Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
August 7, 2025
No Result
View All Result
Concur News

Home » Data Breach at vORBO Portal Uncovers Major Vulnerability

Data Breach at vORBO Portal Uncovers Major Vulnerability

August 4, 2025
in India, News
Reading Time: 3 mins read
Data Breach at vORBO Portal Uncovers Major Vulnerability
Share on LinkedinShare on Whatsapp

AIIMS ORBO Website Exposes Sensitive Donor Information Due to Security Flaw

A major security issue in the AIIMS Organ Retrieval Banking Organisation (ORBO) website exposed highly sensitive personal and medical details of organ and tissue donors from across India. This flaw allowed anyone to access private data without logging in or needing permission.

Aniket Tomar, an independent cybersecurity expert, discovered the problem in May 2025. He found that the system allowed full access to the names, phone numbers, email addresses, home addresses, blood groups, donated organs and tissues, donor ages, and even witness details of thousands of registered ORBO donors.

Why This Matters

ORBO is a department at AIIMS, New Delhi, responsible for handling cadaver organ and tissue donations. It manages the registry of people declared brain dead and coordinates transplants. Because of this, the leaked data involved highly private and sensitive health information.

Consent Foundation

Tomar confirmed that he accessed records not just from Delhi, but also from donors across the country. He warned that such a data breach could seriously damage public trust and compromise India’s national health data system.

Details of the Leak

Tomar revealed that the AIIMS portal did not have any protection in place to block access to the data. Anyone could view the information openly, without needing a password or authentication.

  • Names, phone numbers, emails, and addresses
  • Medical details like blood group and donated organs
  • Details of witnesses who helped with the donation process

Government Response

Tomar immediately informed CERT-In (India’s cybersecurity agency), sharing screenshots and technical proof of the issue. He also pointed out that the leak violated the Digital Personal Data Protection Act, 2023, which mandates strict protection of personal data.

In response, CERT acknowledged the issue and worked with AIIMS to fix it. By June 18, 2025, the security hole was patched, and public access to donor information was blocked. CERT also thanked Tomar for responsibly reporting the issue.

Call for Action

Tomar urged AIIMS and other public health organizations to audit their websites and platforms for similar weaknesses. He also advised them to inform affected donors about the breach, as required by law.

“Sensitive personal and medical data should never be made public,” Tomar said. “Healthcare institutions must protect the privacy of those who trust them.”



Also read: Sri Lanka Sets April 2026 for Digital ID Launch, Pledges Data Protection

Tags: AIIMSCyber securityData breachPublic Health

Related Posts

Chanel Data Breach Hits U.S. Customers as Retail Faces Mounting Cyber Threats
News

Chanel Data Breach Hits U.S. Customers as Retail Faces Mounting Cyber Threats

August 6, 2025
Apple Device - news.concur.live
India

Apple Device Users Beware: Indian Govt Warns of Major Security Threat

August 6, 2025
NPCI and Digital Payment Platforms Urge Relief from DPDP Act Rules
India

NPCI and Digital Payment Platforms Urge Relief from DPDP Act Rules

August 5, 2025
Kaspersky’s Cybersecurity Innovations Power India’s Digital Safety
India

Kaspersky’s Cybersecurity Innovations Power India’s Digital Safety

August 5, 2025

RECOMMENDED NEWS

Privacy - news.concur

Bridging Policy and Technology: An Interview with Gaurav Mehta, Co-founder of Concur – Consent Manager

4 months ago
CoinDCX

India’s Leading Crypto Exchange CoinDCX Reports Internal Wallet Hack

2 weeks ago
TikTok Faces EU Investigation

TikTok Faces EU Investigation

4 weeks ago
NHS software provider fined £3m over data breach

NHS software provider fined £3m over data breach

4 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Investigation Law Meity penalty Personal data Press Release Privacy RBI RTI Act SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager