Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
September 30, 2025
No Result
View All Result
Concur News

Home » Data Breach at vORBO Portal Uncovers Major Vulnerability

Data Breach at vORBO Portal Uncovers Major Vulnerability

August 4, 2025
in India, News
Reading Time: 3 mins read
Data Breach at vORBO Portal Uncovers Major Vulnerability
Share on LinkedinShare on Whatsapp

AIIMS ORBO Website Exposes Sensitive Donor Information Due to Security Flaw

A major security issue in the AIIMS Organ Retrieval Banking Organisation (ORBO) website exposed highly sensitive personal and medical details of organ and tissue donors from across India. This flaw allowed anyone to access private data without logging in or needing permission.

Aniket Tomar, an independent cybersecurity expert, discovered the problem in May 2025. He found that the system allowed full access to the names, phone numbers, email addresses, home addresses, blood groups, donated organs and tissues, donor ages, and even witness details of thousands of registered ORBO donors.

Why This Matters

ORBO is a department at AIIMS, New Delhi, responsible for handling cadaver organ and tissue donations. It manages the registry of people declared brain dead and coordinates transplants. Because of this, the leaked data involved highly private and sensitive health information.

Consent Foundation

Tomar confirmed that he accessed records not just from Delhi, but also from donors across the country. He warned that such a data breach could seriously damage public trust and compromise India’s national health data system.

Details of the Leak

Tomar revealed that the AIIMS portal did not have any protection in place to block access to the data. Anyone could view the information openly, without needing a password or authentication.

  • Names, phone numbers, emails, and addresses
  • Medical details like blood group and donated organs
  • Details of witnesses who helped with the donation process

Government Response

Tomar immediately informed CERT-In (India’s cybersecurity agency), sharing screenshots and technical proof of the issue. He also pointed out that the leak violated the Digital Personal Data Protection Act, 2023, which mandates strict protection of personal data.

In response, CERT acknowledged the issue and worked with AIIMS to fix it. By June 18, 2025, the security hole was patched, and public access to donor information was blocked. CERT also thanked Tomar for responsibly reporting the issue.

Call for Action

Tomar urged AIIMS and other public health organizations to audit their websites and platforms for similar weaknesses. He also advised them to inform affected donors about the breach, as required by law.

“Sensitive personal and medical data should never be made public,” Tomar said. “Healthcare institutions must protect the privacy of those who trust them.”



Also read: Sri Lanka Sets April 2026 for Digital ID Launch, Pledges Data Protection

Tags: AIIMSCyber securityData breachPublic Health

Related Posts

Retailers Face Check for Collecting Phone Numbers Under New Data Law
Global

Retailers Face Check for Collecting Phone Numbers Under New Data Law

August 27, 2025
Canada Updates Rules on Biometric Technology Usage
Global

Canada Updates Rules on Biometric Technology Usage

August 26, 2025
Interview with Simran Gupta: How a Freelance Corporate Lawyer Navigates India’s Evolving Data Privacy Era
Interview

Interview with Simran Gupta: How a Freelance Corporate Lawyer Navigates India’s Evolving Data Privacy Era

August 26, 2025
Chief Secretary Reviews Steps to Safeguard Jammu & Kashmir’s Digital Assets
India

Chief Secretary Reviews Steps to Safeguard Jammu & Kashmir’s Digital Assets

August 21, 2025

RECOMMENDED NEWS

SK telecom

SK Telecom Massive Data Breach: Chairman Chey Publicly Apologizes

5 months ago
Marks & Spencer

Marks & Spencer Admits Customer Data Was Leaked in Cyberattack

5 months ago
Haryana’s Mandatory Pregnancy Registration Raises Privacy Concerns

Haryana’s Mandatory Pregnancy Registration Raises Privacy Concerns

6 months ago
Data breach

Man Claims FIITJEE Fraud and Data Breach, Seeks Rs 71,000

5 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager