·PIB

UIDAI Launches Bug Bounty Programme to Further Strengthen Aadhaar Security

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (last 12-18 months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas

1. At a Glance

  • UIDAI's first structured Bug Bounty Programme, launched 11 March 2026, invites vetted ethical hackers to discover vulnerabilities in core Aadhaar digital assets in exchange for severity-graded rewards [1].
  • Marks a shift from closed in-house security audits to a coordinated vulnerability disclosure (CVD) model — a global best practice now formalised for India's largest digital ID system [1].
  • UPSC relevance: intersects GS-II (governance, digital ID, privacy) and GS-III (cyber security, internal security via IT infrastructure).

2. Why in the News

  • On 11 March 2026, the Unique Identification Authority of India (UIDAI) under the Ministry of Electronics & Information Technology (MeitY) launched its first structured Bug Bounty Programme with a 20-member panel of ethical hackers/researchers [1].
  • Programme is operated in partnership with M/s ComOlho IT Pvt. Ltd., a cybersecurity firm acting as the platform partner [2].

3. Background & Evolution

  • UIDAI established in Jan 2009 under Planning Commission; statutory body since Aadhaar Act, 2016 under MeitY.
  • Predecessor government bug-bounty: Aarogya Setu Bug Bounty Programme announced in 2020 by MeitY/NIC — first government-of-India bug bounty [3].
  • UIDAI's prior security tie-ups: UIDAI–SETS (Society for Electronic Transactions and Security, Chennai) MoU in 2023 for R&D in quantum computing, IoT and cyber security [4].
  • 2025–26 challenges (deepfake/spoofing detection for face authentication) under PRID 2179959 preceded the bug bounty [5].

4. Core Static Facts

  • Parent ministry: Ministry of Electronics & Information Technology (MeitY) [1].
  • Implementing body: UIDAI (statutory authority under Section 11, Aadhaar Act 2016).
  • Launch date: 11 March 2026 [1].
  • Participants: 20 selected security researchers/ethical hackers (closed panel, invite-based) [1].
  • Scope (in-scope assets): UIDAI official website, myAadhaar portal, Secure QR Code application [1].
  • Reward basis: Severity-tiered — Critical / High / Medium / Low [2].
  • Platform partner: M/s ComOlho IT Pvt. Ltd. [2].
  • Model: Responsible/coordinated vulnerability disclosure (RVD/CVD).

5. Multi-Dimensional Analysis

Scientific / Technological

  • Crowdsources offensive security testing — uncovers flaws in-house audits and CERT-In empanelled auditors may miss [1][6].
  • Targets web, mobile and crypto-attestation (Secure QR Code) layers — covers full stack of resident-facing Aadhaar services [1].

Legal / Constitutional

  • Operates within the Aadhaar Act 2016 (Section 28 — security & confidentiality of identity information) and Digital Personal Data Protection (DPDP) Act 2023 duties on data fiduciaries.
  • Reinforces compliance with Puttaswamy (2017) privacy judgment by hardening technical safeguards demanded as "reasonable security".

Governance / Ethical

  • Closed-panel model balances transparency vs. risk — limits exposure of critical national infrastructure while still tapping external expertise [1].
  • Aligns with CERT-In's Cyber Crisis Management Plan and the National Cyber Security Policy 2013 ecosystem [6].

Administrative

  • Builds an institutional pipeline of vetted researchers UIDAI can re-engage; reduces reliance solely on empanelled auditors.
  • Tiered reward structure incentivises focus on high-impact bugs (auth bypass, data exposure) over cosmetic issues [2].

6. Recent Developments (last 12-18 months)

  • Mar 2026: Bug Bounty Programme launched [1].
  • Feb 2026: UIDAI Data Hackathon 2026 showcased data-driven governance solutions [7].
  • 2025: UIDAI Grand Challenge for deepfake/mask/spoofing attack detection in Aadhaar face authentication (applications till 15 Nov 2025) [5].
  • 2024: UIDAI partnered with Sarvam AI (indigenous GenAI) for Aadhaar service UX [8].

