The 2015 Chennai Municipal Corporation Data Leak and Digital Governance Security

In December 2015, cybersecurity advocates identified a severe data exposure flaw on the Corporation of Chennai's official web portal, where birth and death certificates dating as far back as 1910 were accessible to the public without authentication or rate limiting.

An Unprotected Query Interface

Because the municipal database endpoint lacked user access controls, anyone could query arbitrary registration dates and download sensitive citizen birth records containing full names, parentage, residential addresses, and hospital records as PDF documents.

A Wake-Up Call for Municipal Cybersecurity

Birth records are foundational documents used for passport issuance, school admissions, and financial verification in India. The exposure underscored the critical necessity for robust access control, input validation, and security auditing across government digital service portals during India's nationwide digital transformation drive.

Comments