Researchers: India's state gas company allowed a sensitive part of its website to be indexed by Google, exposing 5M+ customer records, including Aadhaar numbers
Context & Ripple Effects
This leak lands a year after reports that India's Aadhaar national ID database itself was breached, exposing information on roughly 1.2B Indians — so the ID number at the center of this exposure was already under scrutiny. The new twist is the mechanism: no hack required, just a state-run gas company letting Google crawl and index a sensitive section of its own website.
It also fits an established pattern in the related coverage of Indian government-adjacent data sitting open in plain sight, from hundreds of unsecured medical imaging servers still exposing 1M+ records to a 274M-record MongoDB dump of citizen PII.
First-order effects
- Over 5 million gas company customers have their names and Aadhaar numbers retrievable through ordinary Google searches right now, meaning anyone — not just skilled attackers — can pull identity data that feeds India's entire verification ecosystem.
- The gas company faces immediate remediation work: de-indexing the exposed pages, purging cached results from Google, and deciding whether the leak triggers breach-notification obligations under India's rules.
Second-order effects
- Every other Indian state agency running a public web portal now has an audit trigger for how its own sensitive endpoints handle robots.txt and authentication, because the failure mode here costs nothing to replicate.
- The Aadhaar system's credibility takes another hit on top of the reported 2018 breach, raising friction for businesses and banks that depend on Aadhaar-based KYC and giving privacy advocates concrete evidence in policy fights.
Third-order effects
- The recurring shape across the corpus — India's medical servers, a Bangladeshi government site leaking millions of citizens' records, a Chinese database of up to 800M resident IDs — suggests national-scale ID digitization is outpacing basic operational security, pushing governments toward mandatory security baselines and researcher-disclosure channels rather than ad hoc fixes.
- If leaks keep surfacing via researchers instead of regulators, oversight may shift toward treating search engines and cloud indexes as de facto auditors of government data hygiene — an uncomfortable but structural dependency.
The trend: Government-held citizen databases are leaking through elementary misconfigurations at national scale, with independent researchers — not regulators or the agencies themselves — doing the discovering.