Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
September 15, 2025
No Result
View All Result
Concur News

Home » Security Breach Compromises Personal Data of Organ Donors

Security Breach Compromises Personal Data of Organ Donors

July 29, 2025
in India
Reading Time: 3 mins read
Security Breach Compromises Personal Data of Organ Donors
Share on LinkedinShare on Whatsapp

Massive Data Leak Found in AIIMS Organ Donor Website, Now Fixed

An independent researcher recently discovered a serious security issue on the website of the Organ Retrieval Banking Organisation (ORBO), which is part of the All India Institute of Medical Sciences (AIIMS), New Delhi.This vulnerability exposed the personal details of people who had voluntarily registered as organ donors from across India. The leaked information included names, health records, contact numbers, home addresses, blood groups, and even emergency contact details.

Aniket Tomar, a cybersecurity researcher, discovered the vulnerability in mid-May 2025. He reported the issue to the Indian Computer Emergency Response Team (CERT-In), which is responsible for handling cybersecurity threats in the country. After receiving his alert, CERT and AIIMS took action, and the exposed data is no longer available to the public.

What ORBO Does

ORBO plays a key role in organ and tissue donation in India. ORBO manages the registry of people who are declared brain dead and coordinates donations and transplants. It also works with hospitals to spread awareness and streamline the donation process.

Consent Foundation

Unfortunately, this platform had a flaw. It allowed anyone to access sensitive personal and medical information without logging in or providing any authentication.

This made it possible for unauthorized individuals to view data that should have remained private.

Expert Raises Alarm Over Data Safety

In his alert, Aniket Tomar warned that the data leak was serious and could allow cybercriminals to exploit it. They could use the exposed information for identity theft, phishing scams, and other harmful activities. He stressed that such a leak from a top medical institution like AIIMS damages public trust in India’s digital health systems.

Tomar further pointed out that the breach violated the rules set by the Digital Personal Data Protection (DPDP) Act, 2023. The Act requires institutions to protect sensitive personal data. He also urged the government to review and audit similar websites of other hospitals and health portals to ensure they are secure.

CERT Responds, ORBO Fixes Issue

CERT officially thanked Tomar on June 18, 2025, for his efforts. Tomar confirmed that the developers fixed the vulnerability and removed public access to the data. However, he recommended that AIIMS should notify all affected donors and take further steps to prevent such incidents in the future.

“I was able to see lakhs of donor records, and they were not just from Delhi—they came from across the country,” Tomar told The Hindu. “This is a serious privacy issue. People who donated their organs trusted the system to keep their information safe. That trust has now been shaken.”

He also called this more than just a technical problem—it’s an ethical issue that puts India’s entire healthcare system under the spotlight. People may hesitate to join life-saving programs like organ donation if they lose trust in how institutions handle their data.



Also read: https://news.concur.live/parliament-panel-questions-meity-on-delays-in-implementing-dpdp-act/

Tags: Data breachData privacyData ProtectionTechnology

Related Posts

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns
India

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

September 8, 2025
Affordability Meets Privacy Risks in ChatGPT Go
India

Affordability Meets Privacy Risks in ChatGPT Go

September 3, 2025
Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw
Global

Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw

September 1, 2025
Raghuveer
Interview

Interview with Dr. Raghuveer Kaur, DPO at Cateina Technologies, on DPDPA, GRC, and Building Scalable Privacy Frameworks

August 29, 2025

RECOMMENDED NEWS

AI Generated Aadhaar and PAN Cards Spark Concerns

AI Generated Aadhaar and PAN Cards Spark Concerns

5 months ago
privacy and hyiegene

Hyderabad: Absence of Urinal Dividers at Inorbit Mall Ignites Debate on Privacy and Hygiene

6 months ago
TRAI Pilot

TRAI Teams Up with RBI and Banks to Launch Digital Consent Pilot Against Spam

3 months ago
Sebi Extends Deadline for Cybersecurity Compliance

Sebi Extends Deadline for Cybersecurity Compliance

6 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager