “You’re Eligible…” Emails Out, Opt-Out Deadline Oct 21 As Processing Ramps For Millions

Latest from India