Income Tax e‑Filing Portal: Fix Confirmed, Reader Safety Toolkit
A serious data exposure risk within India’s income tax e‑filing portal was patched. Details, safety level, and a practical checklist are provided below.

After discovery, the researchers reported the issue to CERT‑In. The matter pertains to the e‑Filing system of the Income Tax Department, under the Ministry of Finance, with platform development associated with the National Informatics Centre. Related reading on Karmactive: misinformation and accountability, copyright and privacy disputes, and large‑scale computing.
Explanation & Current Safety Level
What was found: An IDOR (Insecure Direct Object Reference) permitted a logged‑in user to fetch another taxpayer’s information by altering a request with another PAN.
Data fields involved: names, addresses, phone numbers, email IDs, dates of birth, bank details, and Aadhaar numbers.
Fix status: correction confirmed by the researchers on Oct 2, 2025. The description here relates to the period before that date.
Reader safety level now: Routine precautions advised. The portal was patched; regular password hygiene, updated contact details, and monitoring of accounts remain good practice.