81.5 Crore Aadhaar Records Exposed: Inside India's Biggest Data Breach

In October 2023, a threat actor put 815 million Indian citizen records — names, Aadhaar numbers, passport details — up for sale at $80,000. The breach, believed to originate from ICMR's COVID-19 testing database, became India's largest data leak, testing the country's new data protection regime.

Read Story →94% Evidence5 Sources14 min read
T
The Breakdown Editorial
9 July 2026

Key Takeaways

In October 2023, a threat actor put 815 million Indian citizen records — names, Aadhaar numbers, passport details — up for sale at $80,000. The breach, believed to originate from ICMR's COVID-19 testing database, became India's largest data leak, testing the country's new data protection regime.

  • 815 million (81.5 crore) Indian citizen records posted for sale on Breach Forums on October 9, 2023
  • Data includes Aadhaar numbers, passport details, names, phone numbers, and addresses
  • Suspected source: ICMR's COVID-19 testing database collected during the pandemic
  • Threat actor "pwn0001" offered the dataset for $80,000 — less than $0.0001 per record
  • US cybersecurity firm Resecurity's HUNTER unit discovered and verified the breach
  • CBI launched investigation; CERT-In and Indian cyber agencies engaged
  • The breach became the first major test of India's DPDP Act 2023
  • Triggered AEPS (Aadhaar-enabled payment system) fraud and identity theft concerns

Evidence

The data breach originated from ICMR's COVID-19 testing database.

Verified82%
Primary Sources: 1Evidence: 1 items
Supporting Evidence
  • Multiple cybersecurity researchers and media investigations traced the data structure and collection methodology to ICMR's COVID-19 testing registration system, which collected Aadhaar and passport details for test result delivery.
View Sources →

UIDAI's own systems were compromised in the breach.

Unverified95%
Primary Sources: 1Evidence: 1 items
Supporting Evidence
  • UIDAI clarified that its own systems were not breached. The Aadhaar numbers were obtained from a third-party database (ICMR) that collected Aadhaar data for COVID-19 testing, not from UIDAI's central Aadhaar database.
View Sources →

The DPDP Act 2023 would have prevented this breach had it been in force earlier.

Moderate78%
Primary Sources: 1Evidence: 1 items
Supporting Evidence
  • While the DPDP Act mandates stricter data protection obligations for data fiduciaries, the breach occurred in October 2023, just two months after the Act received presidential assent. Moreover, the Act's provisions were notified in phases, and data collection by ICMR occurred during 2020-2022, before the Act existed.
View Sources →

Aadhaar-enabled Payment System (AEPS) fraud directly increased due to this breach.

Verified85%
Primary Sources: 1Evidence: 1 items
Supporting Evidence
  • The RBI's Financial Stability Report noted a 42% increase in AEPS fraud attempts in the quarters following the breach, with fraudsters using leaked Aadhaar numbers and biometric data to attempt unauthorized transactions.
View Sources →

Key Numbers

81.5 crore (815 million)Total Records CompromisedResecurity
$80,000 (~₹67 lakh)Price Asked for Full DatasetBreach Forums
~$0.0001 (< 1 paisa)Price Per RecordThe Breakdown Analysis
pwn0001Threat Actor AliasResecurity
ICMR COVID-19 Testing DatabaseSuspected Data SourceMultiple Reports
₹250 croreIndia's DPDP Act Fine LimitDPDP Act 2023

Timeline

2020
2021
2022
2023
2024

India's Largest Data Breaches by Records Compromised (in Crores)

020.37540.7561.12581.5ICMR/Aadhaar (2023)Telecom Users (2024)Domino's India (2021)Covaxin/Cowin (2023)Air India (2021)BigBasket (2020)Mobikwik (2021)Justdial (2023)

Estimated Financial Impact of Data Breaches in India (₹ Crore)

02.0k4.1k6.2k8.2k2019202020212022202320242025

Drag to select a range to zoom in

Frequently Asked Questions

Sources

Related Stories

Related Entities

T

The Breakdown Editorial