Investigation: hackers have disabled security features of India's Aadhaar enrollment service with a ~$35 software patch, making it possible to create fake IDs
Skilled hackers disabled security features of Aadhaar enrolment software, circulated hack on Whatsapp
Context & Ripple Effects
Aadhaar's security story has been deteriorating along a clear arc: January 2018 brought reports of a database breach exposing information on roughly 1.2 billion Indians, followed by the Times' finding that the program had delivered neither welfare gains nor anti-corruption wins while exposing personal data. A 2019 leak at India's state gas company later showed Aadhaar numbers themselves circulating on an indexed website.
This investigation moves the attack upstream: rather than exfiltrating records, hackers disabled security controls inside the enrollment software itself using a ~$35 patch spread over WhatsApp — meaning the pipeline that mints credentials can be turned against the database, just as India has been extending Aadhaar to let businesses authenticate customers directly.
First-order effects
- Fake identities can now be minted at the enrollment stage, so every downstream consumer of Aadhaar verification inherits unvetted records alongside genuine ones.
- The compromise vector — a cheap patch distributed through WhatsApp groups — puts enforcement burden on enrollment-operator devices rather than central servers, a perimeter UIDAI-style controls cannot easily police.
Second-order effects
- Businesses adopting Aadhaar-based customer authentication face a credibility problem: the credential they rely on can no longer be assumed to correspond to a real person, forcing them toward layered checks of the kind the SS7 attacks already showed can be bypassed when one trusted layer fails.
- Each new leak tied to Aadhaar — database breach, indexed gas-company records, now forged enrollments — compounds the case made in the earlier coverage that the system creates theft exposure faster than it prevents fraud, raising political cost for further expansion.
Third-order effects
- If enrollment-side tampering persists, national ID programs drift toward a trust paradox: governments expand the credential's reach into commerce while the integrity of issuance, not storage, becomes the binding weakness — pushing regulators toward auditing the software supply chain around identity infrastructure.
- The recurring pattern across Aadhaar's breaches suggests biometric ID systems will need defense-in-depth at every endpoint (operator machines, partner websites, telecom signaling), because securing any single tier has repeatedly proven insufficient.
The trend: India is scaling Aadhaar from a welfare database into economy-wide authentication infrastructure faster than the security of its issuance and sharing endpoints can be hardened.