/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher: for over a year, India's education ministry app Diksha exposed the names, phone numbers, and email addresses of 1M+ teachers via an unsecured server

Wired

Context & Ripple Effects

The Diksha disclosure lands in a familiar arc: India's national-scale databases have been caught open before, from reports of the Aadhaar breach exposing records tied to ~1.2B Indians to the state gas company leak where customer data including Aadhaar numbers was left indexable by Google. What distinguishes this case is both the operator — the education ministry itself, not a private firm — and the duration: an unsecured server sitting open for more than a year.

It also extends a pattern researchers have documented across the education sector specifically, from Get Schooled leaving hundreds of thousands of US students' details exposed to OneClass leaking contact data for over a million students. The difference is that teachers, unlike students on a charity platform, are government employees whose contact details now circulate outside official channels.

First-order effects

  • Over a million teachers have had their names, phone numbers, and email addresses readable by anyone who found the server for at least a year — contact-grade personal data that can be used for targeted phishing and impersonation of ministry communications.
  • The education ministry now owns a public credibility problem for its flagship teacher-facing platform, having to explain a year-long exposure on infrastructure it built and operates directly.

Second-order effects

  • Other Indian government agencies running citizen- and employee-facing apps should expect heightened researcher scrutiny of their server configurations, since Diksha joins Aadhaar and the gas utility as proof that national-scale state systems get probed and reported.
  • Private edtech operators like OneClass gain a defensive talking point — 'even the ministry leaked' — while also facing the same audit pressure, as education-sector leaks are now being catalogued across borders.

Third-order effects

  • If the sequence holds — Aadhaar, the gas company, Get Schooled, OneClass, now Diksha — the structural issue is not any single operator's negligence but that rapid digitization of education and identity systems is outrunning default-secure server practice, pushing toward mandated security baselines for government-built platforms rather than case-by-case fixes.

The trend: India's build-out of national digital platforms is repeatedly colliding with basic server-security failures, making researcher-disclosed leaks of millions of records a recurring feature of its digitization push.

Discussion

  • @digitaldutta Srinivas Kodali on x
    Yet another initiative of Mr Nilekani forcing us to part data with that makes us vulnerable by building shitty tech. What the hell did @IndianCERT do about it? Obviously sleeping on it waiting for orders from Nilekani. https://www.wired.com/...
  • @wired @wired on x
    EXCLUSIVE: A public education app exposed the data of millions of students and teachers to hackers, scammers, and virtually anyone who knew where to look for over a year. https://www.wired.com/...
  • @sandeep_pt Sandeep Manudhane on x
    With such low levels of security, entire citizen data is practically available for stealing. Here, it's the children's data - everything in it. https://www.wired.com/...
  • @dmehro Dhruv Mehrotra on x
    NEW with @telliotter: An app operated by India's Education Ministry exposed the personally identifying information of millions of students and teachers for over a year https://www.wired.com/...
  • @peterguest Peter Guest on x
    The full names, phone numbers, and email addresses of more than 1 million Indian teachers were left exposed on an unsecured database, after being collected by a Ministry of Education app. Solid scoop by @telliotter. https://www.wired.com/...