7. Prelims Hooks

  • UIDAI launched its first structured Bug Bounty Programme on 11 March 2026 [1].
  • Programme covers three assets: UIDAI website, myAadhaar portal, Secure QR Code application [1].
  • Panel size: 20 ethical hackers/researchers (invitation-based) [1].
  • Industry partner: ComOlho IT Pvt. Ltd. [2].
  • Reward tiers: Critical, High, Medium, Low (severity-based) [2].
  • UIDAI is a statutory body under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016.
  • Parent ministry: MeitY (NOT Ministry of Home Affairs, NOT Finance).
  • India's first government bug bounty was for Aarogya Setu (2020) — not Aadhaar [3].
  • UIDAI signed cyber-security R&D MoU with SETS, Chennai [4].
  • CERT-In (under MeitY) is India's nodal cyber-incident response agency [6].
  • Puttaswamy v. Union of India (2017) made privacy a fundamental right (Art. 21).
  • DPDP Act 2023 governs personal data processing in India.

8. Mains Relevance

  • GS-II: e-Governance — applications, models, successes & limitations; citizens' charters; protection of vulnerable sections (digital ID).
  • GS-III: Challenges to internal security through communication networks; basics of cyber security; role of agencies.
  • Probable stems: 1. "Bug-bounty programmes mark a maturing of India's approach to securing critical digital public infrastructure. Discuss with reference to UIDAI's 2026 initiative." (GS-III, 250 words) 2. "Coordinated vulnerability disclosure must coexist with statutory liability under the Aadhaar Act and DPDP Act. Examine." (GS-II, 150 words) 3. "Trust in Aadhaar rests as much on perception as on technical safeguards. Evaluate UIDAI's recent measures." (GS-II)

9. Related Topics to Study Next

  • Aadhaar Act 2016 & Puttaswamy judgment — statutory & constitutional base.
  • DPDP Act 2023 — data fiduciary obligations relevant to UIDAI.
  • CERT-In & CERT-In Directions of April 2022 — incident reporting regime [6].
  • Digital Public Infrastructure (DPI) / India Stack — Aadhaar as foundational layer.
  • National Cyber Security Policy 2013 & upcoming National Cyber Security Strategy.
  • Aarogya Setu Bug Bounty (2020) — first GoI precedent [3].
  • SETS, Chennai — DST-promoted cyber R&D body [4].
  • Face authentication / deepfake challenge by UIDAI [5].

10. Common Errors / Trap Areas

  • Wrong ministry: UIDAI is under MeitY, not Ministry of Home Affairs or Finance.
  • "First Indian govt bug bounty" — that title belongs to Aarogya Setu (2020), not UIDAI [3].
  • Open vs. closed model: UIDAI's programme is closed/invite-only (20 researchers), not a public bug bounty like HackerOne open programmes [1].
  • Scope confusion: The programme covers front-end public assets (website, myAadhaar, QR app) — not the CIDR (Central Identities Data Repository) core [1].
  • Don't confuse UIDAI's bug bounty with CERT-In's RVDP (Responsible Vulnerability Disclosure Programme) — separate frameworks.

Sources

  1. 1UIDAI Launches Bug Bounty Programme to Further Strengthen Aadhaar Security (PIB, 11 Mar 2026)pib.gov.in · tier 1
  2. 2PIB Detail page (same release, additional reward/partner detail)pib.gov.in · tier 1
  3. 3Government announces Bug Bounty Programme for Aarogya Setu (PIB, 2020)pib.gov.in · tier 1
  4. 4UIDAI and SETS join hands for R&D in Quantum Computing, IoT Security and Cyber Security (PIB)pib.gov.in · tier 1
  5. 5UIDAI Seeks Solutions to Defeat Deepfakes/Spoofing in Face Authentication (PIB)pib.gov.in · tier 1
  6. 6CERT-In: India's Frontline Defender against Cyber Threats (PIB document, Jan 2026)static.pib.gov.in · tier 1
  7. 7UIDAI Data Hackathon 2026 (PIB)pib.gov.in · tier 1
  8. 8UIDAI partners with Sarvam AI (PIB)pib.gov.in · tier 1

Also on 11 March

All 11 March articles →