Researcher: for over a year, India's education ministry app Diksha exposed the names, phone numbers, and email addresses of 1M+ teachers via an unsecured server
Context & Ripple Effects
The Diksha disclosure lands in a familiar arc: India's national-scale databases have been caught open before, from reports of the Aadhaar breach exposing records tied to ~1.2B Indians to the state gas company leak where customer data including Aadhaar numbers was left indexable by Google. What distinguishes this case is both the operator — the education ministry itself, not a private firm — and the duration: an unsecured server sitting open for more than a year.
It also extends a pattern researchers have documented across the education sector specifically, from Get Schooled leaving hundreds of thousands of US students' details exposed to OneClass leaking contact data for over a million students. The difference is that teachers, unlike students on a charity platform, are government employees whose contact details now circulate outside official channels.
First-order effects
- Over a million teachers have had their names, phone numbers, and email addresses readable by anyone who found the server for at least a year — contact-grade personal data that can be used for targeted phishing and impersonation of ministry communications.
- The education ministry now owns a public credibility problem for its flagship teacher-facing platform, having to explain a year-long exposure on infrastructure it built and operates directly.
Second-order effects
- Other Indian government agencies running citizen- and employee-facing apps should expect heightened researcher scrutiny of their server configurations, since Diksha joins Aadhaar and the gas utility as proof that national-scale state systems get probed and reported.
- Private edtech operators like OneClass gain a defensive talking point — 'even the ministry leaked' — while also facing the same audit pressure, as education-sector leaks are now being catalogued across borders.
Third-order effects
- If the sequence holds — Aadhaar, the gas company, Get Schooled, OneClass, now Diksha — the structural issue is not any single operator's negligence but that rapid digitization of education and identity systems is outrunning default-secure server practice, pushing toward mandated security baselines for government-built platforms rather than case-by-case fixes.
The trend: India's build-out of national digital platforms is repeatedly colliding with basic server-security failures, making researcher-disclosed leaks of millions of records a recurring feature of its digitization push.